- What: Senator urges NSA to update VPN guidance
- Impact: Concerns about foreign surveillance via traffic analysis
Network Security Senator Wyden urges NSA to update VPN guidance amid foreign surveillance concerns September 3, 2026 Share By SC Staff (Adobe Stock) Senator Ron Wyden is urging the National Security Agency to revise its cybersecurity guidance to inform Americans that standard virtual private network (VPN) services may not adequately protect them from sophisticated foreign surveillance threats, with further coverage provided by Nextgov. A Congressional Research Service analysis, requested by Wyden, indicates that foreign intelligence services may be able to link VPN users to specific websites by analyzing the timing and volume of encrypted data traffic. This traffic analysis method, which does not require breaking encryption, could expose a user's online activities. The concern primarily focuses on single-hop VPNs where traffic passes through one server, potentially allowing adversaries monitoring that server to correlate incoming and outgoing data. Wyden argues this risk should be clearly communicated to government personnel, contractors, and journalists who may be targets of espionage. Current NSA and CISA guidance largely addresses preventing network intrusions that exploit VPN vulnerabilities, recommending measures like timely updates and multi-factor authentication. The Office of the Director of National Intelligence has previously stated VPNs are useful for basic cybersecurity, advising users to review provider encryption and data retention policies, but it remains unclear if they assessed the specific traffic analysis risks associated with conventional VPNs. Source: Nextgov An In-Depth Guide to Network Security Get essential knowledge and practical strategies to fortify your network security. Learn More SC Staff Related Network Security BGP hijacking incident diverts traffic, targeting Softaculous and Virtualizor users SC Staff September 2, 2026 The incident began around 20:57 UTC on August 28, when an unknown network began announcing a block of IP addresses belonging to Hetzner, a Softaculous upstream provider. Network Security Cloudflare launches adaptive intelligence to combat bot attacks SC Staff September 1, 2026 The introduction of Adaptive Intelligence addresses the increasing ease and low cost for attackers to rent compromised devices and employ sophisticated impersonation techniques. Critical Infrastructure Security China-linked campaign targets high-value networks, critical infrastructure Steve Zurier August 31, 2026 Fire Ant targets routers and authentication systems to spy, steal credentials and evade detection. Related Events Cybercast Network security: Adaptive defense, SASE, and micro-segmentation Tue Oct 13 Cybercast How to transform your SOC through XDR and MDR On-Demand Event Cybercast AI for network security: Problems and solutions On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bridge Broadcast Cache Poisoning Call Admission Control (CAC) Cell Computer Network Cut-Through Decapsulation Domain Domain Name You can skip this ad in 5 seconds