Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Navigating cyber threats guide for Australian small businesses

An authentication bypass is exactly what it sounds like: a flaw that lets someone skip the login step entirely. Instead of stealing a password or tricking a staff member, an attacker sends a specially crafted request that fools the system into treating them as an already-approved user. No credentials, no prompt, no warning.

The term is everywhere this week because of CVE-2026-20079, a maximum-severity (CVSS 10.0) authentication bypass in Cisco’s Secure Firewall Management Center. Cisco has now confirmed it’s being actively exploited, and CISA has ordered US federal agencies to patch it by 12 September. Cisco’s own Talos researchers watched attackers use the hole to plant a web shell and quietly harvest credentials straight off the appliance.

Here’s why this one stings for smaller businesses: an authentication bypass on a firewall or its management console hands an attacker the keys to the very device meant to keep everyone else out. In the SMB networks we look after across the Northern Beaches and Central West NSW, the security appliance is often the one box nobody has logged into since the day it was installed — no patch schedule, no admin MFA, no one reading its logs. That’s precisely the blind spot these flaws are built to exploit.

If you run any internet-facing appliance — a firewall, VPN or mail gateway — three things matter: patch it quickly, put multi-factor authentication on its admin login, and make sure someone is actually watching it. Not sure who’s doing that for your business? That’s the conversation worth having. Our cybersecurity team can review your edge devices and lock them down.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →