Act
active
ShinyHunters exploit Grav CMS path traversal to breach Clop leak site
- Engineer — Act: An unauthenticated path traversal in Grav CMS was exploited in the wild — if you run Grav CMS on any public-facing server, audit your version and apply the latest patch immediately to close this pre-auth attack surface.
- SOC/IR — Learn: Confirms ShinyHunters actively weaponizes web CMS vulnerabilities, but the item provides no IOCs or ATT&CK-mappable TTPs applicable to enterprise defenses — useful actor context, no hunt action required.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.