Nearly 22,000 Microsoft Exchange servers remain unpatched for a critical authentication bypass vulnerability allowing complete mailbox takeover. PaperCut print management software, deployed across thousands of UK offices, is actively exploited for data theft days after a patch was released. A 33-hour BGP hijack of Softaculous infrastructure may have poisoned the hosting supply chain for small business websites. This briefing provides specific verification steps for IT providers, explains why the window between patch release and exploitation continues to shrink, and connects these incidents to wider supply chain and social engineering threats including Teams vishing campaigns and fake CAPTCHA attacks. For UK small businesses running on-premises Exchange, PaperCut installations, or shared hosting websites, today’s combination represents direct and immediate exposure requiring same-day action.