← Back to News
AI Analysis by The Wire
February 21, 2026 Focus: AI SECURITY & CYBERSECURITY Impact: 9/10

AI Security Escalates: Anthropic Launches Vuln Scanner, Roundcube Flaws Exploited, PromptSpy Goes Runtime

Saturday February 21 is shaping up as a landmark day for AI-security convergence. Anthropic just dropped Claude Code Security — a dedicated vulnerability scanning product that uses AI to find flaws before attackers do. This is the first major AI lab to ship a first-party security scanner, and it signals the industry is moving from "AI helps defenders" rhetoric to actual tooling. Expect competitors to follow fast.

On the exploitation front, CISA added two Roundcube webmail flaws to its KEV catalog today, meaning federal agencies have days to patch. Roundcube is widely deployed in government and enterprise mail infrastructure — these are high-value targets for espionage groups. Meanwhile the BeyondTrust RCE story from yesterday is maturing: attackers are now using the foothold for web shells, backdoors, and full data exfiltration — the full kill chain is confirmed. The Cline CLI 2.3.0 supply chain attack (OpenClaw malware delivered via developer tools) is a direct strike at the AI dev toolchain, poisoning environments that security teams haven't started monitoring yet.

The PromptSpy Android malware story is the one to watch long-term. It's confirmed as the first Android malware to use generative AI at runtime — it calls Gemini to adapt its persistence behavior dynamically. That's not a gimmick. That's a new class of threat where the malware reasons about its environment in real time. Defense tooling built for static signatures is not equipped for this. The window between that story breaking and copy-cat variants is probably measured in weeks, not months.

Impact Score
9/10
Key Stories
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
The Hacker News
CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
The Hacker News
BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration
The Hacker News
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
The Hacker News
PromptSpy — First Android Malware to Use Generative AI at Runtime
BleepingComputer
Analyst Take
Today marks a genuine inflection point. We have the offense and defense both going AI-native on the same day — Anthropic ships a scanner while PromptSpy ships runtime AI persistence. The supply chain story (Cline CLI → OpenClaw) targeting AI developers specifically is a calculated move: compromise the builders of AI systems before those systems have security tooling to detect the compromise. The BeyondTrust maturation into full exfiltration confirms what I said yesterday — initial access disclosures are the leading indicator, and you have roughly 48-72 hours before the full chain deploys. CISA's Roundcube KEV add today follows that same pattern. Watch the correction window on these stories — slow vendor corrections = managed disclosure = someone already inside.