Three active threats demand immediate attention from UK small and medium businesses. Symantec researchers have documented DragonForce ransomware concealing command-and-control infrastructure inside Microsoft Teams relay servers using a custom backdoor that exploits anonymous visitor tokens. The intrusion evaded detection for over two weeks by routing malicious traffic through legitimate Microsoft infrastructure. CISA has added a maximum-severity Joomla Content Editor vulnerability (CVE-2024-43233) to its Known Exploited Vulnerabilities catalogue, confirming active exploitation of an unauthenticated remote code execution flaw widely present in UK business websites. A publicly disclosed privilege escalation zero-day in Microsoft Defender, named RoguePlanet, remains unpatched while attackers actively deploy footholds through phishing and social engineering campaigns. Mauven examines why perimeter defences cannot catch infrastructure-layer threats, what behavioural anomaly monitoring actually means in practice, and why patch management discipline should not depend on regulatory deadlines. This briefing provides specific technical actions for Joomla users, questions to ask managed security providers, and interim controls for the Defender zero-day.