We Read Every ASD Advisory This Year.
They keep saying the same sentence.

ASD keeps asking one question. Could you answer it about your own environment today? A passive external assessment is where the honest answers begin: what you expose to the outside world, and who owns that risk.

Assess Your Exposure →

Why we wrote this

BlackFlag Advisory reads every alert and advisory the Australian Cyber Security Centre publishes. Not out of diligence for its own sake — it is how we calibrate. When ASD confirms a vector is being used against Australian organisations, that vector becomes a check in our assessment methodology, because it has stopped being theoretical.

Doing that consistently through 2026 produced an observation we did not expect, and it is the reason for this article.

Read the advisories individually and they are six unrelated technical problems, published weeks apart, each with its own indicators and mitigations. Read them together and one instruction recurs in nearly every one, in slightly different words:

Review the need to continue to have the interface exposed to the internet.

That is ASD’s own wording from the cPanel advisory. The same idea — establish what is reachable, and reduce it — is the operative recommendation across the year. It is not being said once. It is being said repeatedly, by the national authority, to an audience that in large part is not reading it.

What the 2026 advisories actually say
0
major ACSC advisories analysed across 2026
0
of them turned on a zero-day
0
age of the oldest affected cPanel version still in use
0
isolation capability now expected of critical infrastructure
Source: ASD’s ACSC alerts and advisories, cyber.gov.au, 2026.
Two things prompted this pieceFirst, that ASD named small and medium Australian businesses as impacted in multiple 2026 advisories — and those are precisely the organisations least likely to be monitoring cyber.gov.au. Second, that nobody in the Australian market appears to be joining these advisories up and stating the pattern plainly. So we have.

The 2026 advisories, in sequence

Eight advisories. Expand any one.

ASD’s ACSC joined the NSA and partners on an alert covering ongoing exploitation of Cisco Software-Defined Wide Area Network technology, including CVE-2026-20127, CVE-2026-20128 and CVE-2026-20122.

Network edge infrastructure — internet-reachable by function. There is no configuration in which an SD-WAN controller is invisible; the only question is who can reach the management plane.

ASD confirmed active exploitation in Australia of a critical vulnerability affecting cPanel and WebHost Manager, carrying a CVSS v4.0 base score of 9.3. The flaw is an authentication bypass permitting unauthenticated remote attackers to reach the control panel and achieve remote code execution.

It affects every version after 11.40 — released in 2013. Patches became available 30 April 2026.

“Review the need to continue to have the interface exposed to the internet.”

The detail that deserved more attention: ASD noted that products managed by several Managed Service Providers were impacted, resulting in the compromise of their customers. One exposed management interface at a provider, many downstream victims with no visibility of it.

ASD warned that since early 2026, attacks against Australian networks have used websites belonging to legitimate Australian businesses as part of the ClickFix vector. Fake CAPTCHA prompts convince the user to execute a malicious command themselves — which bypasses preventative controls, because the user runs it.

The payload is Vidar Stealer: credentials, browser data, cryptocurrency wallets, multi-factor tokens.

Note the loop this closes. A compromised Australian small business website harvests credentials, which enter the criminal market, which supply the credential-driven enterprise breaches that defined 2026. The forgotten WordPress site is not a low-severity finding. It is upstream of everything else.

ASD reported a widespread campaign against Fortinet firewalls and VPN gateways largely using exposed credentials and credential-based attacks, enabling remote access to devices and connected networks, and modification of security controls.

The lead instruction was to rotate all administrative and VPN credentials immediately. No zero-day. Valid credentials against an internet-facing appliance.

ASD signalled its intention to retire the Essential Eight framework within two years, to keep pace with a changing threat environment.

Continue applying it, but plan on the basis that maturity-level reporting against the current model has a finite life. The control objectives will not disappear; the packaging will change.

A critical alert covering a global campaign against content management systems, including in Australia. The exploited classes were unauthenticated file upload, remote code execution, server-side request forgery and insecure deserialisation, with attackers uploading webshells to gain remote control of web servers.

ASD noted many Australian small and medium businesses were impacted, and emphasised that the vulnerabilities exploited were public, known, and already patched.

ASD joined a multinational advisory describing sustained activity by actors linked to Russia’s FSB Centre 16 against internet-facing networking devices — routers, firewalls and similar equipment — ongoing since at least 2015.

