← Back to News
AI Analysis by The Wire
February 21, 2026 Focus: CYBERSECURITY Impact: 9/10

AI Goes Offensive: 600 FortiGates Breached by AI-Assisted Actor as CVSS 9.9 Double-Tap Hits BeyondTrust and Roundcube — Feb 21 Late Edition

The dominant theme of February 21 is artificial intelligence being weaponized at scale against infrastructure while defenders scramble to patch two simultaneous CVSS 9.9 critical vulnerabilities. Amazon Threat Intelligence dropped a major report confirming a Russian-speaking, financially motivated threat actor used multiple commercial generative AI services to compromise over 600 FortiGate devices across 55 countries between January 11 and February 18, 2026. No FortiGate zero-day was needed — the actor exploited exposed management ports and weak single-factor credentials, using AI to automate what would otherwise require advanced technical skill. This is the democratization of sophisticated attack campaigns in real time.

On the vulnerability front, CISA added Roundcube CVE-2025-49113 (CVSS 9.9) to its Known Exploited Vulnerabilities catalog — a deserialization RCE flaw weaponized within 48 hours of public disclosure. Simultaneously, BeyondTrust CVE-2026-1731 (CVSS 9.9) is now confirmed in active ransomware attack chains, with Palo Alto Unit 42 documenting web shell deployment, C2 installation, lateral movement, and data exfiltration across financial services, healthcare, legal, and education sectors in the US, France, Germany, Australia, and Canada. Two CVSS 9.9 actively exploited vulns dropping on the same day is not noise — it's a pressure campaign.

On the defensive side, Anthropic launched Claude Code Security in limited preview — AI-powered codebase scanning that suggests patches for vulnerabilities. The timing is deliberate: as threat actors use AI to find and exploit vulns faster, Anthropic is pitching AI as the countermeasure. Meanwhile, Intellexa's Predator spyware is confirmed hooking iOS SpringBoard to conceal microphone and camera activity — hiding the recording indicators users rely on to detect surveillance. The mobile threat surface is expanding with no signs of slowing.

Impact Score
9/10
Key Stories
AI-Assisted Actor Breaches 600+ FortiGate Devices in 55 Countries
TheHackerNews / Amazon Threat Intelligence
BeyondTrust CVE-2026-1731 (CVSS 9.9) Now Exploited in Ransomware Attacks
BleepingComputer / Palo Alto Unit 42
CISA Adds Roundcube CVE-2025-49113 (CVSS 9.9) to KEV — Weaponized in 48 Hours
TheHackerNews
Predator Spyware Hooks iOS SpringBoard to Hide Mic and Camera Activity
BleepingComputer
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
TheHackerNews
Analyst Take
The FortiGate story is the signal everyone should be reading carefully. Amazon's confirmation that a low-skill actor used commercial AI to breach 600 enterprise firewalls in five weeks is not a one-off — it's the new baseline. The barrier to executing sophisticated multi-phase attack campaigns has collapsed. Meanwhile the simultaneous CVSS 9.9 double-tap on BeyondTrust and Roundcube suggests coordinated exploitation timing, not coincidence. Patch windows are measured in hours now, not days — the Roundcube flaw was weaponized in 48 hours flat. The Predator iOS story is a quiet gut-punch: if users can't trust the camera and mic indicator lights, the hardware trust model on mobile is effectively broken for high-risk targets. And Anthropic's Claude Code Security launch is strategically timed but the real question is speed — defenders need AI patch suggestions deployed faster than attackers can weaponize the same vulns. The race is on, and right now offense has the initiative.