Sen. Ron Wyden asked the National Security Agency to update public guidance on commercial VPNs, warning that conventional single-hop services may not protect users against sophisticated foreign surveillance. A Congressional Research Service analysis requested by Wyden found that an adversary with broad internet-traffic visibility could correlate the timing and volume of encrypted traffic entering and leaving a VPN, linking users to websites without decrypting their communications.
Wyden requested an unclassified NSA response by October 14 and called for clearer advice for government personnel, defense contractors, journalists, human-rights defenders, and other likely espionage targets. He asked the agency to assess multi-hop privacy technologies—including Tor, Nym, mixnets, and Apple iCloud Private Relay—against single-hop VPNs; CRS said such architectures can make correlation harder by separating a user's identity from the destination, but do not guarantee anonymity. Current NSA and CISA guidance largely focuses on securing remote-access VPN products from intrusion rather than surveillance through bulk traffic analysis.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Sen. Ron Wyden sent NSA Director Gen. Joshua Rudd a letter requesting revised public guidance and unclassified answers on whether single-hop commercial VPNs protect against sophisticated foreign traffic-surveillance adversaries. Wyden also released a Congressional Research Service analysis describing traffic-correlation risks and requested NSA's assessment of multi-hop systems such as Tor, Nym, and Apple iCloud Private Relay.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcescworld.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourcecyberscoop.com
Open sourcewyden.senate.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.