Today’s briefing covers two active threats facing UK small businesses. First, CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed to be under active exploitation by the Canadian Centre for Cyber Security and verified by BleepingComputer. The flaw permits unauthenticated remote code execution with a CVSS score of 10.0, affecting legacy installations across SMB websites, internal applications, and shared hosting environments managed by MSPs. Second, a criminal group designated CL-CRI-1147 and tracked as Pink is conducting voice phishing campaigns that impersonate IT helpdesks to extract credentials and bypass multi-factor authentication. Once inside, the group exfiltrates data from SharePoint and OneDrive, then issues a seventy-two-hour ransom demand. The tactic closely mirrors operations by UNC3753, documented by Google Cloud Threat Intelligence. Both threats exploit different attack surfaces but share a common trait: neither discriminates by organisation size. Mauven provides specific procedural guidance for patching, MSP coordination, staff briefings on vishing, and audit log monitoring to detect bulk data downloads before ransom demands arrive.