Clop moved its data leak site to a new Tor address after its old server was defaced by ShinyHunters through an unpatched Grav CMS path traversal flaw. Grav confirmed the issue as CVE-2026-42608 and released a fix for the older 1.7 branch in version 1.7.53.4. #Clop #ShinyHunters #Grav #CVE202642608
Keypoints
- Clop relocated its Tor leak site after the compromise.
- ShinyHunters defaced the site and claimed to steal files and private keys.
- The attack abused an unauthenticated Grav CMS path traversal flaw.
- Grav confirmed the bug as CVE-2026-42608 and said the report was accurate.
- Grav backported the fix to 1.7.53.4 and urged 1.7 users to upgrade.