AI Analysis by The Wire
February 21, 2026
Focus: CYBERSECURITY
Impact: 9/10
CVSS 9.9 Triple Threat, AI-Powered Android Malware, and Anthropic Strikes Back — Feb 21 Threat Digest
February 21 is a heavy news day. Three separate CVSS 9.9 critical vulnerabilities are being actively exploited in the wild simultaneously — BeyondTrust Remote Support (CVE-2026-1731), Roundcube webmail (CVE-2025-49113), and the continued fallout from the Cline CLI 2.3.0 supply chain hit. BeyondTrust is the most alarming: Palo Alto Networks Unit 42 confirmed active exploitation across financial services, healthcare, legal, and higher education in the US, France, Germany, Australia, and Canada — attackers are deploying VShell web shells, establishing C2 infrastructure, and exfiltrating data. CISA separately added two Roundcube flaws to its KEV catalog today, with the CVSS 9.9 deserialization bug weaponized within 48 hours of disclosure. On the AI frontier, researchers at BleepingComputer flagged PromptSpy — the first known Android malware to use generative AI at runtime, leveraging Google's Gemini model to adapt its persistence behavior per device. Meanwhile Anthropic launched Claude Code Security in limited preview, an AI-powered codebase scanner that finds vulnerabilities and suggests patches — a direct counter-offensive to the same AI-driven attack automation threat actors are now deploying at scale.
Key Stories
BeyondTrust CVSS 9.9 RCE Actively Exploited — Web Shells, C2, Data Theft Across 6 Countries
The Hacker News / BleepingComputer
CISA Adds Two Roundcube Flaws to KEV — CVSS 9.9 Weaponized in 48 Hours
The Hacker News
PromptSpy: First Android Malware Using Generative AI at Runtime via Google Gemini
BleepingComputer
Anthropic Launches Claude Code Security — AI Scans Codebases for Vulnerabilities
The Hacker News
Cline CLI 2.3.0 Supply Chain Attack — OpenClaw Silently Installed on Developer Machines
The Hacker News
Analyst Take
Today's threat landscape reads like a stress test designed to break response teams simultaneously. Three CVSS 9.9 actives at once is not coincidence — it reflects attacker awareness that defenders have finite bandwidth. When BeyondTrust burns while Roundcube smolders and the supply chain is leaking, security teams triage by sector and miss lateral vectors. PromptSpy is the story I'm watching closest: the moment malware starts using live LLM calls to adapt in real-time, static signature detection becomes structurally obsolete. Anthropic's Claude Code Security launch today is a direct acknowledgment of that arms race — the same AI that finds your bugs can now be weaponized to find everyone else's. The correction window is shrinking. Roundcube's 48-hour exploit turnaround is the new baseline, not the exception.