The Feb 21 threat cycle is dense and consequential. Anthropic launched Claude Code Security in limited preview today — an AI-powered codebase scanner that flags vulnerabilities and suggests patches before attackers can exploit them. The timing is pointed: CISA simultaneously added two Roundcube webmail flaws to its Known Exploited Vulnerabilities catalog, including CVE-2025-49113 (CVSS 9.9), a deserialization RCE that attackers weaponized within 48 hours of public disclosure. The patch-to-exploit window is collapsing.
BeyondTrust's CVE-2026-1731 (CVSS 9.9) continues its rampage — Palo Alto Unit 42 confirmed active exploitation across financial services, legal, healthcare, higher education, and wholesale sectors in the US, France, Germany, Australia, and Canada. The attack chain runs from reconnaissance through VShell web shells to full C2 and data exfiltration. Meanwhile, Cline CLI 2.3.0 was silently backdoored via a compromised npm publish token on Feb 17, installing OpenClaw on developer systems via postinstall hook — a textbook supply chain hit on the AI coding assistant ecosystem.
Rounding out the cycle: a sophisticated ClickFix campaign is delivering MIMICRAT (AstarionRAT), a custom C++ RAT with SOCKS5 tunneling, Windows token impersonation, and 22 post-exploitation commands — all hiding behind HTTP traffic that mimics legitimate web analytics. North Korea's IT worker fraud network also took a hit with a 5-year sentence handed to Ukrainian facilitator Oleksandr Didenko, who ran fake identity services helping DPRK workers infiltrate 40 US companies.