Two Microsoft vulnerabilities demand immediate attention from UK small businesses running Windows endpoints and Microsoft 365. CISA has confirmed active ransomware exploitation of the Windows Task Host privilege escalation flaw, four months after its initial disclosure. This vulnerability allows attackers who have gained initial access to escalate to system-level privileges, enabling lateral movement and full ransomware deployment. Separately, Microsoft has disclosed CVE-2026-24301, a command injection vulnerability in Copilot that enables information disclosure across the entire Microsoft 365 data estate. Because Copilot operates within user permission contexts, the vulnerability exposes whatever data those users can access, including financial records, HR files, and confidential client information. Researchers have also documented C2Looper, a Rust-based backdoor that uses GitHub for command-and-control traffic and connects to ClickFix infection chains. Together, these developments illustrate a complete ransomware kill chain from initial access through privilege escalation to deployment. Organisations must confirm Windows patch status today, review Copilot access permissions against the principle of least privilege, and brief staff on ClickFix lures that present as fake browser error messages.