ShinyHunters hacked Clop leak site via Grav CMS path traversal flaw
ShinyHunters breached and defaced the Clop ransomware gang's data leak site by exploiting an unpatched path traversal flaw, CVE-2026-42608, in Grav CMS 1.7.43. Clop moved its leak site to a new Tor address, denied negotiating with ShinyHunters, and said no valuable data was stored on the server. Grav confirmed the flaw and released patch 1.7.53.4.
- ShinyHunters claims it stole source code, server logs and Clop's Tor private keys
- CVE-2026-42608 was fixed in Grav 2.0 but never backported to the 1.7 branch
- Clop moved its leak site to a new onion address and denies contact with ShinyHunters
- Grav released patch 1.7.53.4 and urges all 1.7 users to upgrade
Read next
Security