ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Nominet confirms network breach via Ivanti VPN Zero-Day vulnerability

Linked InXFacebook
bookmark_borderSave to Library

Nominet, the official registry for .UK domains and one of the world’s largest country code registries, has confirmed a network breach that occurred two weeks ago. The attack exploited a critical Ivanti VPN zero-day vulnerability, highlighting significant cybersecurity challenges faced by critical infrastructure operators.

 

Nominet manages over 11 million .uk, .co.uk, and .gov.uk domains and other top-level domains such as .cymru and .wales. Until September 2024, it operated the UK’s Protective Domain Name Service (PDNS) for the National Cyber Security Centre (NCSC), safeguarding over 1,200 organizations and 7 million users.

 

The breach was linked to Ivanti Connect Secure, a third-party VPN software enabling remote access to Nominet’s systems. The vulnerability, tracked as CVE-2025-0282, was actively exploited by attackers. Upon detecting suspicious activity, Nominet promptly reported the incident to the NCSC and other authorities, restricted VPN access, and initiated an internal investigation.

 

In a customer notice shared with BleepingComputer, Nominet stated: “We currently have no evidence of data breach or leakage. We already operate restricted access protocols and firewalls to protect our registry systems. Domain registration and management systems continue to operate as normal.”

 

Despite assurances, the investigation is ongoing, and no backdoors or malicious implants have been found on Nominet’s systems so far.

 

The Ivanti VPN zero-day exploited in the attack has been a focal point of concern within the cybersecurity community. Mandiant, a Google Cloud subsidiary, linked the exploitation of this vulnerability to a suspected China-based espionage group (UNC5337). These attackers used the custom Spawn malware toolkit and other tools, such as Dryhook and Phasejam, to compromise vulnerable systems.

 

Ivanti released a patch for the vulnerability shortly after it was identified. The company stated: “Upon identifying the vulnerabilities through our Integrity Checker Tool (ICT), Ivanti rapidly developed and released a patch within weeks for Ivanti Connect Secure. We strongly urge all customers to follow the guidance outlined in our security advisory to ensure their systems are protected.”

 

Ivanti has also addressed several other vulnerabilities in its Cloud Services Appliance (CSA), emphasizing its commitment to improving product security and supporting affected customers.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543