CISA confirms ransomware gangs are actively exploiting a critical JetBrains TeamCity vulnerability patched in July, eleven weeks after the fix became available. UK SMBs face supply chain exposure through managed service providers and development partners with access to production environments. Meanwhile, the Canadian Centre for Cyber Security reports active exploitation of a four-month-old Roundcube Webmail code injection flaw that requires no user interaction beyond reading email. The ClickFix social engineering technique continues to deliver multiple malware families including PavinLoader and AvisLoader, which uses peer-to-peer infrastructure designed to outlast traditional takedown responses. This briefing examines the persistent gap between patch availability and patch application, and provides actionable guidance for UK small and medium businesses on verifying third-party patch status, confirming email infrastructure security, and implementing staff awareness controls that technical measures cannot replace.