ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
ShinyHunters defaced Clop's leak site via unpatched Grav CMS path traversal CVE-2026-42608; Grav patched the 1.7 branch.
The Clop ransomware gang moved its Tor leak site after ShinyHunters compromised and defaced the previous server. ShinyHunters said it stole source code, Grav plugins, server logs, and the onion service's private keys, then demanded a ransom; Clop said the unpatched server held only site content and denied any relationship or negotiations. Grav confirmed the bug as CVE-2026-42608, an unauthenticated path traversal in Grav core, present on Clop's Grav 1.7.43 install. The issue was fixed in Grav 2.0 earlier this year but not backported until Grav 1.7.53.4, and Grav urged remaining 1.7 sites to upgrade.