This episode examines three active threats targeting UK small businesses through infrastructure that is often managed inattentively. PaperCut print management servers face active zero-day exploitation with no official vendor patch available, forcing organisations to choose between unvalidated emergency fixes or taking systems offline. A Microsoft Teams vishing campaign, running since January 2026, uses social engineering and the legitimate Windows Quick Assist tool to deploy the GoGRPC backdoor for ransomware operators. Research into ZBT router firmware reveals three pre-installed implants, including DARKLANTERN, an unauthenticated backdoor offering root shell access. The episode also covers critical ServiceNow vulnerabilities, over 8,300 unpatched Gitea instances facing active exploitation, and CISA’s observation that most exploited vulnerabilities in 2026 should have been eradicated decades ago. The common thread is infrastructure that organisations do not actively monitor: print servers, router firmware, and remote access tools that staff use without scrutiny. Mauven provides specific, actionable guidance for each threat, emphasising that the surfaces receiving least attention from defenders are those being studied most carefully by attackers.