Saturday February 21 is shaping up as a landmark day for AI-security convergence. Anthropic just dropped Claude Code Security — a dedicated vulnerability scanning product that uses AI to find flaws before attackers do. This is the first major AI lab to ship a first-party security scanner, and it signals the industry is moving from "AI helps defenders" rhetoric to actual tooling. Expect competitors to follow fast.
On the exploitation front, CISA added two Roundcube webmail flaws to its KEV catalog today, meaning federal agencies have days to patch. Roundcube is widely deployed in government and enterprise mail infrastructure — these are high-value targets for espionage groups. Meanwhile the BeyondTrust RCE story from yesterday is maturing: attackers are now using the foothold for web shells, backdoors, and full data exfiltration — the full kill chain is confirmed. The Cline CLI 2.3.0 supply chain attack (OpenClaw malware delivered via developer tools) is a direct strike at the AI dev toolchain, poisoning environments that security teams haven't started monitoring yet.
The PromptSpy Android malware story is the one to watch long-term. It's confirmed as the first Android malware to use generative AI at runtime — it calls Gemini to adapt its persistence behavior dynamically. That's not a gimmick. That's a new class of threat where the malware reasons about its environment in real time. Defense tooling built for static signatures is not equipped for this. The window between that story breaking and copy-cat variants is probably measured in weeks, not months.