Ivanti VPNs: The Unwanted Gateway for Cyber Spies – A Cautionary Tale for Nominet!
Thousands of Ivanti VPNs remain vulnerable to cyberattacks exploiting CVE-2025-0282, with Nominet falling victim. Despite Ivanti’s patches, Chinese cyberspies and possibly others have targeted these VPNs. Nominet reported suspicious activity but no data breach. The UK government urges immediate action as thousands of systems face exposure.

Hot Take:
When it comes to cybersecurity, it seems like Ivanti VPNs are playing a dangerous game of “catch me if you can” with cyber-spies. Between the mystery of who’s behind the attacks and Nominet’s surprising cameo as a victim, it’s safe to say the plot has thickened faster than a pot of day-old gravy. Who knew VPNs could be this thrilling?
Key Points:
– Ivanti released patches for a critical zero-day vulnerability, CVE-2025-0282, in its Connect Secure VPN appliances.
– Mandiant suspects Chinese cyberspies might be exploiting the vulnerability, but other groups might also be involved.
– Nominet, the UK domain registry, was a victim in these attacks, but claims no data breach or backdoor was discovered.
– The UK government urged organizations to act swiftly against the Ivanti vulnerability.
– Despite efforts, thousands of Ivanti VPNs remain potentially vulnerable, according to Censys.