ZeroHour
Organization

HackForums

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

ShinyHunters exploited a Grav CMS file upload flaw to breach and deface the Clop ransomware gang's leak site, claiming theft of source code, logs, and Tor private keys.

The ShinyHunters extortion gang exploited a claimed unauthenticated file upload vulnerability in Grav CMS to upload a taunting file and completely deface the Clop ransomware operation's Tor data leak site with Umbreon ASCII art. ShinyHunters claims it gained full server access, stealing source code, Grav CMS plugins, /var/log files, and the private keys for Clop's onion service, and plans to extort Clop with a 72-hour deadline. The feud reportedly stems from Clop's 2025 Oracle E-Business Suite extortion campaign, which used the zero-day CVE-2025-61882 and an exploit ShinyHunters says was stolen from them. BleepingComputer confirmed the defacement but could not verify the data theft or key theft claims.

BleepingComputerupdated · 13h agofirst · 13h agoRansomware in the wild 5 sourcesCVE-2025-61882

Related CVEs

  • Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processing
    CVE-2025-61882 is a critical (CVSS 9.8) authentication flaw (CWE-287) in the BI Publisher Integration component of the Oracle Concurrent Processing product within Oracle E-Business Suite. An unauthenticated attacker with network access over HTTP can exploit it remotely with no credentials and no user interaction, achieving a takeover of Oracle Concurrent Processing with high confidentiality, integrity, and availability impact. Any organization running Oracle E-Business Suite 12.2.3 through 12.2.14 is affected, especially instances reachable from the internet. The flaw is being actively exploited in the wild: the Cl0p data-theft group has used it to breach dozens of organizations (including Harvard University, with 1.3 TB of data leaked), CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06 with known ransomware use, and EPSS puts its 30-day exploitation probability at 99.7%.
    · Oracle E-Business Suite (Oracle Concurrent Processing, BI Publisher Integration component) 12.2.3 - 12.2.14 KEV ransomwarelarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.