← Back to News
AI Analysis by The Wire
February 21, 2026 Focus: CYBERSECURITY Impact: 9/10

Anthropic Fires Back with AI Defense as Roundcube, BeyondTrust, and Cline Hit by Triple CVSS 9.9 Storm

February 21 is shaping up as one of the heaviest news cycles of the year across AI and cybersecurity. Anthropic today launched Claude Code Security in limited research preview — an AI-powered codebase scanner that detects vulnerabilities and suggests patches before attackers can weaponize them. The timing is pointed: this drops the same day CISA added two Roundcube flaws to its KEV catalog, including CVE-2025-49113 (CVSS 9.9), a deserialization RCE that attackers weaponized within 48 hours of disclosure. The second Roundcube flaw, CVE-2025-68461, is an XSS via SVG animate tags.

BeyondTrust's CVE-2026-1731 (CVSS 9.9) continues to bleed — Palo Alto's Unit 42 confirmed active exploitation across financial services, legal, healthcare, higher ed, and more across the US, France, Germany, Australia, and Canada. Attackers are deploying VShell, web shells, C2 backdoors, and running full lateral movement campaigns. Meanwhile, the Cline CLI 2.3.0 supply chain attack is a new vector — a compromised npm publish token silently installed OpenClaw AI agent on developer machines via a postinstall hook. No malicious behavior confirmed yet, but unauthorized agent installation on dev boxes is a serious trust violation.

The pattern this cycle is clear: AI is both the sword and the shield. Anthropic positions Claude as a defender. Threat actors are using AI-powered tools like PromptSpy (abusing Gemini) and supply chain vectors to automate intrusion. The window between patch and exploit is now measured in hours, not days. Organizations running Roundcube or BeyondTrust without patches applied are actively compromised right now.

Impact Score
9/10
Key Stories
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
The Hacker News
CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
The Hacker News
BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration
The Hacker News
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
The Hacker News
ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware
The Hacker News
Analyst Take
The 48-hour weaponization window on Roundcube is the story within the story. FearsOff's Kirill Firsov reported the bug, it got patched, and attackers had a working exploit before the ink dried. That's not a patch management failure — that's a structural collapse of the traditional disclosure-patch-remediate timeline. Anthropic launching Claude Code Security today is either brilliant timing or deliberate counter-messaging, but either way it signals the industry is waking up to the fact that AI-speed discovery needs AI-speed defense. The Cline supply chain attack is the one I'm watching closest — compromising AI coding tools means you own the developer's entire workflow. That's a force multiplier unlike anything we've seen from traditional supply chain attacks.