Let me ask you something: when you lock your office at the end of the day, do you check the doors and windows?
Of course you do. You want to know that nobody can walk in, reach your records, or shut down your business while you are away.
Now imagine one door being opened by an automated machine, another being unlocked with a stolen key, and a third being opened by an employee who thought a fake safety check was legitimate.
That is the pattern behind this week’s biggest cybersecurity stories.
For small businesses in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and throughout Missouri, the message is clear: attackers are moving faster, trusted websites can host dangerous content, and old vulnerabilities remain useful when nobody closes the door.
Here is what you need to know.
1. AI-run ransomware has moved from theory to reality
Microsoft’s 2026 Digital Defense Report, released October 1, documents a major shift in how cyberattacks are being conducted.
In July 2026, Sysdig documented JADEPUFFER, described as the first fully autonomous AI-orchestrated ransomware extortion attack. Instead of relying on a person to guide every stage, an AI-driven system handled key parts of the operation, including finding targets, moving through systems, and managing the extortion process.

That does not mean every ransomware attack is now fully autonomous. Most major intrusions still involve human decision-making.
But the direction is concerning.
Microsoft reports that the median time from vulnerability discovery to active exploitation has fallen below 24 hours. Meanwhile, enterprise patching can still take 30 to 60 days.
That is a dangerous gap.
Nearly 40,000 CVEs, or publicly documented software vulnerabilities, appeared during the first half of 2026 alone. The year is on track for approximately 72,000 vulnerabilities.
Phishing also jumped from 7% to 23% of intrusions. That is more than three times the previous share, and it reflects how artificial intelligence helps criminals create convincing, personalized messages at scale.
And here is another important statistic: 78% of attack techniques against critical infrastructure relied on cloud identity abuse.
What it means for your business
Your business does not need to operate critical infrastructure to face the same basic risks.
Your email, cloud storage, accounting platform, Microsoft 365 environment, and remote-access tools all depend on identity. If an attacker steals a password and bypasses weak login protections, they may not need to break through your firewall at all.
Microsoft’s top recommendation is straightforward: treat phishing-resistant MFA and passkeys as a baseline.
Start by reviewing:
- Email and cloud account MFA
- Administrator and financial accounts
- Remote access and VPN logins
- Password reuse and exposed credentials
- User permissions and inactive accounts
- Backup access controls
For more practical guidance, read our recent article on St. Louis cybersecurity controls insurers now expect.
2. Cisco’s emergency SD-WAN flaw shows why internet-facing devices need priority
CISA added CVE-2026-76504, a Cisco Catalyst SD-WAN Manager hex encoding vulnerability, to its Known Exploited Vulnerabilities catalog on September 30.
The vulnerability carries a CVSS score of 9.8, which places it in the critical range. More importantly, CISA says the flaw is being exploited in the wild.
The federal remediation deadline was October 3, 2026.
That deadline applies to federal agencies, not every private business. But the risk applies to any organization using an affected, internet-facing device.

What it means for your business
You may not manage your network equipment directly.
Perhaps a managed network provider installed your SD-WAN system. Perhaps a former employee configured it years ago. Maybe you are not even sure which Cisco devices are currently exposed.
That uncertainty is the problem.
Ask your IT provider or network vendor:
- Do we use Cisco Catalyst SD-WAN Manager?
- Is our version affected by CVE-2026-76504?
- When was the device last patched?
- Was the management interface exposed to the internet?
- Have you checked logs for signs of compromise?
- What mitigation is in place if patching is delayed?
Patching is not just about laptops. Firewalls, routers, VPN appliances, cloud gateways, and other internet-facing systems deserve priority because attackers can reach them from anywhere.
This is one reason managed IT services in St. Louis should include asset inventories, vulnerability tracking, patch management, and documented escalation.
3. The fake ChatGPT installer proves that a trusted domain is not enough
This week’s most unsettling social-engineering story involved a malicious Custom GPT hosted on the real chatgpt.com domain.
The fake model was called “Plus 5.6.” It told users that ChatGPT had “limited availability” and directed them to what appeared to be a Cloudflare CAPTCHA.
The page then instructed users to copy and paste a PowerShell command into Windows Terminal.
That command installed an eight-stage remote access Trojan, or RAT. A RAT gives criminals the ability to monitor and control an infected computer remotely.

