Sen. Ron Wyden is urging federal leaders to purge older, insecure virtual private networks (VPNs) that are directly accessible via the public internet from federal agencies. In a letter to top officials at the Office of Management and Budget, Cybersecurity and Infrastructure Security Agency, and National Institute of Standards and Technology, Wyden emphasized the need for a comprehensive campaign to adopt modern, secure remote-access technology across the federal government.
Legacy VPNs: A Security Risk
Wyden pointed out that federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access. He cited several attacks that have affected federal agencies, including the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures across Fortinet gateways, and vulnerabilities that hackers exploited across Ivanti and Check Point VPN appliances.
Modern Remote-Access Solutions
Wyden argued that modern remote-access solutions eliminate the vulnerability of legacy VPNs entirely. Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence, making them invisible to hackers. He emphasized the need for agencies to move away from a "castle-and-moat" approach and adopt a zero-trust architecture that uses a never-trust, always-verify approach.
The Congressional Research Service report to Wyden noted that agencies should extend virtual bridges to a more remote workforce, rather than relying on VPNs that assume anyone inside the network is authorized to access an organization's resources. Wyden agreed, stating that the federal government has become trapped in an endless game of "whack-a-mole" in responding to widespread compromises of legacy remote access technologies.
Call to Action
Wyden called on CISA, OMB, and NIST to take action to address the issue. He urged CISA to issue a binding operational directive that gives agencies two years to fully expunge legacy, public-facing remote access systems. He also recommended that NIST issue implementation standards for transitioning to zero-trust architectures and that OMB issue a memo directing agencies to prioritize zero-trust architecture spending.
Furthermore, Wyden suggested that OMB team with CISA and the Defense Department to update procurement rules to block agencies and defense contractors from buying network edge, VPN, or other remote access solutions unless a vendor supplies an attestation that it complies with NIST zero-trust standards. By taking these steps, Wyden believes that the federal government can improve its cybersecurity posture and prevent future cyberattacks.
Wyden's letter highlights the importance of adopting modern, secure remote-access technology to prevent cyberattacks. As the federal government continues to rely on legacy VPNs, it is essential that agencies take action to address this vulnerability and adopt a zero-trust architecture to protect their networks and data.
- ArcaneDoor attacks on Cisco firewalls
- FortiBleed credential exposures across Fortinet gateways
- Vulnerabilities exploited across Ivanti and Check Point VPN appliances
These attacks demonstrate the need for federal agencies to prioritize cybersecurity and adopt modern, secure remote-access technology to prevent future cyberattacks.
Conclusion
In conclusion, Sen. Wyden's call to action emphasizes the importance of adopting modern, secure remote-access technology to prevent cyberattacks. By purging older, insecure public-facing VPNs and adopting a zero-trust architecture, federal agencies can improve their cybersecurity posture and protect their networks and data.
Modern remote-access solutions eliminate this vulnerability entirely. Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence.
As the federal government continues to rely on legacy VPNs, it is essential that agencies take action to address this vulnerability and adopt a zero-trust architecture to protect their networks and data.
By taking these steps, the federal government can improve its cybersecurity posture and prevent future cyberattacks, ensuring the security and integrity of its networks and data.
Source: CyberScoop