Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access — Threadlinqs Intelligence
As of 2026-07-30, Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access is a medium-severity threat intel threat attributed to Multiple Chinese (China / Russia (primary, per Wyden letter); Iran (documented in earlier exploitation of CVE-2019-11510)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1774 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Multiple Chinese · China / Russia (primary, per Wyden letter); Iran (documented in earlier exploitation of CVE-2019-11510) · ESPIONAGE
On 2026-07-27, Sen. Ron Wyden sent a letter (with accompanying CRS memo) to OMB, CISA, and NIST calling for a binding operational directive requiring federal civilian agencies to eliminate
Senator Ron Wyden (D-OR) sent a letter dated 2026-07-27 to OMB Federal CISO Gregory Barbaccia, CISA, and NIST, accompanied by a Congressional Research Service (CRS) memo, arguing that the federal government's reliance on internet-facing legacy VPN appliances constitutes an unfixable architectural weakness rather than a series of isolated patching failures. The letter documents that Chinese and Russian state-sponsored hacking groups have repeatedly exploited internet-facing VPN and network-edge products from Pulse Secure, VMware, Ivanti, F5, and Cisco (reporting from CyberScoop and CyberInsider additionally names Fortinet and Check Point) against federal agencies and government contractors, prompting numerous CISA emergency directives over the past several years (ED 21-03 for Pulse Connect Secure in 2021, ED 24-01 for Ivanti Connect Secure/Policy Secure in 2024, and ED 26-01 for F5 BIG-IP in 2025).
This pattern is independently corroborated by the historical exploitation record: CVE-2019-11510 (Pulse Secure pre-auth arbitrary file read) was exploited by Iranian actors (OilRig, Chafer, Shamoon) and later cited in a 2020 DOJ indictment of Chinese APT41 members for supply-chain intrusions; CVE-2023-46805/CVE-2024-21887 (Ivanti Connect Secure) triggered CISA ED 24-01 after suspected China-nexus exploitation; CVE-2025-0282 (Ivanti) was zero-day exploited from mid-December 2024 by UNC5337 (part of the broader UNC5221 cluster) deploying the SPAWN malware family; Cisco ASA/FTD firewalls were targeted since mid-2023 by the state-sponsored ArcaneDoor campaign (Cisco Talos: UAT4356; Microsoft: STORM-1849) using the custom Line Dancer and Line Runner implants; VMware Tools/vCenter/ESXi flaws (CVE-2025-41244, CVE-2024-37079, CVE-2025-22224/22225/22226) were exploited by China-nexus UNC5174; and in October 2025 F5 disclosed that a nation-state actor (linked to China-nexus UNC5221 and the BRICKSTORM backdoor) had persistent, undetected access to its BIG-IP product-development and engineering-knowledge environments for roughly 12 months, exfiltrating source code and undisclosed-vulnerability data, prompting CISA ED 26-01.
The CRS memo explains that zero-trust architectures replace these inbound-listening, internet-exposed appliances with outbound-only connections that continuously verify user/device identity and restrict access to specific applications rather than the whole network, eliminating the scannable, always-open attack surface that adversaries have exploited for over half a decade. Wyden's specific asks: (1) CISA issue a Binding Operational Directive requiring FCEB civilian agencies to eliminate legacy public-facing VPNs within two years; (2) NSA impose an equivalent deadline on military/intelligence-community networks; (3) NIST publish implementation standards mandating outbound-only zero-trust architectures, memory-safe programming languages, agency-controlled encryption keys, and alignment with post-quantum cryptography; (4) OMB draft a memo directing agency investment in zero-trust infrastructure; and (5) FAR/DFARS be updated to bar agencies and defense contractors from purchasing VPN/remote-access products unless the vendor formally attests NIST zero-trust compliance. The letter cites a Travelers Q4 2025 Cyber Threat Report finding that 85% of ransomware-related cyber-insurance claims stemmed from exploited VPNs, underscoring that the exposure is not limited to nation-state espionage but also enables ransomware access-brokering.
Weaknesses (CWE)
CWE-287, CWE-78, CWE-22, CWE-121, CWE-190, CWE-200, CWE-863, CWE-306
Target sectors: government administration, federal civilian agencies, defense industrial base, critical infrastructure, legal services, technology, telecoms, managed service providers
Target regions: North America, united states of america
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, CVE-2019-11510, CVE-2019-11539, CVE-2019-19781, CVE-2020-5902, CVE-2021-22893, CVE-2020-8243, CVE-2021-22900, CVE-2021-22894, CVE-2023-46805, CVE-2024-21887, T1595, T1583, T1588, T1190, T1133, T1059, T1505, T1543, T1136, T1068