On 14 September 2026, attackers compromised Brevo’s infrastructure, injecting malicious code into JavaScript assets that reached over 100,000 customer websites. WordPress administrators had backdoor plugins silently installed while logged in; regular visitors faced ClickFix credential-harvesting overlays. Meanwhile, the Clop threat group continues exploiting CVE-2026-12569 in PTC Windchill with a custom web shell built for rapid data exfiltration, targeting UK manufacturing and engineering supply chains. A third campaign involves Settra ransomware maintaining persistence via MeshAgent, a legitimate remote monitoring tool that endpoint security often trusts by default. All three attacks share one structural weakness: reliance on third-party platforms, scripts, and tools that UK small businesses cannot directly audit or control. This briefing walks through the mechanics of each campaign, explains why supply chain compromise scales so effectively, and sets out the specific questions business owners must ask their web developers, IT providers, and managed service providers today. No patch can protect you from a script you load from someone else’s content delivery network, and no endpoint tool will flag an RMM agent it has been trained to trust. The NCSC has published supply chain guidance repeatedly; these campaigns demonstrate how rarely it is applied in practice.