
ShinyHunters exploited CVE-2024-21640 in Clop's dark web leak site, escalating from CMS access to steal victim payment records and operational data. The attackers now threaten to re-extort companies that previously paid Clop ransoms. Runtime segmentation of management infrastructure helps limit such lateral movement scenarios. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/shinyhunters-hacked-clop-ransomware-victims-2026
