Sen. Ron Wyden is pressing federal cybersecurity leaders to get insecure remote-access software out of government networks, warning that old VPNs exposed to the public internet have become a repeat entry point for Russian and Chinese hackers targeting federal systems.
In a Monday letter, Wyden, an Oregon Democrat on the Senate Intelligence Committee, asked the Cybersecurity and Infrastructure Security Agency, the Office of Management and Budget and the National Institute of Standards and Technology to lead a governmentwide cleanup of insecure virtual private networks and other public-facing remote-access gateways.
Wyden said federal agencies and government contractors have been damaged by attacks tied to older VPN servers used to give employees remote access. His letter pointed to recent hacking campaigns against VPN and remote-access products from Cisco, Fortinet, Ivanti and Check Point.
Why does Wyden want federal agencies to remove old VPNs?
Wyden’s argument is blunt: internet-facing VPNs are visible targets. If a gateway sits on the public internet and lacks modern protections, attackers can find it, test it and exploit it before moving deeper into the network.
The letter said hackers who compromise those systems can gain administrative access inside a target organization. From there, Wyden wrote, foreign adversaries have stolen sensitive information from U.S. agencies and companies.
VPNs are not magic tunnels. They are servers that accept remote connections, authenticate users and place those users inside an organization’s network. When those servers are old, poorly protected or left exposed, they can become the front door attackers try first.
Wyden said newer remote-access tools can provide access without advertising the access point to the public internet. His letter ties that shift to zero-trust architecture, a security model that requires repeated checks of users and devices and assumes an attacker may already be inside the network.
What is Wyden asking CISA, OMB, NIST and NSA to do?
Wyden urged CISA to impose a two-year deadline for civilian federal agencies to remove public-facing remote-access systems and replace them with zero-trust architecture. That would put a clock on agencies that still depend on legacy VPN gateways instead of leaving the work to vague modernization plans.
He also said the National Security Agency, which is part of the Department of Defense, should order a similar purge across military, intelligence and other federal national security networks. The letter described the targets as legacy remote-access gateways and perimeter entry points.
Wyden asked NIST to write implementation standards for agencies moving to zero-trust systems. That matters because “zero trust” can mean many things in vendor decks, and agencies need concrete technical requirements rather than a slogan with procurement paperwork attached.
He also pressed OMB to issue a memo directing federal agencies to invest in zero-trust infrastructure. OMB memos are one of the ways the White House turns cybersecurity policy into agency requirements, budgets and deadlines.
The letter does not say that every VPN product is compromised, and it does not claim that replacing remote-access tools alone will stop foreign hacking. Wyden’s narrower point is that exposed, outdated gateways have been abused often enough that the federal government should stop treating them as acceptable infrastructure.
This story draws on original reporting from The Record.