Trusence Technology, daily
Last updated 26 September 2026 Türkçe
← All stories
Security

ShinyHunters exploit Grav flaw to deface Clop leak site

The breach forced Clop onto a new onion address while Grav rushed a security fix for older sites.

ShinyHunters breached and defaced Clop’s Tor leak site by exploiting an unpatched Grav CMS path-traversal flaw; Clop has moved to a new onion address and plans to retire the old one after a brief overlap. ShinyHunters says it took material from the server, but Clop says the host held only site content, not operational or financial data. Grav identified the bug as CVE-2026-42608, a core-level vulnerability fixed for Grav 2.0 in 2.0.0-beta.2, with an advisory published on April 27. Clop’s Grav 1.7.43 installation remained exposed because the fix had not reached the 1.7 branch. Grav has since backported the repair in version 1.7.53.4 and urges 1.7 users to upgrade; current 2.x releases were already protected.

Why it matters

The incident shows how a missed backport in widely used software can expose even security-focused operators. Clop is shifting to a new onion site while insisting no critical data was taken, but the breach still undercuts its image of control. For anyone running Grav 1.7, the path-traversal bug and its late fix highlight the risks of lagging on updates and the importance of moving to the patched 1.7.53.4 release or newer 2.x versions.

Sources

  • BleepingComputer