ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
Overview
The Clop ransomware group has shifted its data leak site to a new Tor address after discovering that their previous server was hacked and defaced. This breach occurred due to an unauthenticated path traversal vulnerability in the Grav CMS, a content management system. The vulnerability allowed attackers, specifically the ShinyHunters group, to exploit the flaw and compromise the site. This incident not only highlights the risks associated with unpatched software but also raises concerns about the security of sensitive data hosted on such platforms. Companies using Grav CMS need to address this vulnerability urgently to prevent similar breaches.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Grav CMS
- Action Required: Update Grav CMS to the latest version, apply security patches, and review configurations to close path traversal vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]
Impact
Grav CMS
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Update Grav CMS to the latest version, apply security patches, and review configurations to close path traversal vulnerabilities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Ransomware, Exploit, Vulnerability, and 1 more.