Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Maria Ressa: Big Tech Is Destroying Democracy. Here’s How to Fight Back.

    September 26, 2026

    White House blocks CNN from Air Force One in latest escalation with news media | Trump administration

    September 26, 2026

    Meta makes the Muse filesystem even more accessible

    September 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Maria Ressa: Big Tech Is Destroying Democracy. Here’s How to Fight Back.
    • White House blocks CNN from Air Force One in latest escalation with news media | Trump administration
    • Meta makes the Muse filesystem even more accessible
    • In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
    • North Korean Hackers Linked To $388M Bitget Hack
    • Biodiversity credits shouldn’t copy the carbon market playbook (commentary)
    • Facebook found liable as TikTok settles for $100m over user safety | Social Media News
    • At Meta Connect, the company’s smart glasses were everywhere
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 26, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

    The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.

    Clop data leak site defaced by ShinyHunters
    Clop data leak site defaced by ShinyHunters

    ShinyHunters later claimed on its own data leak site that it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop’s Tor onion service. The group then issued a ransom demand, threatening to leak the stolen files if Clop did not pay.

    Clop has now announced a new onion address and says the old domain will remain accessible temporarily before being retired.

    Clop also denied having any relationship or ongoing negotiations with ShinyHunters.

    “We do not know them, we have never worked with them, and at the moment we are not in contact with them; furthermore, we have not provided them with any information, nor will we do so—either now or in the future,” Clop told BleepingComputer.

    When asked whether the group had determined how ShinyHunters breached the leak site, Clop confirmed that its Grav installation had not been fully updated.

    However, the Russian ransomware gang disputes ShinyHunters’ claims that valuable operational or financial data was stolen from the compromised server.

    “We didn’t update the Grav plugin — though it happened eventually—but the server contained nothing but content (meaning there was absolutely no data or financial activity there, nor could there have been). Therefore, their claim is worthless—as are their words,” Clop said.

    While Clop says they are not communicating with the other threat actors, they have since been quietly removed from ShinyHunters’ data leak site, which commonly happens when negotiations are taking place.

    When questioned about the removal, ShinyHunters told BleepingComputer that they did not want to answer any further questions about this.

    Grav confirms flaw used in attack

    Grav CMS has now confirmed that the vulnerability and exploitation details shared by ShinyHunters with BleepingComputer are accurate.

    ShinyHunters told BleepingComputer that the compromised Clop server was running Grav CMS 1.7.43 and claimed it exploited an unauthenticated file upload flaw in Grav’s form upload handling.

    According to the threat actor, the vulnerable code used values supplied through form-related POST parameters when creating temporary upload directories without first validating them as safe filesystem path components.

    The group specifically identified the __unique_form_id__ parameter and said the value was added into a temporary path like:

    
    tmp/forms//

    ShinyHunters claimed that by supplying directory traversal sequences, such as ../../../shhq, for the unique form identifier, it could cause Grav to create an upload path outside the intended tmp/forms directory.

    The uploaded file could then be written elsewhere under the Grav installation.

    After BleepingComputer shared the technical details with Grav, the CMS developers confirmed that the threat actor’s description was accurate.

    “Yes, it’s a legitimate flaw, and the threat actor’s description is accurate,” Grav told BleepingComputer.

    Grav said the flaw is tracked as CVE-2026-42608 and is a path traversal vulnerability that was privately reported and fixed in Grav 2.0 (2.0.0-beta.2) earlier this year, with the advisory published on April 27.

    The fix added a sanitizeId() function that only accepts identifiers matching the allowlist:

    
    [A-Za-z0-9,_-]{1,64}

    Grav confirmed that this sanitization method is the same mitigation described by ShinyHunters to BleepingComputer.

    However, while current Grav 2.x releases had already been protected, the fix had not been backported to the older Grav 1.7 branch, leaving installations such as Clop’s 1.7.43 deployment vulnerable.

    “The gap was the 1.7 line,” Grav told BleepingComputer. “Grav 2.0 is the current major version, but plenty of sites are still on 1.7, and that fix hadn’t been backported there yet.”

    After BleepingComputer shared the exploitation details with Grav, the developers backported the fix to the 1.7 branch and released Grav 1.7.53.4 yesterday.

    Grav also clarified that the vulnerability is located in Grav core rather than the Form plugin.

    “The bug lives in Grav core, not the Form plugin, so the Form plugin version (7.3.0 in their example) doesn’t change whether a site is vulnerable. It’s the core version that matters,” Grav said.

    Grav is urging anyone still running the 1.7 branch to upgrade to version 1.7.53.4. Users of current Grav 2.x releases have already been protected from the vulnerability for months.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Clop CMS Flaw Grav Hacked leak path ShinyHunters site traversal
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    Kiteworks urges 6-hour server shutdown over potential zero-day attacks

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Maria Ressa: Big Tech Is Destroying Democracy. Here’s How to Fight Back.

    September 26, 2026

    White House blocks CNN from Air Force One in latest escalation with news media | Trump administration

    September 26, 2026

    Meta makes the Muse filesystem even more accessible

    September 26, 2026

    In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    September 26, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Maria Ressa: Big Tech Is Destroying Democracy. Here’s How to Fight Back.

    September 26, 2026

    White House blocks CNN from Air Force One in latest escalation with news media | Trump administration

    September 26, 2026

    Meta makes the Muse filesystem even more accessible

    September 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.