Follow the latest coverage, related explainers and connected technology stories.
Kiteworks lifted its precautionary warning to shut down systems after fixing a critical vulnerability in a feature used by fewer than 1% of customers, confirming that no breach or exploitation had been detected. The company has not yet disclosed details of the vulnerability or its CVE number.
The ShinyHunters group exploited a previously undocumented vulnerability in Grav CMS to breach and deface Clop’s leak site, prompting the group to move its site to a new Tor address. Grav confirmed that the flaw exists in the core and released version 1.7.53.4 to address it in the Grav 1.7 branch.
BleepingComputer confirmed that ShinyHunters hacked a leak site operated by the Clop gang after exploiting a vulnerability allegedly allowing unauthenticated file uploads. ShinyHunters says it stole the site’s server data and Tor service keys, but these claims have not been independently verified.