Three critical threats demand immediate attention from UK small businesses today. DragonForce ransomware has deployed a custom backdoor that tunnels command-and-control traffic through Microsoft Teams relay infrastructure, exploiting implicit trust in cloud services. Multiple critical vulnerabilities in Fortinet’s FortiSandbox platform are being actively exploited in the wild, raising serious questions for businesses relying on managed security providers. Meanwhile, over 1.2 million WordPress sites have been compromised through a supply chain attack targeting OptinMonster, TrustPulse, and PushEngage plugins. CISA has also added a critical LiteSpeed cPanel vulnerability to its Known Exploited Vulnerabilities catalogue, affecting countless UK websites on shared hosting. Mauven MacLeod walks through the behavioural and operational gaps these threats expose, and provides four concrete actions businesses can take today: checking FortiSandbox patch status with managed security providers, verifying LiteSpeed plugin updates with hosting providers, auditing WordPress admin accounts, and reviewing Microsoft Teams external tenant access configurations. None of these actions require large budgets, but all require the willingness to ask direct questions of service providers.