Outdated VPNs should be purged from federal agencies, senator says
The U.S. government must root out insecure remote-access software as concern mounts about how Russian and Chinese hackers have used years-old VPNs to target federal networks, Sen. Ron Wyden said Monday.
Wyden (D-OR) told the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB) and the National Institute of Standards and Technology (NIST) that they must lead an effort to remove public internet facing and insecure virtual private networks from the government’s systems.
“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden said in a letter to the agencies.
The senator cited “multiple recent and devastating hacking campaigns” targeting VPNs and remote-access systems, including products from Cisco, Fortinet, Ivanti and Check Point.
Vulnerable VPNs are considered high-risk because they lack modern safeguards, the letter said.
“Through these hacks, foreign adversaries gained administrative access to target networks, allowing them to steal sensitive data from U.S. government agencies and companies,” Wyden wrote. “Because these entry points are exposed, hackers can easily scan, target, and break into them.”
The problem is easily fixed, according to Wyden, a member of the Senate Intelligence Committee.
Remote-access tools on the market today close the digital front door by giving users that access “without broadcasting their presence,” he said.
Wyden urged CISA to set a two-year deadline for civilian agencies to purge public-facing remote access systems and replace them with zero-trust architecture. The NSA, part of the Department of Defense, likewise must order a purge for “all legacy remote access gateways and perimeter entry points across military, intelligence, and other federal national security networks,” the letter said.
Wyden pressed NIST to create “implementation standards” for agencies migrating to zero-trust architectures, which require regular verification of users and assume that attackers are already inside a network. He also directed OMB to draft a memo ordering federal agencies to make investments in zero-trust infrastructure.
Suzanne Smalley
is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.



