This episode covers three active threats with credible paths to UK small businesses. First, CISA has added a critical Windows IKE Extension remote code execution vulnerability to its Known Exploited Vulnerabilities catalogue, confirming active exploitation against network-reachable systems. Second, Clop ransomware has returned with purpose-built tooling targeting PTC Windchill in manufacturing supply chains, deploying custom web shells designed for credential harvesting and data exfiltration. Third, the Mirage2FA phishing-as-a-service platform is bypassing multifactor authentication through adversary-in-the-middle session token theft, with over four thousand confirmed Microsoft 365 victims. Mauven explains the technical mechanisms behind each threat, identifies the specific organisations at risk, and provides actionable steps that require no budget approval: verifying Windows patch status for IKE Extension, questioning manufacturing suppliers about Windchill patching, and reviewing Microsoft 365 conditional access policies to detect session anomalies. The episode also notes FBI confirmation of Medusa ransomware breaching over five hundred US critical infrastructure organisations using living-off-the-land techniques. All three primary threats demonstrate that speed of response, supplier questioning, and configuration review matter more than technology spending for most small business cyber resilience.