CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3258

As cited

Copy frozen at (site build).

government policy

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

Senator Ron Wyden called on federal cybersecurity leaders to coordinate a comprehensive effort to retire legacy, internet-facing VPN appliances from federal agencies and contractors, citing repeated exploitation by attackers through products like Cisco, Fortinet, Ivanti, and Check Point devices. He urged adoption of modern zero-trust architecture and recommended CISA issue a binding operational directive requiring agencies to eliminate such systems within two years, while NIST establish implementation standards and OMB update procurement rules to block non-compliant solutions. The senator characterized the current reactive approach of emergency patches as unsustainable and argued that modern remote-access solutions eliminate the public-facing entry point vulnerability entirely.

Why it matters: Federal agencies and defense contractors face ongoing compromise risk from legacy VPN exploitation; practitioners should track whether leadership implements Wyden's directive timeline and procurement changes to understand when legacy remote-access systems must be phased out across the federal government.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

government policy

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

government policy

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

Senator Ron Wyden urged OMB, CISA, and NIST to lead a campaign removing outdated, internet‑facing VPNs from federal networks. He argued that legacy remote‑access appliances act as visible entry points that have been exploited in incidents such as ArcaneDoor, FortiBleed, and Ivanti/Check Point vulnerabilities, and advocated zero‑trust alternatives. Wyden recommended binding directives, implementation standards, spending memos, and updated procurement rules to ensure agencies replace the legacy systems within two years.

Why it matters: Federal agencies and contractors that rely on legacy, public‑facing VPNs remain exposed to credential theft and network intrusion; they should begin assessing and planning migration to zero‑trust remote‑access solutions now.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

government policy

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

Senator Ron Wyden urged OMB, CISA, and NIST to lead a campaign removing outdated, internet‑facing VPNs from federal networks. He argued that legacy remote‑access appliances act as visible entry points that have been exploited in incidents such as ArcaneDoor, FortiBleed, and Ivanti/Check Point vulnerabilities, and advocated zero‑trust alternatives. Wyden recommended binding directives, implementation standards, spending memos, and updated procurement rules to ensure agencies replace the legacy systems within two years.

Why it matters: Federal agencies and contractors that rely on legacy, public‑facing VPNs remain exposed to credential theft and network intrusion; they should begin assessing and planning migration to zero‑trust remote‑access solutions now.

VendorsCiscoFortinetIvantiCheck Point
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary