logo

Nominet probes network intrusion linked to Ivanti zero-day exploit

ID: 4e7336bc-0b3c-5059-b57c-11e090661578

STIX ID: report--4e7336bc-0b3c-5059-b57c-11e090661578

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-01-13

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Nominet, the UK domain registry for millions of .uk domains, reported a network intrusion traced to exploitation of an Ivanti zero-day (CVE-2025-0282) used to access systems via Ivanti VPN products; the activity is linked to threat clusters UNC5337 (and ties to UNC5221) and has resulted in deployment of known and novel malware families (Spawn, Dryhook, Phasejam). Ivanti and Mandiant disclosed the vulnerability and released patches for affected products, while mitigations and investigations are ongoing and customers have been notified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.