Select a theme from the list.
Insights

From our experts

Latest
Storm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOC
Security Insight

Clop Ransomware Gang Gets Hacked Through Its Own Outdated CMS

Clop Ransomware Gang Gets Hacked Through Its Own Outdated CMS
Photo by Antoni Shkraba on Pexels

The Clop ransomware operation moved its leak site after ShinyHunters compromised and defaced the server through an unpatched Grav CMS vulnerability. Grav confirmed that the path traversal flaw affected older 1.7 installations and released a backported fix, while claims about stolen operational data remain disputed.

News Date: 2026-09-25

The Clop ransomware operation has learned an uncomfortable lesson familiar to many of its victims: an overlooked software update can provide attackers with an opening. The group relocated its Tor-based leak site after ShinyHunters compromised and defaced the original server through a vulnerability in Grav CMS.

An Outdated Platform Created the Opening

The affected server reportedly ran Grav 1.7.43. The vulnerability, tracked as CVE-2026-42608, involved insufficient validation of a form-related identifier used when constructing temporary upload paths. By supplying directory traversal sequences, an unauthenticated attacker could potentially cause an uploaded file to be written outside its intended directory.

Grav confirmed that the technical description of the flaw was accurate. Although the issue had already been addressed in the Grav 2.x branch, the correction had not initially been backported to the older 1.7 line. Following disclosure of the exploitation details, the developers released Grav 1.7.53.4 for organizations that remain on the legacy branch.

Competing Claims Complicate the Incident

ShinyHunters claimed it obtained server logs, source code, CMS components and private keys associated with Clop's onion service. Clop acknowledged that its Grav installation was not fully updated but disputed claims that the server held valuable financial or operational information. Without independent verification, organizations should treat statements from both criminal groups cautiously.

Lessons for Legitimate Website Operators

  • Upgrade Grav 1.7 deployments to version 1.7.53.4 or move to a supported 2.x release.
  • Review web directories for unexpected files and recently created scripts.
  • Rotate exposed server, administrative and service credentials.
  • Monitor outbound connections and changes to site content or configuration.

In my view, the wider lesson is not that cybercriminals are uniquely careless. It is that internet-facing content systems remain attractive entry points regardless of who operates them. Security teams often prioritize business applications while treating a website or publishing platform as a low-value asset. That assumption becomes dangerous when the same server stores private keys, logs, credentials or administrative tools.

The incident also illustrates how quickly vulnerability risk changes after confirmed exploitation. A flaw that appears to affect a relatively modest CMS can suddenly become urgent when attackers demonstrate a practical path to server compromise. Asset discovery, branch-specific patch tracking and rapid credential rotation are therefore just as important as installing the eventual update.

Talk to our team →

Latest

Storm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutSep 27, 2026One Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftSep 27, 2026Clop Ransomware Gang Gets Hacked Through Its Own Outdated CMSSep 27, 2026Microsoft Pushes Data-Loss Prevention Into the Path of Shadow AISep 26, 2026Dormant GitHub Actions Reawakened With Their Malicious Payloads IntactSep 26, 2026Kiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksSep 26, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path