Senator Wyden Demands Federal Government Root Out Insecure VPNs Amid Rising Cyber Threats
Senator Ron Wyden (D-OR) has issued a stark warning to U.S. federal agencies, urging them to immediately address the pervasive use of legacy, internet-facing Virtual Private Networks (VPNs) within government networks. Citing years of successful exploitation by state-sponsored hackers, Wyden is pushing for a swift transition to more secure, zero-trust architectures to protect sensitive national data.
# Senator Wyden Demands Federal Government Root Out Insecure VPNs Amid Rising Cyber Threats
The U.S. government is facing mounting pressure to eliminate vulnerable remote-access software, with Senator **Ron Wyden** (D-OR) highlighting the extensive use of years-old VPNs by Russian and Chinese hackers to target federal networks. Wyden, a member of the Senate Intelligence Committee, underscored the critical need for immediate action to safeguard national security.
## A Call to Action for Key Agencies
In a letter addressed to the **Cybersecurity and Infrastructure Security Agency (CISA)**, the **Office of Management and Budget (OMB)**, and the **National Institute of Standards and Technology (NIST)**, Senator Wyden called for a concerted effort to remove public internet-facing and insecure VPNs from government systems.
"For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access," Wyden stated in his communication to the agencies.
## The Pervasive Threat of Vulnerable VPNs
The Senator's letter cited numerous recent and devastating hacking campaigns that have successfully exploited vulnerabilities in VPNs and remote-access systems. Products from major vendors such as **Cisco**, **Fortinet**, **Ivanti**, and **Check Point** were specifically mentioned as targets.
These vulnerable VPNs are considered high-risk due to their lack of modern security safeguards. "Through these hacks, foreign adversaries gained administrative access to target networks, allowing them to steal sensitive data from U.S. government agencies and companies," Wyden explained. He further emphasized the ease with which these exposed entry points can be scanned, targeted, and breached by malicious actors.
## The Path to a More Secure Future: Zero Trust
Senator Wyden asserted that the problem is not only critical but also easily fixable. He highlighted that contemporary remote-access tools on the market can provide users with access without "broadcasting their presence," thereby closing a significant digital vulnerability.
Wyden urged **CISA** to establish a two-year deadline for civilian agencies to purge public-facing remote-access systems and migrate to a **zero-trust architecture**. This security model mandates regular verification of users and assumes that attackers may already be present within a network, requiring continuous authentication and authorization.
Similarly, the **NSA**, under the Department of Defense, must mandate a purge of "all legacy remote access gateways and perimeter entry points across military, intelligence, and other federal national security networks," according to the letter.
To facilitate this transition, Wyden pressed **NIST** to develop "implementation standards" for agencies adopting zero-trust architectures. He also directed **OMB** to draft a memo instructing federal agencies to prioritize investments in zero-trust infrastructure.
