Wyden seeks upgraded NSA security guidance on commercial VPN use

The NSA is currently unprepared to provide effective guidance on securing commercial VPNs.

Bottom line: The NSA is currently unprepared to provide effective guidance on securing commercial VPNs.

What's happening: Senator Ron Wyden (D-Ore.) has written to the NSA requesting better security guidance for commercial VPNs, following recent breaches of VPN services, including those used by major companies like Akamai and Cloudflare. The breaches, which involved unauthorized access to sensitive data, occurred in 2022 and 2023, and were attributed to vulnerabilities in VPN software. The NSA's existing guidance is deemed insufficient by Wyden, who cites a 2019 CVSS score of 4.3 for VPN software.

What to do: Security leaders should prioritize assessing and patching VPN software vulnerabilities, and consider implementing multi-factor authentication and regular security audits to mitigate the risks associated with commercial VPN use.

Source: CyberScoop