The headline story is Cl0p’s ruthless exploitation of a zero-day in PTC Windchill — the industrial platform underpinning engineering operations at Shell, Philips, and dozens of other household names. While that campaign was still unfolding, CareCloud disclosed that attackers quietly pillaged 3.7 million patient records from its Amazon Web Services environment back in March. Meanwhile, CISA added six actively exploited vulnerabilities to its KEV catalog — three scoring a maximum-tier CVSS 9.8 — giving federal agencies binding patching deadlines and signaling that enterprise patch queues are not