ShinyHunters Hacks Clop Ransomware Leak Site via Grav CMS Flaw, Demands Ransom
On September 19, 2026, hacking group ShinyHunters defaced and compromised the dark web leak site operated by the Clop ransomware gang, exploiting an unauthenticated file upload vulnerability in Grav CMS. The attackers claim to have stolen the site's source code, system logs from /var/log, and the private cryptographic keys for Clop's Tor onion service. ShinyHunters issued a 72-hour ultimatum to Clop, threatening to extort the ransomware group — a move the attackers framed as retaliation for Clop allegedly stealing their exploit and issuing violent threats. The conflict stems from Clop's October 2025 mass exploitation campaign targeting Oracle E-Business Suite via CVE-2025-61882, which ShinyHunters claims was based on their own original exploit. BleepingComputer independently confirmed the defacement, though the data theft claims remain unverified.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in