Clop Ransomware Gang Relocates Leak Site After Grav CMS Compromise
Unauthenticated path traversal flaw in Grav CMS used to target ransomware infrastructure

Key Takeaways
- The Clop ransomware gang moved its data leak site to a new Tor address after its previous server was compromised and defaced.
- The compromise was attributed to an unauthenticated path traversal vulnerability in Grav CMS.
- No specific CVE has been assigned to the vulnerability at the time of reporting.
- Grav CMS users should apply the latest security updates to address path traversal flaws.
- The incident demonstrates that CMS platforms can be exploited against diverse targets, including ransomware infrastructure.
Quick answers
- What happened?
- The Clop ransomware gang has moved its data leak site to a new Tor address following confirmation that its previous server was compromised and defaced through an unauthenticated path traversal vulnerability in Grav CMS. The incident highlights the risk of content management system flaws being exploited against threat actor infrastructure.
- Which products are affected?
- Grav CMS
- What should defenders do?
- Grav CMS administrators should apply the latest security updates and patches released by the Grav CMS development team. Admins should also review file permissions, disable unnecessary administrative interfaces exposed to the internet, and monitor for unauthorized file access patterns.
According to reporting by BleepingComputer, the Clop ransomware gang confirmed that its data leak site server was compromised and defaced via an unauthenticated path traversal vulnerability in Grav CMS. Following this compromise, the gang relocated its leak site to a new Tor address. The exact mechanism by which the path traversal flaw was leveraged against the Clop server has not been independently verified, but the incident underscores that content management systems remain a vector for compromise, even in threat actor environments. No specific CVE has been assigned to the flaw at the time of reporting, and Grav CMS users are advised to apply the latest security updates to mitigate path traversal risks.
Security Details
Unauthenticated path traversal vulnerability in Grav CMS used to compromise and deface a server hosting the Clop ransomware gang's data leak site. The flaw allows unauthorized access to file system paths, enabling defacement or data exposure.
Affected products
Grav CMS
Mitigation
Grav CMS administrators should apply the latest security updates and patches released by the Grav CMS development team. Admins should also review file permissions, disable unnecessary administrative interfaces exposed to the internet, and monitor for unauthorized file access patterns.
Sources
BleepingComputer
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
Sep 25, 2026 · 20:57
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




