CuraSec

Act active

ShinyHunters exploit Grav CMS path traversal to breach Clop leak site

2026-09-26 14:58 UTC · BleepingComputer · read the source ↗ #grav-cms#path-traversal#shinyhunters
  • Engineer — Act: An unauthenticated path traversal in Grav CMS was exploited in the wild — if you run Grav CMS on any public-facing server, audit your version and apply the latest patch immediately to close this pre-auth attack surface.
  • SOC/IR — Learn: Confirms ShinyHunters actively weaponizes web CMS vulnerabilities, but the item provides no IOCs or ATT&CK-mappable TTPs applicable to enterprise defenses — useful actor context, no hunt action required.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.