Why we wrote this
BlackFlag Advisory reads every alert and advisory the Australian Cyber Security Centre publishes. Not out of diligence for its own sake — it is how we calibrate. When ASD confirms a vector is being used against Australian organisations, that vector becomes a check in our assessment methodology, because it has stopped being theoretical.
Doing that consistently through 2026 produced an observation we did not expect, and it is the reason for this article.
Read the advisories individually and they are six unrelated technical problems, published weeks apart, each with its own indicators and mitigations. Read them together and one instruction recurs in nearly every one, in slightly different words:
Review the need to continue to have the interface exposed to the internet.
That is ASD’s own wording from the cPanel advisory. The same idea — establish what is reachable, and reduce it — is the operative recommendation across the year. It is not being said once. It is being said repeatedly, by the national authority, to an audience that in large part is not reading it.
The 2026 advisories, in sequence
ASD’s ACSC joined the NSA and partners on an alert covering ongoing exploitation of Cisco Software-Defined Wide Area Network technology, including CVE-2026-20127, CVE-2026-20128 and CVE-2026-20122.
Network edge infrastructure — internet-reachable by function. There is no configuration in which an SD-WAN controller is invisible; the only question is who can reach the management plane.
ASD confirmed active exploitation in Australia of a critical vulnerability affecting cPanel and WebHost Manager, carrying a CVSS v4.0 base score of 9.3. The flaw is an authentication bypass permitting unauthenticated remote attackers to reach the control panel and achieve remote code execution.
It affects every version after 11.40 — released in 2013. Patches became available 30 April 2026.
The detail that deserved more attention: ASD noted that products managed by several Managed Service Providers were impacted, resulting in the compromise of their customers. One exposed management interface at a provider, many downstream victims with no visibility of it.
ASD warned that since early 2026, attacks against Australian networks have used websites belonging to legitimate Australian businesses as part of the ClickFix vector. Fake CAPTCHA prompts convince the user to execute a malicious command themselves — which bypasses preventative controls, because the user runs it.
The payload is Vidar Stealer: credentials, browser data, cryptocurrency wallets, multi-factor tokens.
Note the loop this closes. A compromised Australian small business website harvests credentials, which enter the criminal market, which supply the credential-driven enterprise breaches that defined 2026. The forgotten WordPress site is not a low-severity finding. It is upstream of everything else.
ASD reported a widespread campaign against Fortinet firewalls and VPN gateways largely using exposed credentials and credential-based attacks, enabling remote access to devices and connected networks, and modification of security controls.
The lead instruction was to rotate all administrative and VPN credentials immediately. No zero-day. Valid credentials against an internet-facing appliance.
ASD signalled its intention to retire the Essential Eight framework within two years, to keep pace with a changing threat environment.
Continue applying it, but plan on the basis that maturity-level reporting against the current model has a finite life. The control objectives will not disappear; the packaging will change.
A critical alert covering a global campaign against content management systems, including in Australia. The exploited classes were unauthenticated file upload, remote code execution, server-side request forgery and insecure deserialisation, with attackers uploading webshells to gain remote control of web servers.
ASD noted many Australian small and medium businesses were impacted, and emphasised that the vulnerabilities exploited were public, known, and already patched.
ASD joined a multinational advisory describing sustained activity by actors linked to Russia’s FSB Centre 16 against internet-facing networking devices — routers, firewalls and similar equipment — ongoing since at least 2015.
Sectors named include communications, defence, energy, finance, government services and healthcare.
Revised guidance, aligned with a CISA initiative and following roughly twelve months of industry consultation, instructing critical infrastructure operators on fully separating operational technology and vital enabling systems from external connectivity in a crisis. It sets a three-month target for running essential services in complete disconnection.
What it counts as coupling is the useful part: shared routing and switching, common virtualisation and storage, Active Directory, DNS, DHCP, certificate services — and Network Time Protocol.
Dependencies that appear on no architecture diagram, and which quietly determine whether isolation is achievable at all.
Three conclusions
1. Almost none of it was a zero-day
cPanel: patched 30 April. The CMS campaign: ASD stated explicitly that the vulnerabilities were public and known with patches available. Fortinet: credentials, not exploits. The router campaign: poorly configured or unpatched equipment, running since 2015.
The gap is not intelligence about emerging threats. It is knowing what you run and whether it is reachable. That is an inventory problem wearing a vulnerability problem’s clothes — and inventory problems do not get solved by buying a threat feed.
2. Compromise of small organisations is a supply chain event
MSP-managed cPanel instances leading to customer compromise. Legitimate Australian business websites distributing infostealers. Many Australian SMEs impacted by the CMS campaign. A small business website is not only that business’s risk — it is a distribution node, and its harvested credentials become somebody else’s initial access.
This is also why the advisory audience problem matters. The organisations ASD names most frequently are the ones with no security function, no monitoring, and no reason to be reading cyber.gov.au on a Thursday.
3. ASD is describing an assessment gap it cannot close itself
The instruction is consistent: determine whether these interfaces are exposed. Not scan for vulnerabilities — establish what is reachable. Most organisations cannot answer that from internal sources, because internal records document what was intended rather than what answers.
The question ASD keeps asking is an external question. It has to be answered from outside.
What to do with this
- Enumerate your internet-facing management interfaces. Hosting control panels, CMS admin paths, VPN portals, firewall and router management, SD-WAN controllers, environment hubs. If any is reachable from the general internet, ask whether it needs to be — and put the answer in writing.
- Find the websites nobody owns. Campaign microsites, the 2019 rebrand domain, the subsidiary site, the events registration page. Unpatched CMS installations on forgotten domains are the exact target set of the July campaign.
- Rotate credentials on internet-facing appliances, and check whether corporate credentials appear in published infostealer corpora. ASD’s Fortinet advisory led with rotation for a reason.
- Read CI Fortify even if you are not critical infrastructure. Its coupling list — AD, DNS, DHCP, certificates, NTP — is a good test of whether anyone has mapped your real dependencies.
- Subscribe to the alerts. ASD publishes an RSS feed at cyber.gov.au. Free, authoritative, and in 2026 it repeatedly named the exact vector about to be used against Australian organisations. If you have suppliers, forward it to them — the advisories are written for an audience that mostly is not reading them.
ASD has done the analysis and published it, at no cost, six times this year. The advisories are not the hard part. Knowing whether they apply to you is.