As cited
Copy frozen at (site build).
government policy
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Senator Ron Wyden called on federal cybersecurity leaders to coordinate a comprehensive effort to retire legacy, internet-facing VPN appliances from federal agencies and contractors, citing repeated exploitation by attackers through products like Cisco, Fortinet, Ivanti, and Check Point devices. He urged adoption of modern zero-trust architecture and recommended CISA issue a binding operational directive requiring agencies to eliminate such systems within two years, while NIST establish implementation standards and OMB update procurement rules to block non-compliant solutions. The senator characterized the current reactive approach of emergency patches as unsustainable and argued that modern remote-access solutions eliminate the public-facing entry point vulnerability entirely.
Why it matters: Federal agencies and defense contractors face ongoing compromise risk from legacy VPN exploitation; practitioners should track whether leadership implements Wyden's directive timeline and procurement changes to understand when legacy remote-access systems must be phased out across the federal government.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
government policy
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
government policy
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Senator Ron Wyden urged OMB, CISA, and NIST to lead a campaign removing outdated, internet‑facing VPNs from federal networks. He argued that legacy remote‑access appliances act as visible entry points that have been exploited in incidents such as ArcaneDoor, FortiBleed, and Ivanti/Check Point vulnerabilities, and advocated zero‑trust alternatives. Wyden recommended binding directives, implementation standards, spending memos, and updated procurement rules to ensure agencies replace the legacy systems within two years.
Why it matters: Federal agencies and contractors that rely on legacy, public‑facing VPNs remain exposed to credential theft and network intrusion; they should begin assessing and planning migration to zero‑trust remote‑access solutions now.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
government policy
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Senator Ron Wyden urged OMB, CISA, and NIST to lead a campaign removing outdated, internet‑facing VPNs from federal networks. He argued that legacy remote‑access appliances act as visible entry points that have been exploited in incidents such as ArcaneDoor, FortiBleed, and Ivanti/Check Point vulnerabilities, and advocated zero‑trust alternatives. Wyden recommended binding directives, implementation standards, spending memos, and updated procurement rules to ensure agencies replace the legacy systems within two years.
Why it matters: Federal agencies and contractors that rely on legacy, public‑facing VPNs remain exposed to credential theft and network intrusion; they should begin assessing and planning migration to zero‑trust remote‑access solutions now.
- Source published
- First seen by Cybersecurity Tracker