Find notable cyber news and cases, enriched with sources, timelines, and signals.

Clop leak site hit by network compromise linked to ShinyHunters

Incident
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The Clop leak site was breached and defaced by ShinyHunters, forcing the operation to shift to a new Tor address. The compromise was tied to Grav CMS 1.7.43 and an unpatched path traversal flaw now identified as CVE-2026-42608. The attacker later claimed to have taken source code, plugins, server logs, and private keys and threatened to leak them for payment. Clop said the old onion address would stay online only temporarily before retirement.

Related Happenings

Grav CMS path traversal (CVE-2026-42608)

Vulnerability
H score8 First: 25.09.2026 23:57 Last: 25.09.2026 23:57 Sources 1

How related: Grav said the flaw is tracked as CVE-2026-42608 and is a path traversal vulnerability that was privately reported and fixed in Grav 2.0 (2.0.0-beta.2) earlier this year, with the advisory published on April 27.

About this happening: Grav CMS 1.7.x installations were exposed to CVE-2026-42608, an unauthenticated path traversal flaw in form upload handling that could create unsafe upload paths and w...

Clop (aka Cl0p) hit by network compromise linked to ShinyHunters

Incident
H score77 First: 19.09.2026 16:48 Last: 19.09.2026 16:48 Sources 1

About this happening: ShinyHunters breached and defaced Clop’s Tor-based data leak site on 18 September, replacing it with its own message and link after an alleged Grav CMS upload flaw...

Chinese state-sponsored campaign to hijack Notepad++ update traffic

Campaign
H score32 First: 02.02.2026 16:53 Last: 02.02.2026 16:53 Sources 1

About this happening: A months-long campaign hijacked Notepad++ update traffic, selectively sending some users to malicious servers and threatening the integrity of software updates. The operat...

Timeline

  1. 25.09.2026 23:57 2 articles · 0h ago

    ShinyHunters breaches Clop leak site through Grav CMS path traversal flaw

    Initial Disclosure

    ShinyHunters breached and defaced Clop's Tor leak site after exploiting an unpatched Grav CMS path traversal flaw on a server Clop said was running Grav CMS 1.7.43. The group claimed it stole source code, Grav CMS plugins, server logs, and Clop's Tor onion private keys, then issued a ransom demand. Clop moved the leak site to a new onion address and said the old domain would stay online temporarily, while Grav later confirmed the flaw as CVE-2026-42608, said it had been fixed in Grav 2.0 and backported to Grav 1.7.53.4, and noted that the vulnerable 1.7 branch had not been updated.

    Show sources