The most useful actions from this week's technology news are straightforward: check that Chrome has finished updating, remind your team to question unexpected sign-in codes, and make sure someone owns your security alerts. There are also new Microsoft security tools and Google search reports worth watching, with a few rollout details to understand first.
This is IT MGMT's recap for September 25, 2026, for business owners and people managing technology at home. It covers announcements from the preceding seven days through our Friday morning fact-check cutoff, shown below. It is a selection of useful developments, not every headline from the week.
Chrome has a new security update
Who this affects: People using Google Chrome on Windows, Mac or Linux, including managed business computers.
Google announced Chrome 154 for desktop on September 22. The release includes 108 security fixes and is rolling out over days and weeks, so availability can differ between computers. A long list of fixes does not, by itself, mean those issues were all being used in attacks. Google's release announcement
What I recommend: Save your work, open Chrome's menu, and choose Help → About Google Chrome. Let it check for updates, then relaunch if prompted. On a work computer managed by your IT provider, follow that provider's update process rather than trying to work around a policy. Google's update instructions
For a business, the useful question is whether updates actually finished across the team. A browser left open for weeks deserves a quick check before the next busy stretch.
A real Microsoft sign-in page can still be part of a scam
Who this affects: Businesses using Microsoft accounts, especially staff who handle invoices, approvals or shared email.
On September 22, Microsoft announced a disruption of EvilTokens, a platform used to compromise email accounts and support fraud. Its announcement describes attackers persuading people to enter a device code on a legitimate Microsoft sign-in page. The page can be real while the request that brought you there is fraudulent. Microsoft's announcement
What I recommend: If an unexpected email or message asks you to enter a code to view a document, stop and verify the request through a contact method you already trust. Ask whether you actually started the sign-in and whether the app or device being connected is one you intended to authorize.
If you already approved something suspicious, contact your IT provider promptly. Microsoft's technical guidance calls for investigating the account and revoking affected sessions and tokens; a password change alone may not resolve the access. Some access can persist briefly even after revocation, so this needs an incident response rather than a quick password reset and an assumption that everything is fine. Microsoft's device-code phishing guidance
I would also use this as a reminder to confirm payment-detail changes through a known phone number or another established channel. You can review the broader account-access responsibilities in our employee offboarding checklist.
Microsoft's new security-operations experience is a preview
Who this affects: Business owners and the IT teams or providers responsible for monitoring their systems.
On September 23, Microsoft announced its integrated security operations center, or ISOC, in Microsoft Defender. Microsoft describes it as bringing security monitoring, threat protection and context together for human analysts and AI agents. It is available in preview, which is different from a feature being generally available to every customer. Microsoft's announcement
What I recommend: Before adding another tool, ask your provider three questions:
- Who reviews our alerts, and during what hours?
- Which actions can happen automatically, and which need a person's approval?
- Who contacts us and takes responsibility when an alert becomes an incident?
Those answers are useful whether or not you adopt this preview. For a business with 5–100 users, I would start with the work that needs to be covered, then evaluate whether a tool improves it. Preview access, licensing and suitability need to be checked for your environment.
Our managed IT services and cybersecurity services explain the areas we can help you assess.
Google is adding reporting for visual searches
Who this affects: Business owners and the people responsible for their websites.
Google announced a global rollout of multimodal search reporting in Search Console on September 24. The new reporting helps website owners understand traffic from searches involving images, including Google Lens and Circle to Search. The announcement describes changes to the Search results and Generative AI features performance reports. Google's announcement
What I recommend: Ask whoever manages your website to check whether the new reporting is available and whether there is data for your site. A new report is a way to learn about activity; it is not evidence that your traffic has increased.
For a trade or property-management business, I would start with the images customers actually need: accurate service illustrations, permitted project photos and clear captions. Check that the pictures load properly and describe what they really show. Our website-development services cover websites and the business workflows around them.
Your end-of-week technology checklist
You do not need to adopt every new product to get something useful from this week's news.
| Check | Who can own it | What to confirm |
|---|---|---|
| Browser updates | You or your IT provider | Updates completed and any required relaunch happened. |
| Unexpected sign-in codes | Everyone using company accounts | People know how to verify and report a suspicious request. |
| Payment-detail changes | Owner or finance lead | Changes are confirmed through an established, independent channel. |
| Security alerts | Your IT provider or security lead | Monitoring hours, action authority and escalation contacts are clear. |
| Website reporting | Website owner or marketing lead | New reports are checked when available, without assuming a traffic increase. |
At home, start with the browser update and the sign-in reminder. At work, put a person's name next to each relevant item so the follow-through is clear.
If you want help deciding which actions matter for your business, book a conversation with IT MGMT. For help with your household's devices and accounts, use our Home IT booking option.
Source dates: September 22–24, 2026. Coverage window: September 18 at 2:12 a.m. through September 25 at 2:12 a.m. Eastern. Updates published after that cutoff are outside this recap. The EvilTokens item reports this week's announcement, not a claim that all of the underlying activity began this week.



