CISA has confirmed active exploitation of a critical Splunk Enterprise vulnerability, with a patch deadline of 22 June 2026 for US federal agencies. UK organisations face the same threat but lack a legal mandate. Separately, over 140 npm packages in the mastra ecosystem were compromised through account takeover, pushing typosquatted dependencies that harvest credentials on installation. A second npm attack exploited a lapsed maintainer email domain to compromise node-ipc, exfiltrating SSH keys and cloud credentials via DNS. A third attack targeted PyPI’s Microsoft DurableTask client through a stolen GitHub account. The Okendo Reviews widget, used by over 18,000 e-commerce brands, was also found to contain malicious JavaScript in May 2026. These attacks share a common thread: patient exploitation of trust frameworks in developer tooling and monitoring platforms. Mauven provides actionable steps for UK businesses to verify patch status, audit dependency chains, review DNS monitoring capability, and confirm e-commerce widget remediation before the weekend.