LIVE · cybersecurity feed
Live wire
CVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEs
ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]

zeroday.news ·

The ShinyHunters cybercrime group has claimed responsibility for breaching and defacing the data leak site operated by the Clop ransomware gang. The attack, which began on a Friday night, involved defacing Clop's Tor-based site with ASCII art and a message, and ShinyHunters alleges it also stole server data and private keys for Clop's onion service.

ShinyHunters stated that the initial breach exploited an unauthenticated file upload vulnerability in Grav CMS, the content management system used by Clop. This allowed them to upload a text file containing a warning to Clop and a link to ShinyHunters' own leak site. Hours later, the Clop site was completely defaced, displaying an Umbreon Pokémon ASCII art, which is ShinyHunters' emblem, along with the message "rooting your systems since '19 ;)" and another link to their site. The defaced page was reportedly still being served from Clop's infrastructure.

ShinyHunters claims to have gained full access to the Clop server, alleging the theft of source code, Grav CMS plugins, system logs, and other data. Specifically, they mentioned downloading all files from the `/var/log` directory, which could contain sensitive information like system activity and authentication records. A significant claim made by ShinyHunters is the acquisition of Clop's Tor onion service private keys. If these keys are valid, ShinyHunters could potentially operate a Tor site using Clop's existing onion address on their own servers. While the defacement and the initial file upload have been independently confirmed, the claims of data theft, including server logs, source code, and private keys, remain unverified by independent parties.

ShinyHunters has indicated its intention to extort Clop, planning to issue a message on its own leak site instructing the ransomware group to make contact within 72 hours. The Umbreon artwork used in the defacement is consistent with previous defacements claimed by ShinyHunters, such as the HackForums website in August 2020.

This attack is reportedly a retaliatory measure stemming from an ongoing feud between the two cybercrime groups. ShinyHunters alleges that a Clop representative made threats to identify and harm their members after ShinyHunters disrupted a Clop data theft campaign. The dispute reportedly originated during Clop's 2025 Oracle E-Business Suite data theft campaign, which exploited multiple vulnerabilities, including a zero-day flaw identified as CVE-2025-61882.

During that period, a group including ShinyHunters, operating under the name "Scattered Lapsus$ Hunters," leaked a proof-of-concept exploit that Oracle later confirmed matched one used in Clop's attacks. ShinyHunters asserted that this exploit originally belonged to them and was obtained by Clop without authorization. Tensions escalated, with ShinyHunters claiming a Clop representative sent a personal message containing threats, including a translated Russian quote about having more money and intending to kill. These allegations of threats and the origin of the exploit have not been independently verified.

ransomwarebreach
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

CVE-2026-58138critical

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

ai

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

nation-state

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

security

Flock Offers Employees Buyouts as Customers Flee

As dozens of cities end contracts for its controversial license plate readers, Flock is rolling out a voluntary severance program, WIRED has learned.