vulnerabilitydata-breachransomware

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

September 26, 2026

Back to all posts

Source: BleepingComputer

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.
vulnerabilitydata-breachransomware

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment