Critical

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

CyberScoop
Actively Exploited

Overview

Senator Ron Wyden from Oregon is urging federal agencies to stop using outdated and insecure public-facing VPNs, which he claims have led to severe attacks on the government. In a letter reported by CyberScoop, Wyden expressed concern that these older VPN technologies are vulnerable and have contributed to significant security breaches. He emphasized that the risks associated with these systems are unacceptable given the sensitive nature of government operations. The senator's call to action is aimed at prompting federal agencies to adopt more secure solutions to protect against potential cyber threats. This issue is particularly pressing as cyberattacks on government infrastructure continue to rise, highlighting the need for modern security practices.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Older public-facing VPNs used by federal agencies
  • Action Required: Agencies should replace older VPNs with updated, secure alternatives.
  • Timeline: Disclosed on [date of letter]

Original Article Summary

In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech. The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.

Impact

Older public-facing VPNs used by federal agencies

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on [date of letter]

Remediation

Agencies should replace older VPNs with updated, secure alternatives.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

BleepingComputer

Apple is facing a lawsuit from three individuals who claim they lost nearly $1.8 million in Bitcoin due to a fraudulent app called Sparrow Wallet, which was available on the App Store. The plaintiffs downloaded the app, believing it to be a legitimate cryptocurrency wallet, only to discover that it was a scam designed to steal their funds. This incident raises serious concerns about the vetting process for apps on major platforms like Apple's App Store. Users need to be vigilant when downloading financial apps, as scammers are finding new ways to exploit unsuspecting individuals. The lawsuit could have implications for how Apple manages app security and user protection in the future.

Jul 27, 2026

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

The Hacker News

The Dysphoria botnet, which targets Internet of Things (IoT) devices, has evolved its infrastructure by incorporating blockchain-based name services and victim relays. This change comes after a law enforcement operation in March disrupted the JackSkid botnet, which had been a significant player in the IoT threat landscape. Researchers from CNCERT and XLab report that these new features make Dysphoria more resilient against future disruptions. By using blockchain technology, the botnet can better obscure its command and control functions, making it harder for authorities to shut it down. This development raises concerns for users of IoT devices, as it indicates an increase in the sophistication of attacks on interconnected devices.

Jul 27, 2026

Is open source the answer to rogue AI agents? Nvidia's new alliance says yes

Latest news

As incidents involving AI in cybersecurity increase, Nvidia has formed a new alliance aimed at addressing the potential risks posed by rogue AI agents. This collaboration brings together various stakeholders to explore the role of open source solutions in mitigating these threats. The concerns stem from the possibility that AI systems could be manipulated for malicious purposes, leading to serious security breaches. By focusing on open source, the alliance hopes to foster transparency and community-driven innovation, enabling faster responses to emerging threats. This initiative is crucial as businesses and individuals rely more heavily on AI technologies, making it essential to ensure these systems are secure and trustworthy.

Jul 27, 2026

Coca-Cola confirms data theft in Fairlife ransomware attack

BleepingComputer

Coca-Cola has confirmed that hackers accessed sensitive data from its dairy arm, Fairlife, during a ransomware attack that occurred earlier this month. This breach raises concerns about the security of customer and operational data within the company, which could potentially be misused by the attackers. The incident highlights the growing threat of ransomware attacks in the food and beverage sector, where companies may hold valuable consumer information. It is still unclear what specific data was taken or how many individuals may be affected. Companies in similar industries should take note and enhance their cybersecurity measures to protect against such threats.

Jul 27, 2026

Ernst & Young data breach claimed by ShinyHunters extortion gang

BleepingComputer

The ShinyHunters extortion gang has taken responsibility for a data breach involving Ernst & Young, claiming to have accessed credentials for several of the company's systems through a supply-chain attack. This breach raises serious concerns about the security of sensitive information held by one of the world's largest professional services firms. Affected stakeholders may include clients relying on Ernst & Young for auditing and consulting services, as well as employees whose data could have been compromised. The incident underscores the risks associated with supply-chain vulnerabilities and the potential for attackers to exploit them to access valuable corporate data. Organizations are urged to review their security protocols and ensure that their supply chains are adequately protected against such threats.

Jul 27, 2026

Claude AI shared chats indexed by Google - see if your conversations were exposed

Latest news

Recently, it was discovered that conversations from Claude AI, an artificial intelligence chat tool, were inadvertently indexed by Google. This issue came to light when users on Reddit began sharing their experiences, revealing that private chats could be accessed through search results. This exposure raises significant privacy concerns, as users may not have intended for their discussions to be publicly searchable or visible. Those who used Claude AI may want to check if their conversations are affected. The situation underscores the challenges of data privacy in AI tools and the importance of secure user data management.

Jul 27, 2026