CISA has confirmed active exploitation of a critical ConnectWise ScreenConnect vulnerability, the remote access tool used by countless UK IT providers to support small business clients. Attackers are targeting managed service providers to gain indirect access to entire client portfolios. Meanwhile, the GhostCode phishing campaign is bypassing traditional defences by abusing Microsoft’s legitimate OAuth device code flow, landing in inboxes through web contact forms and requiring no fake login pages. Finally, Google has patched a zero-day privilege escalation flaw in Pixel devices that was exploited in targeted attacks. This briefing explains why these threats matter to UK SMBs, what the attack patterns look like in practice, and what concrete actions business owners and IT managers should take today. Mauven MacLeod delivers the technical detail and the operational context that turns threat intelligence into defensible decisions.