Two active exploitation campaigns are affecting UK small businesses today. Ransomware operators are exploiting a critical WatchGuard Firebox vulnerability that was added to CISA’s Known Exploited Vulnerabilities catalogue in December 2025, yet remains unpatched in many deployments nine months later. The flaw allows remote, unauthenticated code execution on internet-facing devices. Separately, four China-aligned threat actors have adopted an identical Chrome and Windows zero-day exploit chain within days of each other, enabling full system compromise through a single malicious webpage visit. The BlueMoon exploit kit combines CVE-2026-85046 in Chrome’s V8 engine with CVE-2026-85880 in the Windows kernel. Patches are available for both campaigns. Additionally, Cisco Secure Firewall Management Center is under active exploitation via two vulnerabilities that grant administrative control, with possible connections to the Qilin ransomware group. Today’s briefing provides specific remediation steps for each threat and examines why a nine-month-old vulnerability continues to find victims, highlighting fundamental patch management failures across the UK SMB sector. Mauven frames the discussion around visibility, accountability, and the compression of exploitation windows in modern threat environments.