A delayed patch for the RoguePlanet zero-day in Windows Defender has finally arrived, but working exploit code was publicly available for weeks before Microsoft closed the vulnerability. Mauven examines what that exposure window means for UK SMBs and why confirming patch deployment today is not optional. The Vidar infostealer campaign has quietly evolved beyond phishing emails into developer toolchains, with malicious Go modules staged across more than two hundred GitHub repositories designed to appear credible and actively maintained. Socket’s Operation Muck and Load research reveals how attackers are using commit farming and typosquatting to compromise software supply chains, particularly targeting payment SDK names. Finally, the NCSC has published guidance on Cyber Essentials Pathways, an alternate route to Cyber Essentials Plus certification that may reduce friction for smaller organisations pursuing verified assessment. Mauven explores what this policy shift signals about the growing expectation for Plus-level certification in public sector contracts and supply chain assurance. Three practical actions close the episode: verify the RoguePlanet patch has been applied, implement dependency verification for developers pulling open-source packages, and review the NCSC pathways guidance if you hold basic Cyber Essentials certification.