Two critical vulnerabilities demand immediate attention from UK businesses today. Researchers have disclosed SearchLeak, a prompt injection vulnerability chain in Microsoft 365 Copilot Enterprise that allows attackers to steal data from mailboxes, OneDrive, and SharePoint with a single malicious link. The attack exploits Copilot’s AI assistant functionality to exfiltrate sensitive information without further user interaction. Meanwhile, Cisco Talos reports active exploitation of authentication bypass vulnerabilities in Cisco Catalyst SD-WAN infrastructure by the sophisticated threat actor UAT-8616, who is deploying multiple command-and-control frameworks including Sliver and Godzilla for persistent network access. Most UK SMBs don’t run SD-WAN directly but face indirect exposure through managed service providers. Both threats target infrastructure that organisations trust by default but rarely examine closely. The episode provides specific verification steps for IT providers and MSPs, emphasising the gap between vendor patches and organisational verification as the primary source of security incidents.