Three active threats demand immediate attention from UK small businesses today. ClickFix social engineering campaigns have matured into a multi-vector malware ecosystem using MSI packages, NodeJS execution, and fake CAPTCHA lures to deliver persistent backdoors across Windows and macOS systems. Attackers are abusing legitimate Windows tools and storing command-and-control addresses in blockchain smart contracts, making traditional network defences less effective. Check Point has confirmed active exploitation of CVE-2026-16232, a critical authentication bypass in SmartConsole that grants unauthenticated remote attackers full administrative access to firewall management servers. Organisations using managed service providers for firewall infrastructure need specific answers about exposure windows and remediation status. A remote code execution vulnerability in Zimbra Collaboration Suite has already compromised over 270 email servers, with the campaign ongoing. This episode provides actionable guidance on endpoint monitoring configuration, management server security reviews, and supplier due diligence for email hosting platforms. None of these threats are theoretical. All three are actively exploiting UK organisations today.