Cyber SOTU: The Week the Internet Needed a Patch (Sep 10–17, 2026)
Patch o'clock. The cat hits the big red button; the gremlins scatter. That's basically this entire week.
Welcome to the first Cyber SOTU — the State of Cyber, delivered every Sunday. Five stories from the week that mattered, translated into plain English: what happened, why you should care, and what to do about it.
🚨 Cisco's perfect-10 zero-day is being exploited right now
What happened: Cisco disclosed CVE-2026-76460 — an authentication bypass in Identity Services Engine (ISE) rated a perfect CVSS 10.0 — and confirmed it's already being exploited in the wild. In the same week, Cisco also patched CVE-2026-76461 (CVSS 9.8) in Secure Email Gateway.
Why it matters: ISE is the bouncer for enterprise networks — it decides who gets on. An auth bypass there means attackers walk in without credentials. When a vendor ships two criticals in one week and one is already exploited, that's not a drill.
What to do: If you run ISE or Secure Email Gateway, patch immediately and hunt for indicators of compromise in Cisco's advisory. Everyone else: this is why your security team looked tired this week. Source: The Register →
📱 Your Pixel's modem had a zero-day — CISA gave everyone 3 days
What happened: Google patched CVE-2026-58704 (CVSS 8.0), a zero-day in the Pixel's cellular modem that was exploited in limited, targeted attacks. CISA added it to its Known Exploited Vulnerabilities catalog with a 3-day remediation deadline for federal agencies.
Why it matters: Modem bugs sit below the operating system — they're deep, nasty, and hard to see. And a 3-day federal deadline is CISA-speak for "this one is genuinely bad, move."
What to do: Install the September Pixel security update. That's it. That's the whole step. Source: TechRepublic →
🪪 150 million driver's licenses: confirmed stolen
What happened: ID-verification company IDScan.net confirmed hackers stole driver's licenses from its cloud — full names, license numbers, and other government ID numbers. The breach surfaced when Brian Krebs found the data for sale on the dark web (he verified his own record in the listing); the shop vanished hours after his story published.
Why it matters: You can't rotate a driver's license number like a password. This data fuels identity theft and convincing phishing for years — and the timestamps reportedly lined up with times people handed over licenses while renting cars or traveling.
What to do: Freeze your credit at all three bureaus, watch for phishing that uses real details about you, and consider an IRS Identity Protection PIN. Source: TechCrunch →
🕵️ Two Chinese spy groups, one exploit chain
What happened: Volexity reported that two China-linked groups — UTA0560 and JungleBamboo (APT31) — used the identical Chrome-to-Windows zero-day chain against NGOs starting September 1: CVE-2026-85046 (Chrome V8), CVE-2026-87491 (Chrome sandbox escape), CVE-2026-85880 (Windows privilege escalation). Same shellcode, different malware.
Why it matters: Two twists. First, shared exploit supply chains: the chain may have been sold to multiple operators. Second, the patch gap: the Chrome bug was already fixed upstream in Chromium, but the fix hadn't shipped to Chrome users yet — so it was effectively a zero-day in practice. Upstream fix ≠ users protected.
What to do: Update Chrome and apply September's Windows Patch Tuesday (which covers the Windows piece). Source: Volexity →
🤖 A WeChat worm built with AI in ten days
What happened: Researchers at Calif built "WeWorm" — a zero-click worm for WeChat. One incoming call from someone on your friend list could take over your WeChat account. No answering, no clicking, no tapping. AI found the VoIP memory-corruption bug and wrote the first working exploit in about two days; the full worm took roughly ten. Tencent mitigated it server-side; there's no evidence it was ever used in the wild.
Why it matters: The worm isn't the headline — the timeline is. Work that used to take a skilled team months took days with AI assistance. Exploit development just got a lot cheaper, which means defenders' patching discipline matters more than ever.
What to do: Update WeChat (8.0.76+ on iOS, 8.0.77+ on Android). The server-side fix covers everyone regardless. Source: The Register →
Your Sunday homework, courtesy of this week's SOTU:
- Chrome updated past the September fixes
- Windows September Patch Tuesday applied
- Pixel September security update installed
- Cisco ISE / Secure Email Gateway patched (if you run them)
- WeChat updated — or just let the server-side fix do its thing
- Credit frozen at all three bureaus (post-IDScan, just do it)
That's the state of cyber for the week of September 10–17. Patch your stuff, freeze your credit, and I'll see you next Sunday. 🐱
Every Sunday at 7 PM ET, right here and on the mckai.net homepage. Past editions live in the blog under the NEWS tag.