← Back to all briefings
Cybersecurity 5 min read Published Updated Credibility 40/100

CISA issues enterprise VPN security alert during COVID-19 surge

CISA Alert AA20-073A warned that VPN usage was spiking as organizations moved to remote work, urging patching, multi-factor authentication, and monitoring for compromised credentials on VPN concentrators.

Timeline plotting source publication cadence sized by credibility.
2 publication timestamps supporting this briefing. Source data (JSON)

Executive briefing: CISA published Alert AA20-073A highlighting increased enterprise VPN reliance during early COVID-19 responses. The agency urged patching VPN appliances, enforcing MFA, and monitoring for unauthorized logins or brute-force attempts.

Why it matters

  • Remote work expansion increases attack surface on VPN concentrators and remote access gateways.
  • Unpatched VPN flaws (e.g., Pulse Secure, Fortinet, Citrix) had active exploitation, including credential theft and session hijacking.
  • Credential stuffing and phishing campaigns target remote workers; MFA and log review reduce compromise risk.

Operator actions

  • Apply current vendor patches to VPN appliances and disable legacy SSL VPN features that lack fixes.
  • Enable multi-factor authentication for all remote access users and administrative interfaces.
  • Increase monitoring for anomalous VPN logins, repeated failures, and connections from unexpected geographies.
  • Review capacity and continuity plans to ensure VPN infrastructure can handle sustained remote work loads without disabling security controls.

Key sources

Timeline plotting source publication cadence sized by credibility.
2 publication timestamps supporting this briefing. Source data (JSON)
Horizontal bar chart of credibility scores per cited source.
Credibility scores for every source cited in this briefing. Source data (JSON)

Continue in the Cybersecurity pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • VPN
  • CISA
  • AA20-073A
Back to curated briefings