Sen. Ron Wyden called on the National Security Agency to update federal cybersecurity guidance for virtual private networks (VPNs), highlighting the continued importance of securing remote-access infrastructure used to reach protected government and enterprise networks.
The existing NSA and CISA guidance, Selecting and Hardening Remote Access VPN Solutions, warns that nation-state actors can exploit VPN vulnerabilities for credential theft, remote code execution, session hijacking, cryptographic weakening, and disclosure of sensitive device data. It recommends using validated VPN products, enforcing strong multi-factor authentication, promptly applying patches, and disabling unnecessary non-VPN features to reduce attack surface.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
U.S. Senator Ron Wyden called on the NSA to update federal cybersecurity guidance concerning VPNs.
NSA and CISA jointly released the Cybersecurity Information Sheet “Selecting and Hardening Remote Access VPN Solutions.” The guidance recommends validated VPN products, multi-factor authentication, prompt patching, and disabling unnecessary features.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
wyden.senate.gov
Open sourcensa.gov
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.