Cybersecurity News · Reviewed 27 September 2026
Your accounts, college projects and creator pages deserve protection. Here are three recent security reports, explained without the jargon. This is a dated editorial roundup, not a live alert feed.
1. Microsoft disrupts an AI-enabled fraud service
Source date: 22 September 2026. Microsoft says it worked with industry partners and law enforcement to disrupt EvilTokens. The service used AI to analyse compromised inboxes and help criminals identify fraud opportunities. Disruption does not mean similar scams have disappeared.
Your move: independently verify unexpected requests to change payment details or send money. Use a known phone number or a separate trusted channel, even when the email appears to come from someone you know.
Read Microsoft’s original report
2. Fake passkey and security-support messages target accounts
Source date: 9 September 2026. Microsoft documented social engineering that leads to compromised identities and cloud data access. Attackers can abuse authentication enrolment after gaining access. This is not evidence that passkeys themselves are broken.
Your move: treat an unsolicited call asking you to register a new sign-in method as suspicious. Contact your college or workplace IT team through its official channel. Never approve a login you did not initiate; report unfamiliar devices or authentication methods.
Read Microsoft’s security analysis
3. Chrome 154 brings desktop security fixes
Source date: 22 September 2026. Google announced Chrome 154 for Windows, Mac and Linux, with 108 security fixes and a gradual rollout. A security fix does not automatically mean every issue was actively exploited.
Your move: open Chrome’s menu, choose Help → About Google Chrome, allow the available update to finish and relaunch when prompted. Use the built-in updater instead of a download link in a pop-up.
Read Google’s release announcement
Your five-minute account check
- Use a different password for each important account.
- Enable a passkey or multi-factor authentication where supported.
- Keep recovery details current and store recovery codes securely.
- Review signed-in devices and remove sessions you do not recognise.
- Keep a separate backup of important documents and creative work.
How we build trust
We link to original announcements, distinguish source dates from our review date and separate reported facts from our practical advice. This roundup is not a claim that your device is infected. For corrections, email sunmaddy@mvrethnics.com with the article link and supporting evidence.
Explore more ideas in Technology, or read how we approach our content.



