Senator Ron Wyden (D-OR) has issued a directive to the Cybersecurity and Infrastructure Security Agency (CISA), the Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST). Wyden urged these agencies to spearhead an initiative to eliminate public internet-facing and insecure virtual private networks (VPNs) from government systems.
Wyden highlighted that federal agencies and contractors have experienced cyberattacks due to their reliance on legacy, insecure VPN servers for remote access. He cited recent hacking campaigns that targeted VPNs and remote-access systems from vendors including Cisco, Fortinet, Ivanti, and Check Point. These vulnerable VPNs are considered high-risk due to their lack of modern safeguards, allowing foreign adversaries to gain administrative access and steal sensitive data.
To mitigate these risks, Wyden, a member of the Senate Intelligence Committee, proposed a transition to zero-trust architectures. He recommended that CISA set a two-year deadline for civilian agencies to replace public-facing remote access systems with zero-trust solutions. The National Security Agency (NSA) is also urged to mandate a similar purge for all legacy remote access gateways across military, intelligence, and national security networks.
Wyden also pressed NIST to develop implementation standards for agencies migrating to zero-trust architectures, which involve continuous user verification and assume potential network breaches. Additionally, he directed OMB to draft a memo instructing federal agencies to invest in zero-trust infrastructure to enhance their cybersecurity posture.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Senator Ron Wyden has called on federal agencies to remove insecure, public internet-facing VPNs and adopt zero-trust architectures within two years. This push comes amid concerns that foreign adversaries are exploiting vulnerabilities in legacy VPNs to access government networks and steal sensitive data.