OpenAI removed the first malicious Custom GPT. Forty-eight hours later, researchers found an almost identical replacement.
What it means for your business
Here is the rule your team should remember:
No legitimate website should ask you to paste a command into PowerShell or Windows Terminal to complete a CAPTCHA, verify your identity, fix an outage, or download an application.
Not ChatGPT. Not Microsoft. Not Cloudflare. Not your bank.
The danger here is that the domain was real. The page looked familiar. The user did not have to visit a typo-filled imitation website.
Trusting the address bar was not enough.
Train employees to:
- Stop when a web page asks for a terminal command
- Avoid “fixes” that require PowerShell or Command Prompt
- Download software only from approved sources
- Contact IT before installing an unfamiliar tool
- Report suspicious pages immediately
- Close the browser instead of following urgent instructions
If someone already pasted the command, disconnect the computer from the network and contact your IT or security provider immediately. Do not continue using the device for email, banking, or customer work.
You can read the original reporting on the fake ChatGPT Custom GPT campaign.
4. Warlock ransomware is still exploiting old SharePoint weaknesses
Warlock ransomware, associated with Longlegs and Storm-2603, continues to exploit year-old SharePoint “ToolShell” flaws.
Recent victims reportedly included a water utility, a telecommunications provider, a regional government body, and a university.
In one intrusion, attackers disabled security software on more than 40 hosts in approximately two hours. They then deployed ransomware to at least 33 hosts through the domain’s SYSVOL share.
SYSVOL is a normal part of a Windows domain environment. Because it replicates across domain controllers, attackers can abuse it to distribute malicious files throughout a network.
What it means for your business
If you operate on-premises SharePoint Server and have not confirmed that the relevant patches and mitigations are in place, the door may still be open.
The fact that a vulnerability is a year old does not mean it is no longer dangerous. In fact, old flaws can remain attractive because attackers know some organizations delay patching systems that are difficult to maintain.
Review:
- On-premises SharePoint versions
- Microsoft security updates and mitigations
- SharePoint web-server logs
- Unexpected files in application directories
- New administrator accounts
- Unusual PowerShell activity
- Security tools that were disabled
- SYSVOL changes and unexpected executable files
The Warlock ransomware and SharePoint report offers additional technical detail.
For a broader look at recovery readiness, see our article on outdated backups and ransomware exposure.
Other developments worth watching
CISA added two Zammad vulnerabilities, CVE-2026-102489 and CVE-2026-102490, to its Known Exploited Vulnerabilities catalog on October 2.
The Citrix NetScaler zero-days CVE-2026-88771 through CVE-2026-88778 are also still being exploited globally.
If your business uses Zammad, Citrix NetScaler, SharePoint Server, or internet-facing Cisco equipment, do not rely on a general “we patch regularly” answer. Confirm the exact product, version, exposure, patch status, and signs of compromise.
You can review CISA’s Known Exploited Vulnerabilities catalog for current entries.
What to do this week
You do not have to fix everything in one afternoon.
Start here:
- Deploy phishing-resistant MFA: Prioritize email, cloud, administrator, financial, and remote-access accounts.
- Patch internet-facing systems first: Review firewalls, VPNs, routers, SharePoint, SD-WAN equipment, and public-facing applications.
- Check offline and tested backups: Confirm that at least one recovery copy cannot be altered by ordinary network credentials.
- Inventory internet-exposed assets: Identify devices, applications, remote tools, and services reachable from outside your network.
- Apply least privilege: Give users and applications only the access they need.
- Review suspicious software activity: Pay special attention to PowerShell, new remote-control tools, and unexpected administrator accounts.
- Make sure someone is watching: Alerts are not protection if nobody investigates them.
Platinum Web Services provides personalized cybersecurity solutions for small business, ransomware protection, network security, cloud services, and St. Louis IT support for small business.
We help businesses in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and throughout Missouri build practical defenses without adding unnecessary complexity.
Frequently asked questions
Does a small business really need phishing-resistant MFA?
Yes. Passwords can be stolen, reused, guessed, or captured through fake login pages. Phishing-resistant MFA and passkeys make it much harder for an attacker to reuse stolen credentials.
What should I do if an employee pasted a command from a website?
Disconnect the device from the network if possible, do not delete evidence, and contact your IT or security provider immediately. Change potentially exposed passwords from a clean device after your provider evaluates the incident.
How quickly should we patch a critical internet-facing vulnerability?
As quickly as your business can safely do so, with priority given to vulnerabilities being actively exploited. A standard monthly patch cycle may not be appropriate for a critical flaw listed in CISA’s KEV catalog.
Are cloud services automatically safer than on-premises systems?
Not automatically. Cloud platforms can provide strong security features, but weak identities, excessive permissions, stolen credentials, and poor configuration can still create serious exposure.
Get a practical security review
The news can feel overwhelming. But the goal is not to panic every time a new vulnerability appears.
The goal is to know what you own, who can access it, how quickly you can patch it, and whether you can recover if something goes wrong.
Platinum Web Services offers a free IT and security assessment for small businesses. We provide 24/7 emergency support and 24/7 IT support for urgent technology issues.
Regular service availability includes Monday through Friday, 8:00 AM–5:00 PM, Saturday, 9:00 AM–3:00 PM, with 24/7 emergency support.
Call (636) 204-5335, email support@platinumwebservices.net, or visit us at:
Platinum Web Services
7827 Town Square Ave, 104-1184
O’Fallon, MO 63368
You lock your physical doors because protecting your business matters. This week’s news is a reminder to check the digital doors, too.
SEO and social metadata
- Rank Math focus keyword: St. Louis cybersecurity
- Category: Blog
- Open Graph title: News Roundup: AI-Run Ransomware, Cisco's Emergency Patch, and the Fake ChatGPT Installer St. Louis Businesses Need to Know About
- Open Graph description: AI-run ransomware, an actively exploited Cisco flaw, a fake ChatGPT installer, and ongoing SharePoint attacks have clear lessons for St. Louis small businesses. Learn what to do this week.
- Open Graph image: https://cdn.marblism.com/1duhrTcnBmM.webp
- Open Graph image dimensions: 1200×630
- Twitter card: Summary Card with Large Image
- Twitter username: @platinumws


0 Comments