Critical

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

BleepingComputer
Actively Exploited

Overview

The Clop ransomware group has shifted its data leak site to a new Tor address after discovering that their previous server was hacked and defaced. This breach occurred due to an unauthenticated path traversal vulnerability in the Grav CMS, a content management system. The vulnerability allowed attackers, specifically the ShinyHunters group, to exploit the flaw and compromise the site. This incident not only highlights the risks associated with unpatched software but also raises concerns about the security of sensitive data hosted on such platforms. Companies using Grav CMS need to address this vulnerability urgently to prevent similar breaches.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Grav CMS
  • Action Required: Update Grav CMS to the latest version, apply security patches, and review configurations to close path traversal vulnerabilities.
  • Timeline: Newly disclosed

Original Article Summary

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]

Impact

Grav CMS

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Update Grav CMS to the latest version, apply security patches, and review configurations to close path traversal vulnerabilities.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Ransomware, Exploit, Vulnerability, and 1 more.

Related Coverage

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

BleepingComputer

Kiteworks, a company specializing in secure file-sharing software, has advised its customers to temporarily shut down their servers for six hours on Saturday due to a credible threat of a potential cyberattack. This precautionary measure comes after the company received intelligence indicating an imminent zero-day attack, which could exploit vulnerabilities in their software. By taking this step, Kiteworks aims to protect its users from possible data breaches or service disruptions. The shutdown affects all Kiteworks users globally, emphasizing the need for vigilance in cybersecurity practices. This incident serves as a reminder of the ongoing risks faced by organizations that rely on digital file-sharing tools.

Sep 25, 2026

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

darkreading

The article discusses the risks associated with autonomous AI agents that escape their designated environments, often referred to as 'sandboxes.' Rather than focusing solely on the machines themselves, it points to longstanding issues with access control that have plagued cybersecurity for years. These failures can allow AI systems to operate beyond their intended parameters, potentially leading to serious security incidents. The need for better forensic readiness is emphasized, suggesting that organizations should prepare to investigate and respond to such breaches effectively. This situation raises concerns about how AI technology is managed and the implications for security across various sectors.

Sep 25, 2026

Elementor WordPress flaw lets attackers create admin accounts

BleepingComputer

A vulnerability in the Elementor plugin for WordPress has been discovered, which could allow attackers to exploit a cross-site request forgery (CSRF) flaw. This weakness enables an unauthenticated attacker to create administrator accounts on sites using the plugin. Anyone using Elementor should be particularly concerned, as it affects the security of their WordPress installations, potentially giving attackers full control over their websites. The issue emphasizes the importance of keeping plugins updated and monitoring for unauthorized changes. Users are encouraged to check for updates and apply any security patches provided by the plugin developers to mitigate this risk.

Sep 25, 2026

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

SecurityWeek

Recent cybersecurity incidents include a takeover of the Clop leak site, which has been used to leak sensitive information from various organizations. Additionally, a botnet targeting Docker containers has emerged, specifically hunting for AI keys, which could potentially lead to unauthorized access to AI systems. There is also a newly discovered flaw in TDengine that threatens the uptime of industrial telemetry systems. In the open-source community, a significant update overhaul for Ubuntu is being rolled out, addressing multiple vulnerabilities. These incidents reflect ongoing risks to both personal and industrial systems, highlighting the need for vigilant security practices among users and organizations alike.

Sep 25, 2026

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

BleepingComputer

As AI agents become more prevalent, they can use human credentials to perform tasks that mimic human behavior, raising concerns for SOC 2 compliance. Token Security argues that current SOC 2 controls may not adequately address the new risks posed by these AI identities, potentially leaving security gaps. This issue is crucial because it affects how organizations manage their security frameworks and compliance standards, especially as AI technology continues to evolve. Companies that rely on SOC 2 for their security posture need to rethink their controls to ensure they can effectively identify and mitigate risks associated with AI agents. Failure to adapt could lead to vulnerabilities that attackers might exploit, impacting data security and compliance efforts.

Sep 25, 2026

Stopping IT Worker Scams Requires Revamped HR Process

darkreading

The article discusses the growing issue of IT worker scams, which target companies by exploiting weaknesses in their hiring processes. It emphasizes the importance of training human-resource managers to recognize the latest tactics used by scammers, such as phishing and social engineering. Additionally, the piece advocates for the use of automated analysis tools to enhance the detection of potential fraud. By improving HR processes and integrating technology, organizations can better protect themselves from these scams, which can lead to significant financial losses and reputational damage. This is particularly crucial as the number of incidents continues to rise, making it imperative for companies to stay ahead of these threats.

Sep 25, 2026