security1 publisher
ShinyHunters breached Clop's leak site through an unpatched Grav path traversal flaw
ShinyHunters took over Clop's Tor leak site by exploiting CVE-2026-42608, an unauthenticated path traversal flaw in Grav CMS. The fix reached the still-popular Grav 1.7 branch only after the breach, in release 1.7.53.4.
Publishers:bleepingcomputer.com
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives62
- Confidence66