Sources: US is investigating a recently discovered hack against federal agencies that used a vulnerability in Pulse Secure VPN, that began during Trump years
Context & Ripple Effects
Days after FireEye and Pulse Secure disclosed that [[a:965536|two China-linked hacking groups were exploiting a flaw in Pulse Secure's VPN devices to target US defense industry customers]], Reuters sources say the same vulnerability reached federal agencies — and that the intrusions began during the Trump administration, meaning discovery again lags the operation by months. That gap mirrors the pattern set by the Treasury Department email breach via SolarWinds hackers, which Sen. Ron Wyden revealed had run since July before its December disclosure.
First-order effects
- Federal agencies whose networks ran Pulse Secure VPN now face a formal US investigation into intrusion scope and duration, with the Trump-era start date complicating both attribution and remediation timelines.
- Pulse Secure moves from disclosing a defense-industry exploit to being at the center of a government compromise probe, raising the stakes for its patching and disclosure practices across its entire customer base.
Second-order effects
- Enterprise VPN appliance vendors come under the same scrutiny Juniper faced when the FBI probed its likely state-sponsored breach of compromised communications equipment in 2015 — perimeter devices are re-emerging as preferred state-attack vectors, forcing buyers to reassess trust in the appliances fronting their networks.
- FireEye's role as the private-sector discoverer of both this campaign and prior intrusions strengthens its position in government incident-response work, while agencies weigh whether vendor-supplied edge devices warrant independent auditing.
Third-order effects
- If the pattern holds — Juniper in 2015, SolarWinds in 2020, Pulse Secure now, and later CISA confirming agency intrusions in the Progress MOVEit hack ([[a:841175]]) — the structural direction is toward zero-trust architectures and mandatory security attestation for network appliances, with CISA institutionalized as the standing responder to cascading federal intrusions.
- Repeated multi-month gaps between intrusion and discovery point to systemic pressure for continuous monitoring mandates on federal networks rather than perimeter-based defenses alone.
The trend: State-sponsored exploitation of trusted network infrastructure — from Juniper to SolarWinds to Pulse Secure — is pushing US federal security from perimeter appliances toward continuously verified, zero-trust architectures.