Threat Analysis: Active Exploits and UK SMB Risks

Threats & Attacks

Threat Analysis: Active Exploits and UK SMB Risks

This is your Daily Threat Analysis for 9 September 2026.

Let’s start with Microsoft’s latest Patch Tuesday – a veritable flood of 973 vulnerabilities, including 113 marked as critical and two zero-days actively exploited in the wild. These record-setting numbers raise significant concerns for UK small and medium businesses (SMBs) relying on unpatched systems. If your IT provider tells you that updates can wait, remind them that 113 critical vulnerabilities say otherwise.

The NCSC has long advocated for timely patch management. The fact we find ourselves repeatedly discussing these updates underscores how often this advice is ignored, perhaps at perilous cost.

Next up, more than 36,000 Plex Media Servers remain unsecured against newly disclosed vulnerabilities, leaving them juicy targets for cybercriminals. As attacks on Plex are neither new nor sophisticated, the ongoing lack of patch compliance is troubling. The Shadowserver Foundation’s alert will not lessen the anxiety for those affected but serves as a sharp reminder: neglecting server updates invites unnecessary risk.

If you’re running one of these platforms, it’s time to ask some hard questions about your security measures. The BlueMoon exploit chain showcases how rapidly nation-state actors can weaponise newly found weaknesses in Chrome and Windows. Seeing it adopted so swiftly by multiple state-aligned groups should prompt reevaluation of browser and OS update policies.

These cases highlight the critical need for robust patch management strategies and the dangers of deferred maintenance. You might think you’re too small to be targeted, but it’s precisely this thinking that threat actors exploit.

Before the next item: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically, and pass it to someone who needs the heads-up.

Sources

Filed under

  • smb-security
  • uk-business
  • ransomware-groups
  • credential-theft
  • patch-management