This episode examines two unconnected but similarly exploitative campaigns targeting UK small businesses in August 2026. The first, SynkLoader, uses Microsoft Teams to impersonate IT helpdesk staff, delivering memory-resident malware through plausible maintenance requests. The attack succeeds because default Teams external access settings allow unrestricted messages from unknown tenants. The second involves a coordinated supply chain attack against three legitimate Rust programming language packages, injecting malicious code through a typosquatted dependency that executes during software builds. Both campaigns exploit trust in familiar channels rather than technical vulnerabilities. Mauven MacLeod explains why these attacks work, what they reveal about default configurations in SMB environments, and provides actionable steps: restricting Teams external federation, establishing clear IT contact protocols, auditing Rust dependencies for the malicious proc-macro1 package, and questioning software vendors about supply chain verification. The episode emphasises that effective defence requires deliberately changing insecure defaults, not advanced security tooling.