MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-25 · via BleepingComputer

Clop moves leak site after ShinyHunters exploits Grav CMS bug

Image via BleepingComputer
Image via BleepingComputer

Clop moved its data leak site to a new Tor address after ShinyHunters defaced the old one through an unpatched Grav CMS path traversal bug. ShinyHunters claimed it stole source code, plugins, logs, and Tor private keys, and demanded payment; Clop denied valuable operational or financial data was taken and said it had no dealings with the group. Grav confirmed the vulnerability details.

Expanded Detail

Clop shifted its Tor leak portal after ShinyHunters replaced the original page with a defacement carrying an Umbreon logo and a link to its own site. ShinyHunters claimed it took code, add-ons, server records, and keys tied to the Tor hidden service, then asked for payment.

Grav later confirmed the exploit account. The flaw, CVE-2026-42608, is an unauthenticated traversal bug in form upload handling; a manipulated __unique_form_id__ value could write outside the intended temporary folder. A fix landed in Grav 2.0.0-beta.2, with an April 27 advisory and a sanitizeId() allowlist.

Context

The breach may affect victims whose data is already held by Clop, as uncertainty over the leak site's integrity could complicate extortion negotiations and monitoring. Organizations running Grav CMS could face similar path traversal attacks if unpatched. Security researchers and law enforcement may find threat-actor communications harder to track if onion addresses change or are impersonated. The incident could also erode trust in underground leak portals, though its practical impact remains unclear.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw.” Browse more stories.