February 21 is shaping up as one of the heaviest news cycles of the year across AI and cybersecurity. Anthropic today launched Claude Code Security in limited research preview — an AI-powered codebase scanner that detects vulnerabilities and suggests patches before attackers can weaponize them. The timing is pointed: this drops the same day CISA added two Roundcube flaws to its KEV catalog, including CVE-2025-49113 (CVSS 9.9), a deserialization RCE that attackers weaponized within 48 hours of disclosure. The second Roundcube flaw, CVE-2025-68461, is an XSS via SVG animate tags.
BeyondTrust's CVE-2026-1731 (CVSS 9.9) continues to bleed — Palo Alto's Unit 42 confirmed active exploitation across financial services, legal, healthcare, higher ed, and more across the US, France, Germany, Australia, and Canada. Attackers are deploying VShell, web shells, C2 backdoors, and running full lateral movement campaigns. Meanwhile, the Cline CLI 2.3.0 supply chain attack is a new vector — a compromised npm publish token silently installed OpenClaw AI agent on developer machines via a postinstall hook. No malicious behavior confirmed yet, but unauthorized agent installation on dev boxes is a serious trust violation.
The pattern this cycle is clear: AI is both the sword and the shield. Anthropic positions Claude as a defender. Threat actors are using AI-powered tools like PromptSpy (abusing Gemini) and supply chain vectors to automate intrusion. The window between patch and exploit is now measured in hours, not days. Organizations running Roundcube or BeyondTrust without patches applied are actively compromised right now.