ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

Executive Summary

ShinyHunters exploited an unauthenticated path‑traversal flaw in Grav CMS to deface the Clop ransomware gang’s data‑leak site. The attack forced Clop to move the site to a new Tor address. The vulnerability, present in unpatched Grav installations, allowed attackers to read arbitrary files and modify site content.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-25T20:57:55+00:00 - Category: threat-intel

Original Description: The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]

"The highest stage in moral ure at which we can arrive is when we recognize that we ought to control our thoughts."

— Charles Darwin
Source: Bleeping Computer