Outdated VPNs should be purged from federal agencies, senator says

The U.S. government must root out insecure remote-access software as concern mounts about how Russian and Chinese hackers have used years-old VPNs to target federal networks, Sen. Ron Wyden said Monday.
Wyden (D-OR) told the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB) and the National Institute of Standards and Technology (NIST) that they must lead an effort to remove public internet facing and insecure virtual private networks from the government’s systems.
“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden said in a letter to the agencies.
The senator cited “multiple recent and devastating hacking campaigns” targeting VPNs and remote-access systems, including products from Cisco, Fortinet, Ivanti and Check Point.
Vulnerable VPNs are considered high-risk because they lack modern safeguards, the letter said.
“Through these hacks, foreign adversaries gained administrative access to target networks, allowing them to steal sensitive data from U.S. government agencies and companies,” Wyden wrote. “Because these entry points are exposed, hackers can easily scan, target, and break into them.”
The problem is easily fixed, according to Wyden, a member of the Senate Intelligence Committee.
Remote-access tools on the market today close the digital front door by giving users that access “without broadcasting their presence,” he said.
Wyden urged CISA to set a two-year deadline for civilian agencies to purge public-facing remote access systems and replace them with zero-trust architecture. The NSA, part of the Department of Defense, likewise must order a purge for “all legacy remote access gateways and perimeter entry points across military, intelligence, and other federal national security networks,” the letter said.
Wyden pressed NIST to create “implementation standards” for agencies migrating to zero-trust architectures, which require regular verification of users and assume that attackers are already inside a network. He also directed OMB to draft a memo ordering federal agencies to make investments in zero-trust infrastructure.
References in this story
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
- Suzanne Smalley (@suzannesmalley.bsky.social) bsky.app Reporter covering digital privacy and cybersecurity policy for The Record. Mom. Pub trivia queen. Crossword enthusiast. Literary fiction connoisseur. Idiosyncratic. Signal: Suzanne.236 Email…



