INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Exploited Grav CMS Path Traversal Flaw to Hacked Clop

| 2026-09-25 20:57 CRITICAL LOW DATA BREACH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Clop ransomware gang's data leak site was breached by the ShinyHunters extortion gang on an unpatched Grav CMS flaw, specifically a path traversal vulnerability in form upload handling. The attack occurred earlier this month and involved exploiting values supplied through POST parameters when creating temporary directories without validation. As a result of the breach, Clop's server contained only content with no valuable operational or financial data, according to the Russian ransomware gang. ShinyHunters claimed they stole source code, Grav CMS plugins, server logs, and private keys used by Clop's Tor onion service from the compromised server. The attack has been resolved as the Clop leak site was moved to a new Tor address after being defaced with a full-page display of its Umbreon Pokémon logo.
Technical Mitigations AI-generated
• SanitizeId() function in Grav CMS 2.0 (2.0.0-beta.2) to prevent path traversal attacks • Update to Grav CMS version 1.7.43 or later, as the vulnerability is tracked as CVE-2026-42608 and has been fixed in newer versions • Validate form-related POST parameters before creating temporary upload directories
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters UmbreonUmbreon CVE-2026-42608CVE-2026-42608
Target & Sectors
RU
Incident Timeline
‎April 27
Threat actors exploited a privately reported path traversal vulnerability in Grav CMS, tracked as CVE-2026-42608, which was fixed in version 2.0.0-beta.2 earlier this year.
vulnerability CVE-2026-42608
infrastructure 2.0
infrastructure 2.0.0-beta
general_metric 2.0 Grav
‎2026/09/24
Threat actors exploited a Grav CMS path traversal flaw to target the Clop leak site, which was later patched by releasing version 1.7.53.4 of the software on September 24, 2026.
infrastructure 1.7
general_metric 1.7 older branch
infrastructure 1.7.53
‎2026/09/25
ShinyHunters exploited an unauthenticated path traversal vulnerability in Grav CMS version 1.7.43 to breach the Clop leak site, which was later defaced with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.
threat_actor ShinyHunters
organisation Tor
organisation BleepingComputer
infrastructure 2.0
infrastructure 1.7
infrastructure 1.7.43
infrastructure 1.7.53
infrastructure 7.3.0
organisation POST
organisation CMS
organisation NFL
organisation CHANEL
Tactical Metrics
Metrics
infrastructure
‎2.0
Software Version
Metrics
infrastructure
‎2.0.0-beta
Software Version
Metrics
infrastructure
‎1.7
Software Version
Metrics
infrastructure
‎1.7.43
Software Version
Metrics
infrastructure
‎1.7.53
Software Version
Metrics
infrastructure
‎7.3.0
Software Version
Intelligence Sources