This episode examines three active threat campaigns with direct SMB relevance. Russian state group APT29 (Midnight Blizzard) is conducting large-scale credential harvesting through compromised hotel and conference Wi-Fi networks across the UK and Europe, specifically targeting business travellers. The operation exploits captive portal authentication flows to harvest Microsoft 365 credentials through spoofed login pages and device code phishing that bypasses MFA. A second campaign demonstrates AI-orchestrated exploitation of PaperCut print management software, progressing from vulnerability research to remote code execution in under four hours across 440+ installations. The episode also covers a maximum-severity GitLab path traversal vulnerability and recent Conti ransomware sentencing. Analysis focuses on the systematic targeting of authentication layers, the operational risk to SMBs from compromised cloud tenancies, and the acceleration of exploit development through AI automation. Practical guidance addresses device code flow controls, conditional access policies, VPN discipline for travelling staff, and the limitations of MFA as a single defensive layer.