Ransomware

Clop ransomware gang moves to new server after Grav CMS vulnerability exploited

As reported by Bleeping Computer, the Clop ransomware gang has relocated its data leak site to a new Tor address following a security breach of its previous server, which was defaced by the ShinyHunters extortion group. The breach exploited an unpatched Grav CMS vulnerability.

ShinyHunters claimed to have stolen source code, server logs, and private keys from the Clop server, subsequently demanding a ransom. Clop has denied any relationship with ShinyHunters and downplayed the significance of the stolen data, stating the compromised server contained only content and no sensitive operational or financial information. Grav CMS confirmed the vulnerability, identified as CVE-2026-42608, is an unauthenticated path traversal flaw in its core system.

While the issue was fixed in Grav 2.0, it had not been backported to the older 1.7 branch, which Clop was using. Grav has since released an updated version, 1.7.53.4, to address the vulnerability for users still on the 1.7 branch.

Source: Bleeping Computer

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds