Three critical threats demand immediate attention today. A remote code execution vulnerability in ServiceNow’s AI Platform (CVE-2026-6875) is now actively exploited in the wild, requiring urgent patch verification from direct users and managed service providers alike. Meanwhile, a vishing campaign running since April has been successfully defeating Microsoft 365 passkey enrolment through carefully scripted social engineering, targeting UK SMBs who adopted phishing-resistant MFA but failed to brief staff on the human attack vector. The third story examines FortiBleed, an industrial-scale FortiGate credential harvesting operation exposed when attackers left their staging server accessible, revealing 36 rented GPUs running distributed password cracking as a production workflow. The episode also covers the Cruciferra crypter service, which offers high-quality endpoint evasion as a purchased feature, and the Hugging Face breach involving an autonomous AI agent. Each story includes specific, actionable guidance for UK organisations, with particular emphasis on the ServiceNow vulnerability requiring same-day verification from users and their supply chain.