
ARLINGTON, Va. — With millions of federal personnel and defense contractors shifting abruptly to telework architectures, the Cybersecurity and Infrastructure Security Agency has issued an urgent technical alert warning of widespread scanning campaigns targeting unpatched enterprise VPN gateways.
ARLINGTON, Va. — In a joint technical advisory released Monday, CISA and the Federal Bureau of Investigation warned operators across all 16 critical infrastructure sectors that sophisticated nation-state cyber actors and ransomware syndicates are actively exploiting known vulnerabilities in commercial Virtual Private Network appliances and remote desktop protocols.
The transition to distributed enterprise environments, mandated in response to public health lockdowns, occurred at a velocity that left many organizations relying on legacy perimeter architectures. Threat telemetry collected by the National Cybersecurity and Communications Integration Center reveals sustained probing of unpatched Pulse Secure, Fortinet, and Citrix gateway appliances.
Targeting Operational Technology and Supply Chains
Of primary concern to federal cybersecurity coordinators is the convergence between corporate administrative IT networks and industrial control systems (ICS). Municipal water utilities, electrical cooperatives, and healthcare networks that enabled split-tunnel VPN connections or remote engineering access to facilitate offsite operations have inadvertently expanded their exploitable attack surface.
“Threat actors recognize that organizations are operating with distributed workforces and stretched IT security teams,” CISA Director Christopher Krebs said during a media briefing. “A compromised remote credential or an unpatched gateway appliance can provide an adversary with the foothold they need to move laterally across sensitive operational networks.”
Immediate Mitigation Priorities
The alert outlines non-negotiable defensive baselines for critical infrastructure administrators, starting with the universal enforcement of multi-factor authentication across all external access portals. CISA strongly discourages SMS-based two-factor authentication, urging operators to deploy hardware-backed tokens or authenticator apps.
Furthermore, network administrators are instructed to strictly isolate supervisory control and data acquisition (SCADA) networks from general telework VPN pools, terminate inactive remote desktop sessions, and disable legacy authentication protocols that bypass conditional access policies. Federal analysts stress that enterprise resilience during extended remote postures depends not on perimeter boundaries, but on rigorous identity verification and continuous endpoint visibility.