ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

Summary

The Clop ransomware gang's data leak site was compromised and defaced due to an unpatched Grav CMS path traversal vulnerability. The attackers reportedly exploited this flaw to gain access to the server before the Clop group could update their systems. ShinyHunters is allegedly behind the hack, which forced Clop to relocate their leak site to a new Tor address.

IFF Assessment

FOE

This article details a successful attack on a ransomware group's infrastructure, indicating an ongoing conflict and evolving threat landscape that could impact defensive efforts.

Severity

8.8 High (AI Estimated)

The vulnerability is an unauthenticated path traversal flaw in Grav CMS, which allows attackers to read and potentially write files on the server without authentication. This leads to a high CVSS score due to the ease of exploitation and significant impact on confidentiality and integrity.

Defender Context

This incident highlights the importance of promptly patching Content Management Systems (CMS) like Grav, even for criminal organizations. Defenders should be aware of path traversal vulnerabilities as they can be exploited to access sensitive information or compromise servers, and ensure their own web applications and services are regularly patched and scanned for such flaws.

Read Full Story →