VYPR
advisoryPublished Jul 27, 2026· 1 source

Senator Wyden Demands Federal Agencies Purge Legacy VPNs, Embrace Zero Trust

Citing repeated cyberattacks, Senator Ron Wyden is urging federal agencies to eliminate outdated, internet-facing VPNs and transition to zero-trust architecture.

Senator Ron Wyden has issued a strong call to action for federal agencies, imploring them to dismantle legacy virtual private networks (VPNs) that remain exposed to the public internet. In a letter addressed to leaders at the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Institute of Standards and Technology (NIST), Wyden highlighted the persistent threat posed by these systems, which he described as "devastating cyberattacks" enablers.

Wyden emphasized that these internet-facing VPNs serve as a critical vulnerability, acting as an open "front door" for attackers seeking to infiltrate federal networks. He pointed to a series of high-profile attacks, including the ArcaneDoor exploits targeting Cisco firewalls, the FortiBleed credential exposure on Fortinet gateways, and various vulnerabilities exploited in Ivanti and Check Point VPN appliances. These incidents underscore the inherent insecurity of relying on such legacy technology for remote access.

"Modern remote-access solutions eliminate this vulnerability entirely," Wyden stated, contrasting them with older systems. He explained that contemporary technologies offer remote access without broadcasting their presence, rendering them effectively invisible to potential attackers. This approach significantly reduces the attack surface by ensuring that entry points are not readily discoverable.

The senator advocated for a fundamental shift away from the traditional "castle-and-moat" security model, which assumes internal network users are trustworthy. Instead, he urged federal agencies to adopt a zero-trust architecture. This model operates on a "never-trust, always-verify" principle, requiring continuous authentication and authorization for all users and devices, regardless of their location.

Wyden also called for concrete policy and procedural changes to facilitate this transition. He proposed that CISA issue a binding operational directive mandating the complete removal of legacy, public-facing remote access systems within two years. Concurrently, NIST should develop implementation standards for zero-trust architectures, while OMB should issue guidance prioritizing zero-trust spending within agencies.

Furthermore, Wyden suggested that OMB collaborate with CISA and the Department of Defense to revise procurement rules. These updated rules would prevent agencies and defense contractors from purchasing network edge, VPN, or other remote access solutions unless vendors can attest to their compliance with NIST zero-trust standards. This measure aims to incentivize the market towards more secure solutions.

"The federal government has become trapped in an endless game of ‘whack-a-mole’ in responding to widespread compromises of legacy remote access technologies," Wyden noted, criticizing the reactive nature of current cybersecurity responses. He argued that the repeated issuance of emergency directives and accelerated patch mandates by CISA is unsustainable and fails to address the root cause of these vulnerabilities.

By pushing for these systemic changes, Wyden aims to move the federal government towards a more resilient and secure posture, fundamentally addressing the risks associated with outdated remote access technologies and embracing a future-proof zero-trust framework.

Synthesized by Vypr AI