Sources: US is investigating a recently discovered hack against federal agencies that used a vulnerability in Pulse Secure VPN, that began during Trump years
Labor Secretary Marty Walsh told a panel of House Appropriators … Stephen E. Arnold / Beyond Search : How Are Those Cyber Security Vendors Performing? (Yes, That Is the Correct Word) Tweets: Chris Bing / @bing_chris : CISA said they've seen evidence of breaches at five civilian federal agencies tied to the Pulse Secure exploitation. That's based on information gathered by the agency last week through an emergency directive. https://www.reuters.com/... Chris Bing / @bing_chris : Sources told Reuters the recent Pulse Secure hacking campaign effected less than 100 organizations. Went beyond defense contractors - to also include companies of competitive economic interest to China: like Solar energy technology firms. https://www.reuters.com/... Katie Moussouris / @k8em0 : Wondering about “upcoming executive order that will require agencies to identify their most critical software & promote a “bill of materials” that demands a certain level of digital security across products sold to the government” Tons data enrichment needed to make that useful. https://twitter.com/... Sean Lyngaas / @snlyngaas : At least 5 federal civilian agencies confirmed breached in Pulse Secure hacking, per @josephmenn and @Bing_Chris: https://www.reuters.com/...
Context & Ripple Effects
The Pulse Secure campaign did not appear out of nowhere. Back in September 2020, [[a:957907|CISA warned that hacking groups linked to China's Ministry of State Security were exploiting bugs in F5, Citrix, Pulse Secure, and Microsoft Exchange]] to break into US government networks — this investigation reads as the confirmation that Pulse Secure was not just on the list but actively used. It lands in a run of intrusions that includes state-sponsored hackers reaching DHS internal communications during the Treasury and Commerce breaches.
What makes this disclosure notable is scale and duration: sources put the blast radius at fewer than 100 organizations — including solar energy technology firms and defense contractors — and CISA says it has evidence of breaches at five civilian federal agencies, gathered through an emergency directive. The campaign reportedly began during the Trump years, meaning agencies were living with compromised VPN access for months before discovery.
First-order effects
- The five breached civilian agencies and the other affected organizations must now execute CISA's emergency directive — hunt for persistence, revoke credentials, and rebuild or replace Pulse Secure gateways rather than simply patch them.
- Pulse Secure (Ivanti) faces immediate reputational and commercial damage as its enterprise VPN becomes the named vector in a federal espionage case, forcing emergency customer outreach while investigators work.
Second-order effects
- Rival VPN and secure-access vendors will be pressed by federal buyers to prove their own edge devices are hardened, as procurement teams re-evaluate whether any single perimeter appliance should hold the keys to agency networks.
- Defense contractors and solar energy firms in the victim set become indirect intelligence losses for their government partners, tightening supply-chain security expectations on cleared contractors — a pressure that compounds the severe shortage of cybersecurity workers across the public and private sectors.
Third-order effects
- The pattern here — espionage campaigns quietly exploiting edge appliances long before discovery, then confirmed years later — recurs with Progress' MOVEit Transfer in 2023, when CISA again confirmed several federal agencies were intruded upon, pointing toward a structural shift: continuous validation of remote-access infrastructure replacing point-in-time compliance.
- If repeated emergency directives remain the main federal response mechanism, expect Congress and CISA to push binding mandates on edge-device patching and telemetry sharing, converting ad hoc incident response into standing policy.
The trend: State-sponsored hackers are systematically weaponizing enterprise edge appliances like VPNs and file-transfer tools, and US civilian agencies keep discovering the intrusions months or years late.