Download Privacy Needle App

Type to search

Cybersecurity

ShinyHunters Exploits Grav CMS Flaw to Breach Clop Leak Site

Share

The Clop ransomware gang has moved its data leak site to a new Tor address following a successful breach by the ShinyHunters extortion group. The intrusion was facilitated by an unpatched path traversal vulnerability in the Grav CMS software.

ShinyHunters defaced the Clop leak site, replacing its content with an Umbreon Pokémon logo and a link to the attackers’ own data leak platform. The threat actors claimed to have exfiltrated source code, server logs, Grav CMS plugins, and the private keys used by Clop for its Tor onion service. They subsequently issued a ransom demand, threatening to release the stolen data if Clop failed to pay.

Clop has confirmed that its Grav installation was not fully updated, though the group disputed the severity of the theft. Clop stated that the compromised server contained only website content and lacked any sensitive financial or operational data. The gang also denied any relationship or ongoing negotiations with ShinyHunters.

Technical details of the Grav CMS exploit

The vulnerability, identified as CVE-2026-42608, is an unauthenticated path traversal flaw located within the Grav core. The exploit targets the __unique_form_id__ parameter used in form upload handling. By supplying directory traversal sequences, such as ../../../, attackers could cause the CMS to create upload paths outside of the intended temporary directory, allowing files to be written to other locations within the installation.

Grav developers confirmed the accuracy of the exploitation details. While a fix had been integrated into the Grav 2.x major release earlier this year, the patch had not been backported to the 1.7 branch, leaving older installations like Clop’s vulnerable.

Mitigation and updates

Following the exploitation, developers backported the security fix to the 1.7 branch. Users currently running Grav 1.7.x are urged to upgrade to version 1.7.53.4 immediately to remediate the flaw. Those already using Grav 2.x releases have been protected by existing sanitisation measures for several months.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.