As reported by Bleeping Computer, the Clop ransomware gang has relocated its data leak site to a new Tor address following a security breach of its previous server, which was defaced by the ShinyHunters extortion group. The breach exploited an unpatched Grav CMS vulnerability.ShinyHunters claimed to have stolen source code, server logs, and private keys from the Clop server, subsequently demanding a ransom. Clop has denied any relationship with ShinyHunters and downplayed the significance of the stolen data, stating the compromised server contained only content and no sensitive operational or financial information. Grav CMS confirmed the vulnerability, identified as CVE-2026-42608, is an unauthenticated path traversal flaw in its core system.While the issue was fixed in Grav 2.0, it had not been backported to the older 1.7 branch, which Clop was using. Grav has since released an updated version, 1.7.53.4, to address the vulnerability for users still on the 1.7 branch.Source: Bleeping Computer
Ransomware
Clop ransomware gang moves to new server after Grav CMS vulnerability exploited
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
