Outdated VPNs should be purged from federal agencies, senator says
Senator Ron Wyden is urging federal agencies to remove outdated and insecure VPNs from their systems, citing a growing threat of foreign adversaries exploiting these vulnerabilities to gain access to sensitive U.S. government data. He’s pushing for a phased approach, including a two-year deadline for civilian agencies to migrate to zero-trust architecture and urging OMB to invest in necessary infrastructure.
Senator Ron Wyden is calling on federal agencies to address a critical security vulnerability stemming from the widespread use of outdated and insecure VPNs. He argues that these legacy systems have become a significant entry point for foreign adversaries, particularly Russian and Chinese hackers, who have successfully exploited them to gain administrative access to U.S. government networks and steal sensitive data. Wyden highlighted ‘multiple recent and devastating hacking campaigns’ targeting VPNs and remote-access systems, specifically mentioning products from Cisco, Fortinet, Ivanti and Check Point. He believes that modern remote-access tools, which provide secure access without broadcasting user presence, offer a far more robust solution. Wyden is requesting that CISA establish a two-year deadline for civilian agencies to eliminate public-facing remote access systems and transition to a zero-trust architecture, a security model that assumes attackers are already present within a network. Furthermore, he is directing OMB to issue a memo ordering federal agencies to invest in zero-trust infrastructure and NIST to develop implementation standards for this migration. The senator emphasized the need for a proactive approach to mitigate the ongoing risk posed by these vulnerable systems.
