The dominant theme of February 21 is artificial intelligence being weaponized at scale against infrastructure while defenders scramble to patch two simultaneous CVSS 9.9 critical vulnerabilities. Amazon Threat Intelligence dropped a major report confirming a Russian-speaking, financially motivated threat actor used multiple commercial generative AI services to compromise over 600 FortiGate devices across 55 countries between January 11 and February 18, 2026. No FortiGate zero-day was needed — the actor exploited exposed management ports and weak single-factor credentials, using AI to automate what would otherwise require advanced technical skill. This is the democratization of sophisticated attack campaigns in real time.
On the vulnerability front, CISA added Roundcube CVE-2025-49113 (CVSS 9.9) to its Known Exploited Vulnerabilities catalog — a deserialization RCE flaw weaponized within 48 hours of public disclosure. Simultaneously, BeyondTrust CVE-2026-1731 (CVSS 9.9) is now confirmed in active ransomware attack chains, with Palo Alto Unit 42 documenting web shell deployment, C2 installation, lateral movement, and data exfiltration across financial services, healthcare, legal, and education sectors in the US, France, Germany, Australia, and Canada. Two CVSS 9.9 actively exploited vulns dropping on the same day is not noise — it's a pressure campaign.
On the defensive side, Anthropic launched Claude Code Security in limited preview — AI-powered codebase scanning that suggests patches for vulnerabilities. The timing is deliberate: as threat actors use AI to find and exploit vulns faster, Anthropic is pitching AI as the countermeasure. Meanwhile, Intellexa's Predator spyware is confirmed hooking iOS SpringBoard to conceal microphone and camera activity — hiding the recording indicators users rely on to detect surveillance. The mobile threat surface is expanding with no signs of slowing.