chiprook
← Security
SecuritySeptember 26, 2026, 03:57

ShinyHunters hacked Clop leak site via Grav CMS path traversal flaw

ShinyHunters breached and defaced the Clop ransomware gang's data leak site by exploiting an unpatched path traversal flaw, CVE-2026-42608, in Grav CMS 1.7.43. Clop moved its leak site to a new Tor address, denied negotiating with ShinyHunters, and said no valuable data was stored on the server. Grav confirmed the flaw and released patch 1.7.53.4.

ShinyHunters hacked Clop leak site via Grav CMS path traversal flaw
#Clop#ShinyHunters#GravCMS
Read next
Security

ShinyHunters Hacks Clop Leak Site, Threatens to Extort Ransomware Gang

Security

Cybersecurity roundup: Clop leak site seized, Docker botnet hunts AI keys, water utility exposure

Security

FBI investigating alleged ShinyHunters breach of its jobs site

Security

ShinyHunters hijacks Cl0p ransomware site, demands extortion payment