Two critical threats require immediate attention from UK businesses today. Cisco has disclosed an authentication bypass vulnerability in its Identity Services Engine with a maximum CVSS score of 10.0, and exploitation is already confirmed as active. ISE functions as a network gatekeeper for VPN, device compliance, and access control, making this vulnerability a direct path to your network perimeter. Separately, the GhostCode phishing technique weaponises Microsoft’s legitimate OAuth device code flow to bypass multi-factor authentication entirely. The attack arrives via business contact forms, presents victims with authentic Microsoft URLs, and produces valid session tokens that persist even after password resets. Analysis of ransomware activity in Japan reveals that 80 per cent of victims had capital under one billion yen, confirming that small and medium businesses are the majority of targets, not the exception. With Windows 11 24H2 reaching end of support in October 2026, unpatched endpoints remain a consistent entry point in post-breach analysis. This briefing provides specific actions for patching, MFA hardening, conditional access policies, and session revocation.