Nominet, the official .uk domain registry and one of the largest global country code registries, has confirmed a cyberattack exploiting a critical zero-day vulnerability in Ivanti’s VPN software, tracked as CVE-2025-0282.
The breach, discovered in early January 2025, marks the first confirmed case of exploitation of this critical vulnerability. CVE-2025-0282 is a stack-based buffer overflow flaw with a CVSS score of 9.0, enabling unauthenticated remote code execution. It impacts Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways.
Nominet detected suspicious network activity linked to the Ivanti VPN software on January 8, 2025. The company disclosed that attackers gained access through a vulnerability in the VPN software, used for remote access by its employees.
- No Data Theft Identified: Nominet assured customers that no evidence of data theft, backdoors, or unauthorized access has been found.
- Safeguards Implemented: Access via VPN has been restricted, and external cybersecurity experts, along with the UK’s National Cyber Security Centre (NCSC), are assisting in the investigation.
Cybersecurity researchers have linked the exploitation of this flaw to UNC5337, a Chinese state-sponsored hacking group, also associated with attacks on Ivanti products in early 2024. These attackers have deployed a mix of known and new malware strains, including Spawn, Dryhook, and Phasejam.
Ivanti released patches for vulnerable Connect Secure versions on January 8, 2025, with fixes for Policy Secure and Neurons for ZTA Gateways scheduled for release on January 21.
Cybersecurity firm Censys reported 33,542 exposed Ivanti Connect Secure instances worldwide, with significant exposure in the United States and Japan.
Organizations using Ivanti products are advised to:
- Apply patches immediately.
- Investigate potential compromises.
- Enhance monitoring to mitigate risks.
Nominet’s swift response and transparency highlight the critical importance of robust cybersecurity measures in protecting essential infrastructure and customer trust.














Comments