WASHINGTON — U.S. Sen. Ron Wyden is calling for federal agencies to remove outdated virtual private network systems from government networks, warning that internet-facing remote-access technology has provided Russian and Chinese hackers with pathways into sensitive systems.
Wyden, an Oregon Democrat and member of the Senate Intelligence Committee, sent a letter to the Cybersecurity and Infrastructure Security Agency, Office of Management and Budget, and National Institute of Standards and Technology outlining a proposed government-wide transition away from legacy VPN infrastructure.
The senator urged federal cybersecurity and administrative agencies to identify insecure remote-access gateways, establish a firm replacement deadline, and accelerate the adoption of zero-trust security architecture across civilian and national-security networks.
“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden wrote.
VPN systems allow employees, contractors, and administrators to connect to an organization’s internal network from an outside location. They became a central part of government and corporate operations as remote work expanded and organizations needed employees to access internal systems from homes, temporary offices, and other locations.
The same accessibility can create a high-value target when a VPN gateway is directly exposed to the public internet. Attackers can scan for those systems, identify product versions, search for known vulnerabilities, and attempt to enter a network through stolen credentials or unpatched software.
Wyden cited multiple cyber campaigns targeting VPN and remote-access products developed by Cisco, Fortinet, Ivanti, and Check Point. Vulnerabilities affecting those systems have drawn attention because a successful intrusion can provide attackers with access extending beyond the initial remote-access device.
“Through these hacks, foreign adversaries gained administrative access to target networks, allowing them to steal sensitive data from U.S. government agencies and companies,” Wyden wrote. “Because these entry points are exposed, hackers can easily scan, target, and break into them.”
Administrative access can allow an intruder to examine network configurations, create accounts, collect credentials, monitor communications, change security settings, and move into additional systems. The exact level of access depends on the affected product, network design, account permissions, and protections operating behind the gateway.
Legacy remote-access systems pose an elevated risk when they no longer receive effective security support, lack current authentication controls, or depend on a network model that grants broad internal access after a user connects.
Wyden argued that newer remote-access technologies can provide authorized users with access to specific applications and resources without openly advertising a traditional VPN gateway to every system scanning the internet.
His proposal centers on replacing public-facing remote-access systems with zero-trust architecture.
Zero trust operates on the principle that no person, device, connection, or location should receive automatic trust solely because it has reached an internal network. Access decisions are repeatedly evaluated using identity, authentication, device condition, requested resource, location, and other security information.
Under a traditional perimeter model, a user who successfully connects through a VPN may gain access to a wider section of the internal network. A zero-trust system can restrict the user to the particular application or service required for an authorized task.
This approach can reduce the damage caused by a stolen account or compromised device because gaining one form of access does not automatically provide unrestricted movement throughout the network.
Wyden asked CISA to establish a two-year deadline requiring civilian federal agencies to remove public internet-facing remote-access systems and transition to zero-trust alternatives.
CISA would play a central role in identifying vulnerable systems, coordinating the transition across civilian agencies, and ensuring that replacement technology meets federal security requirements.
Wyden also called for the National Security Agency to direct the removal of legacy remote-access gateways and perimeter entry points from military, intelligence, and other federal national-security networks.
The NSA’s involvement would address systems operating within the Department of Defense and the wider national-security environment, where a remote-access compromise could expose military, intelligence, or classified operations.
The senator asked NIST to develop implementation standards that agencies could follow while replacing VPN infrastructure with zero-trust architecture. Those standards would provide a common technical foundation for identity verification, access control, device security, network segmentation, logging, and continuous monitoring.
Without consistent implementation standards, agencies could adopt systems labeled as zero trust while applying different security requirements or preserving weaknesses from older network designs.
Wyden also urged OMB to issue a memorandum directing agencies to invest in the infrastructure needed to complete the transition. Such an effort would require agencies to identify affected systems, determine operational needs, secure funding, replace legacy equipment, update internal policies, and train employees and contractors.
A two-year deadline would also require agencies to account for specialized systems that cannot be replaced immediately without interrupting essential services. Those systems could require temporary safeguards until full migration is possible.
Wyden’s letter is a policy recommendation and does not itself order agencies to remove their VPN systems. CISA, OMB, NIST, the NSA, and individual federal departments would need to take formal action before the proposed deadline and technical requirements become binding across government networks.
The request places renewed attention on a security problem that extends beyond the discovery of individual vulnerabilities. Wyden’s proposal would change how federal remote access is designed by reducing reliance on publicly exposed gateways and limiting the amount of trust granted after a connection is established.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



