{"ok":true,"trend":{"id":285155,"platform":"news","region":"global","key":"clop ransomware gang moves to new server after grav cms vulnerability exploited","title":"Clop ransomware gang moves to new server after Grav CMS vulnerability exploited","url":"https://news.google.com/rss/articles/CBMirgFBVV95cUxNN2hFNUZkRndfeGRxSjZvU1VJY0c4S2tyNW90cXBGSEc3QklLZTBIR05ZNDRCek44YkF6bkVKejduXzB4UWx1OEJHOUs1dVBGMXVVQVY4QWFFMmYwS1EwOFc0anMtSDRPVl9uQnZwX2E3NGNtZjNyMktTZEl0RGpYMWVVblZWdTI5MnAwcnV0VU5CcS03UzZQcVpzWXR6NWxUVUk4SUg0VnNyLUhGd0E?oc=5","first_seen":"2026-09-28T22:35:53.725880Z","last_seen":"2026-09-29T02:41:53.498544Z","last_rank":31,"peak_rank":26,"last_volume":null,"peak_volume":0,"seen_count":4,"score":26.0,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"The Clop ransomware gang has moved to new server infrastructure after exploiting a vulnerability in Grav CMS, the open-source flat-file content management system. The extortion group, known for large-scale data-theft campaigns against corporations and government agencies, is continuing operations despite the disruption. Security teams are being urged to patch Grav CMS installations and review whether their systems were targeted.","why":"Clop is one of the most aggressive ransomware groups, and each new exploitation campaign raises immediate concerns for organisations running the affected software.","tone":"neutral","entities":["Clop","Grav CMS"],"summarized_at":"2026-09-29T04:37:46.056038Z","meta":{"via":"scan","lang":"en","term":"security breach","source":"SC Media","generic":0.05,"published":"Mon, 28 Sep 2026 21:33:25 GMT"},"nw":0.57,"promo":0.02,"kind":"news_event","importance":1.69,"hidden":false,"hide_reason":null,"judged_at":"2026-09-28T22:35:55.443231Z","title_en":"Clop ransomware gang relocates servers after exploiting Grav CMS flaw","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-28T22:35:53.725880Z","rank":26,"volume":null},{"captured_at":"2026-09-28T23:57:53.036255Z","rank":28,"volume":null},{"captured_at":"2026-09-29T01:19:53.115673Z","rank":28,"volume":null},{"captured_at":"2026-09-29T02:41:53.498544Z","rank":31,"volume":null}],"posts":[{"platform":"news","url":"https://news.google.com/rss/articles/CBMirgFBVV95cUxNN2hFNUZkRndfeGRxSjZvU1VJY0c4S2tyNW90cXBGSEc3QklLZTBIR05ZNDRCek44YkF6bkVKejduXzB4UWx1OEJHOUs1dVBGMXVVQVY4QWFFMmYwS1EwOFc0anMtSDRPVl9uQnZwX2E3NGNtZjNyMktTZEl0RGpYMWVVblZWdTI5MnAwcnV0VU5CcS03UzZQcVpzWXR6NWxUVUk4SUg0VnNyLUhGd0E?oc=5","author":"SC Media","title":"Clop ransomware gang moves to new server after Grav CMS vulnerability exploited","snippet":null,"posted_at":"2026-09-28T21:33:25Z","likes":null}],"elsewhere":[],"window":"7d"}}