Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

ShinyHunters breached Clop leak site through Grav CMS flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after its previous server was compromised and defaced. BleepingComputer reports that the breach used an unpatched, unauthenticated path traversal flaw in Grav CMS.

ShinyHunters first posted a small text file on the site, then replaced it with a defacement featuring its Umbreon Pokémon logo and a link to its own leak site. The group later claimed it stole source code, Grav CMS plugins, server logs and private keys for Clop’s Tor onion service, and demanded a ransom while threatening to publish the files.

Clop said its Grav installation had not been fully updated, but disputed that valuable operational or financial data was taken. It denied having a relationship or ongoing negotiations with ShinyHunters. ShinyHunters declined to answer further questions from BleepingComputer about Clop’s removal from its leak site.

Grav confirmed the flaw and the attacker’s technical description. Tracked as CVE-2026-42608, the path traversal issue was fixed in Grav 2.0 (2.0.0-beta.2), but the fix had not initially been backported to the 1.7 branch. Grav later backported it and released version 1.7.53.4. The developers said the flaw is in Grav core, not the Form plugin, and advised users still on the 1.7 branch to upgrade to 1.7.53.4. Current Grav 2.x releases were already protected.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.