Senator Ron Wyden has urged federal cybersecurity agencies to remove all insecure, internet-facing VPN systems from government networks within two years, citing multiple breaches by Russian and Chinese threat actors. In a letter sent Monday to the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST), the Oregon Democrat called for a comprehensive purge of legacy remote-access systems that have enabled devastating cyberattacks on federal agencies and contractors.
The senator's letter references recent hacking campaigns that exploited vulnerabilities in VPN products from major vendors including Cisco, Fortinet, Ivanti, and Check Point. These attacks allowed foreign adversaries to gain administrative access to target networks, enabling them to steal sensitive data from U.S. government agencies and private companies. Wyden, who serves on the Senate Intelligence Committee, emphasized that these legacy systems lack modern security safeguards and create easily discoverable entry points for attackers.
Wyden specifically called on CISA to establish a two-year deadline for civilian agencies to eliminate public-facing remote access systems and transition to zero-trust architecture. He also directed the National Security Agency to order similar purges across military, intelligence, and other national security networks within the Department of Defense. Zero-trust architecture operates on the principle that no user or device should be automatically trusted, requiring continuous verification and assuming potential compromise.
The problem stems from legacy VPN systems that broadcast their presence on the public internet, making them easy targets for attackers to scan and exploit. Modern remote-access tools address this vulnerability by providing secure connections without exposing entry points to potential adversaries. Wyden argued that the solution is readily available and straightforward to implement using existing commercial technologies.
Wyden directed NIST to develop implementation standards for agencies migrating to zero-trust architectures and instructed OMB to draft a memo requiring federal agencies to invest in zero-trust infrastructure. The senator's push reflects growing concern within Congress about the persistent exploitation of outdated remote-access systems, which have become a preferred attack vector for sophisticated nation-state actors targeting U.S. government networks.
Source: https://therecord.media/federal-purge-outdated-vpns-wyden-letter


