This episode examines three active threat vectors affecting UK businesses in July 2026. First, a sophisticated Microsoft Teams impersonation campaign documented by Unit 42, in which attackers pose as IT helpdesk staff to deploy EtherRAT remote access trojans without requiring any technical vulnerability. Second, a global phishing operation delivering AsyncRAT and Remcos through multi-stage infection chains that use steganography and fileless execution to evade detection, targeting finance, HR, and procurement functions. Third, the UK government’s new voluntary cyber pledge, signed by sixty organisations including two currently managing recovery from significant recent breaches. The episode also covers UAT-7810’s operational relay box networks and the NCSC’s Cyber Shield initiative. Practical mitigations include restricting Teams external access, blocking Office macros by default, implementing helpdesk verification processes, and ensuring endpoint protection uses behavioural detection rather than signature matching alone. Each recommendation is actionable within the current week and addresses documented attack patterns actively being exploited against UK small and medium businesses.