ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
Clop moved its data leak site to a new Tor address after its old server was defaced by ShinyHunters through an unpatched Grav CMS path traversal flaw. Grav confirmed the issue as CVE-2026-42608 and released a fix for the older 1.7 branch in version 1.7.53.4. #Clop #ShinyHunters #Grav #CVE202642608

Keypoints

  • Clop relocated its Tor leak site after the compromise.
  • ShinyHunters defaced the site and claimed to steal files and private keys.
  • The attack abused an unauthenticated Grav CMS path traversal flaw.
  • Grav confirmed the bug as CVE-2026-42608 and said the report was accurate.
  • Grav backported the fix to 1.7.53.4 and urged 1.7 users to upgrade.

Read More: https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/