Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

Дата публикации: 27-07-2026 13:00:00

In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech.
The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.


Основное содержимое страницы с новостью.

Sen. Ron Wyden implored a trio of federal leaders Monday to lead a comprehensive campaign to purge older, insecure virtual private networks that are directly accessible via the public internet from federal agencies.

“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden, D-Ore., wrote in his missive to top officials at the Office of Management and Budget, Cybersecurity and Infrastructure Security Agency and National Institute of Standards and Technology. They should coordinate “require the adoption of modern, secure remote-access technology across the federal government,” he said.

Such VPNs serve as a digital “front door” accessible via the public internet that allows mobile devices and remote employees to log in, Wyden said in a letter first reported by CyberScoop.

Wyden referenced several attacks that have affected federal agencies, including the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures across Fortinet gateways and vulnerabilities that hackers exploited across Ivanti and Check Point VPN appliances.

“Modern remote-access solutions eliminate this vulnerability entirely. Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence,” he said. “This effectively makes these servers invisible, ensuring that hackers cannot attack an entry point they cannot see.”

Agencies should move away from what a Congressional Research Service report to Wyden called a “castle-and-moat” approach of assuming anyone inside the network is authorized to access an organization’s resources that VPNs rely upon by extending virtual bridges to a more remote workforce, he said. They should instead focus on zero-trust architecture that uses a never-trust, always-verify approach, he said.

Furthermore, CISA, the OMB and NIST need to fundamentally change how the federal government approaches agency vulnerabilities, Wyden wrote. 

“The federal government has become trapped in an endless game of ‘whack-a-mole’ in responding to widespread compromises of legacy remote access technologies,” he said. “To keep federal networks online, CISA has been forced to repeatedly issue extraordinary Emergency Directives and hyper-accelerated patch mandates. These reactive emergency mandates are unsustainable for federal cybersecurity teams, and fail to address the fundamental issue that these flaws are inherent in the use of legacy remote-access appliances.”

CISA needs to issue a binding operational directive that gives agencies two years to fully expunge legacy, public-facing remote access systems, he said. NIST needs to issue implementation standards for transitioning to zero-trust architectures.

OMB needs to issue a memo directing agencies to prioritize zero-trust architecture spending. And OMB needs to team with CISA and the Defense Department to update procurement rules to block agencies and defense contractors from buying network edge, VPN or other remote access solutions unless a vendor supplies an attestation that it complies with NIST zero-trust standards, Wyden wrote.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Cyber industry coalition urges federal action after suspected Iran-linked water hacks010.9731-07-2026
2How companies could share cyber risks without exposing their secrets06.904-08-2026
3Соцфонд выделил миллиард на обслуживание защищенной государственной VPN-сети0701-07-2026
4Байден считает последние кибератаки серьезной угрозой нацбезопасности0028-12-2020
5В США заявили, что риск катастрофической кибератаки на страну возрастает с каждым днем0014-05-2021
6Huntress warns about attack spree that hit 30 SonicWall customers in 2 days014.4329-07-2026
7Минцифры обсуждает с хостинг-провайдерами повышение эффективности контроля за IP-адресами легитимных VPN — РБК015.4403-08-2026
8Reuters: американский сенатор Рубио представит законопроект по борьбе с киберугрозами0015-06-2021
9Reuters: Байден считает разумным для США атаки на используемые преступниками серверы0009-07-2021

Классификация: Международные. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 10.52. Источник: www.cyberscoop.com.