As reported by BleepingComputer, the Clop ransomware gang's data leak site was compromised and defaced by the ShinyHunters extortion group through an unpatched Grav CMS vulnerability — an unauthenticated path traversal flaw in the CMS's form upload handling. The incident is a striking demonstration of criminal-on-criminal cyber operations, but more importantly, it underscores a pervasive and ongoing risk to legitimate Grav CMS deployments worldwide.

Security Impact: As reported by BleepingComputer, the Clop ransomware gang's data leak site was compromised and defaced by the ShinyHunters extortion group through an unpatched Grav CMS vulnerability — an unauthenticated path traversal flaw in the CMS's form upload handling.

Vulnerability Profile

AttributeDetail
CVE (likely)CVE-2024-28120 — path traversal in Grav CMS file upload handling (not explicitly named in source; matched on technical details)
SeverityHigh (unauthenticated, remote code execution potential via arbitrary file write)
Affected ProductGrav CMS versions prior to 1.7.45 (compromised server confirmed running 1.7.43)
VendorGrav CMS (getgrav.org)
Patch StatusFixed in Grav CMS 1.7.45+ — Clop's installation was unpatched
Active ExploitationConfirmed — Grav CMS has validated the exploitation details shared by ShinyHunters
Attack VectorUnauthenticated POST parameters manipulating temporary upload directory paths without validation

Why This Matters Beyond the Irony

The schadenfreude of a ransomware gang being extorted is undeniable, but security teams should look past the spectacle. The real story is that an unauthenticated path traversal vulnerability in a popular flat-file CMS was trivially exploitable and remained unpatched on an internet-facing server — exactly the posture many legitimate organizations find themselves in with secondary or forgotten web properties.

The compromised server ran Grav CMS 1.7.43 — a version at least two years out of date. This wasn't a zero-day; it was neglect.

Grav CMS is widely deployed for documentation sites, marketing pages, blogs, and internal portals. Its flat-file architecture makes it appealing for lightweight deployments, but it also means these instances are frequently stood up and forgotten — rarely enrolled in centralized patch management or vulnerability scanning programs. Attackers know this. ShinyHunters simply scanned for a known flaw and found an opportunistic target.

Broader Implications

  • Threat actor operational security is deteriorating. Ransomware gangs running leak sites on unpatched CMS software reveals a growing arrogance — or staffing shortage — in criminal operations. This creates intelligence opportunities for law enforcement and rival groups alike.
  • Tor onion private keys are high-value targets. ShinyHunters' claim of stealing Clop's onion service private keys, if accurate, means the old onion address could be impersonated indefinitely. Organizations monitoring ransom group infrastructure should flag any legacy Clop onion addresses as potentially compromised.
  • Criminal-on-criminal attacks will escalate. As more gangs compete for victims and extortion revenue, expect additional groups to target each other's infrastructure for financial gain, disruption, or reputational dominance.
  • Path traversal remains a top exploitation vector. Despite being a well-understood class of vulnerability, path traversal continues to produce high-impact compromises because input validation on file handling remains inconsistently implemented across CMS platforms.

Who Is at Risk

Any organization running Grav CMS versions below 1.7.45 on an internet-facing server is directly exposed. The vulnerability is unauthenticated, meaning no credentials are required. High-risk deployments include:

Who Is at Risk
Documentation and knowledge base sites managed by engineering teams outside IT oversight
Legacy marketing or landing pages that receive no regular maintenance
Internal portals exposed via reverse proxies or VPNs that may be reachable through misconfigurations
Any Grav instance with enabled form functionality (the attack vector targets form upload handling)

Shield53 Recommendations

Immediate Actions

  • Patch Grav CMS immediately to version 1.7.45 or later. Verify via the admin dashboard or by checking system/config/system.yaml for the current version.
  • Audit all Grav installations across your environment, including forgotten dev/staging instances and shadow IT deployments. Use asset inventory tools to scan for Grav fingerprints.
  • Disable form upload functionality on any Grav instance that does not require it as a temporary mitigation while patching is scheduled.
  • Restrict write permissions on the Grav web root to prevent arbitrary file writes from escalating to code execution. Ensure the web server process cannot write to executable directories.
  • Deploy a WAF rule blocking POST requests containing path traversal sequences (../, ..\, encoded variants) in form-related parameters.

Strategic Actions

  • Enroll all CMS platforms — including flat-file and headless systems — into centralized vulnerability management and patch SLAs. Treat secondary web properties with the same rigor as primary applications.
  • Implement file integrity monitoring on web roots to detect unauthorized file creation or modification indicative of path traversal exploitation.
  • Hunt for compromise indicators if you have Grav instances that were unpatched: check for unexpected files in upload directories, suspicious PHP files in non-executable paths, and anomalous POST requests in access logs targeting form endpoints.
  • Monitor threat actor infrastructure shifts. Clop's migration to a new onion address means threat intelligence feeds and blocklists must be updated. Treat the old address as untrusted.

The lesson here is not that criminals got hacked — it's that an unpatched CMS on an exposed server is a liability regardless of who operates it. If a ransomware gang with millions in extortion revenue can't maintain basic patch hygiene on a single server, the same gap likely exists somewhere in your environment. Find it before someone else does.