Sectors named include communications, defence, energy, finance, government services and healthcare.

“Assess whether their networking equipment is exposed to the internet.”

Revised guidance, aligned with a CISA initiative and following roughly twelve months of industry consultation, instructing critical infrastructure operators on fully separating operational technology and vital enabling systems from external connectivity in a crisis. It sets a three-month target for running essential services in complete disconnection.

What it counts as coupling is the useful part: shared routing and switching, common virtualisation and storage, Active Directory, DNS, DHCP, certificate services — and Network Time Protocol.

Dependencies that appear on no architecture diagram, and which quietly determine whether isolation is achievable at all.

Click any advisory to expand
Source: ASD’s ACSC alerts and advisories, cyber.gov.au, 2026.
Six advisories, one instructionAssess what is reachable from the internet, and reduce it. cPanel management interfaces. CMS admin panels. VPN gateways. Routers and firewalls. SD-WAN controllers. OT coupling points. Every one of them is externally visible — which means every one is assessable from outside, without touching a system.

Three conclusions

1. Almost none of it was a zero-day

cPanel: patched 30 April. The CMS campaign: ASD stated explicitly that the vulnerabilities were public and known with patches available. Fortinet: credentials, not exploits. The router campaign: poorly configured or unpatched equipment, running since 2015.

The gap is not intelligence about emerging threats. It is knowing what you run and whether it is reachable. That is an inventory problem wearing a vulnerability problem’s clothes — and inventory problems do not get solved by buying a threat feed.

2. Compromise of small organisations is a supply chain event

MSP-managed cPanel instances leading to customer compromise. Legitimate Australian business websites distributing infostealers. Many Australian SMEs impacted by the CMS campaign. A small business website is not only that business’s risk — it is a distribution node, and its harvested credentials become somebody else’s initial access.

This is also why the advisory audience problem matters. The organisations ASD names most frequently are the ones with no security function, no monitoring, and no reason to be reading cyber.gov.au on a Thursday.

3. ASD is describing an assessment gap it cannot close itself

The instruction is consistent: determine whether these interfaces are exposed. Not scan for vulnerabilities — establish what is reachable. Most organisations cannot answer that from internal sources, because internal records document what was intended rather than what answers.

The question ASD keeps asking is an external question. It has to be answered from outside.

What to do with this

ASD has done the analysis and published it, at no cost, six times this year. The advisories are not the hard part. Knowing whether they apply to you is.

Could you answer ASD’s recurring question?
Eight statements. Tick every one that is true of your organisation.
We could list every internet-facing management interface we operate, today, without a project.
We know every domain and subdomain that resolves to something we own.
No hosting control panel or CMS admin path is reachable from the general internet.
We have rotated administrative and VPN credentials on internet-facing appliances in the last 90 days.
We have checked whether our staff credentials appear in published infostealer corpora.
Someone in our organisation reads ASD advisories and assesses whether they apply to us.
We have mapped our dependencies on AD, DNS, DHCP, certificates and NTP.
Our suppliers receive the advisories that name their software.
Tick every statement that is true of your organisation
Source: ASD’s ACSC alerts and advisories, cyber.gov.au, 2026.
Passive only — no systems accessedBlackFlag Advisory answers ASD’s recurring question — what is exposed to the internet — using exclusively passive OSINT techniques and publicly available data. No systems, networks or accounts are accessed, probed or tested. Findings are mapped to the ISM, the Essential Eight, CPS 234, SOCI and the Privacy Act.
SourcesASD’s ACSC alerts and advisories published at cyber.gov.au during 2026, including active exploitation of cPanel/WHM; ClickFix distributing Vidar Stealer via WordPress (7 May 2026); reported widespread credential exposure affecting Fortinet firewalls and VPN gateways (18 June 2026); large-scale exploitation campaign targeting website content management systems (9 July 2026); joint international advisory on Russian FSB Centre 16 activity against network devices (9 July 2026); CI Fortify guidance on isolating vital systems (late July 2026); NSA and partner alert on Cisco SD-WAN exploitation; ASD Annual Cyber Threat Report 2024-25. Analysis by BlackFlag Advisory.

ASD Asks What You Expose.
We Answer It, From the Outside.

A BlackFlag Advisory passive assessment enumerates every internet-reachable interface, administrative console and forgotten host attributable to your organisation, mapped to the ISM and the Essential Eight. Passive only. No systems accessed.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.