← Back to News
AI Analysis by The Wire
February 21, 2026 Focus: AI-AUGMENTED CYBER THREATS Impact: 9/10

AI Goes Fully Offensive: 600 FortiGates Down, CVSS 9.9 Double-Tap Active, Predator Spyware Kills iOS Indicators — Feb 21 Late-Night Edition

The AI-as-weapon story just got a primary source: Amazon Threat Intelligence confirmed a Russian-speaking financially motivated actor used commercial generative AI tools to breach 600+ FortiGate devices across 55 countries between January 11 and February 18. No FortiGate vulnerabilities were exploited — the AI simply made an unsophisticated actor fast and scalable enough to hammer exposed management ports with weak single-factor creds at industrial scale. Amazon CISO CJ Moses called it out directly: this is what happens when AI lowers the barrier to entry for commodity attackers. Separately, Anthropic answered the threat with the same tool — Claude Code Security launched today in limited preview, scanning codebases for vulnerabilities and suggesting patches before adversaries can find them first.

On the exploit front, two CVSS 9.9 critical flaws remain the headline risk. BeyondTrust CVE-2026-1731 is now confirmed by Palo Alto Unit 42 as being weaponized for web shells, C2 installs, lateral movement, and data theft across financial, legal, healthcare, and tech sectors in the US, France, Germany, Australia, and Canada. Roundcube CVE-2025-49113 (also 9.9, deserialization RCE) was added to CISA's KEV catalog today after attackers weaponized it within 48 hours of public disclosure. Both are in active exploitation — patch windows are effectively zero.

Mobile threat landscape deepened with two significant reports. Intellexa's Predator spyware now hooks iOS SpringBoard to suppress the camera and microphone indicator dots while silently streaming to operators — a direct attack on Apple's privacy UI. And PromptSpy, the first confirmed Android malware using Google's Gemini model at runtime to adapt persistence across device configurations, signals that AI-augmented malware is no longer theoretical. Supply chain also took a hit: Cline CLI 2.3.0 was poisoned via a compromised npm token to silently install OpenClaw on developer machines via postinstall script.

Impact Score
9/10
Key Stories
AI-Assisted Actor Breaches 600+ FortiGate Devices in 55 Countries
TheHackerNews / Amazon Threat Intelligence
BeyondTrust CVE-2026-1731 (CVSS 9.9) Exploited for Web Shells and Data Theft
BleepingComputer / Palo Alto Unit 42
Roundcube CVSS 9.9 RCE Added to CISA KEV — Weaponized in 48 Hours
TheHackerNews / CISA
Anthropic Launches Claude Code Security for AI-Powered Vuln Scanning
TheHackerNews / Anthropic
Predator Spyware Hooks iOS SpringBoard to Hide Mic and Camera Activity
BleepingComputer
Analyst Take
The FortiGate story is the most structurally important thing that dropped today. Amazon just confirmed with receipts what we've been flagging for weeks: AI doesn't need to be sophisticated to be dangerous. It just needs to be fast and scalable, and commodity actors now have that. The 600-device breach without a single CVE is the proof of concept that changes the threat model. Every exposed management interface on weak auth is now effectively a target with a robot running brute-force 24/7. The Anthropic counter-move with Claude Code Security is the right answer directionally — use AI to find holes before the attackers do — but it's enterprise-only preview, so the gap between defender AI and attacker AI is still live. CVSS 9.9 double-tap on BeyondTrust and Roundcube means patch teams are in triage mode across multiple critical sectors right now. The Predator iOS hook is the sleeper story — Apple's privacy indicators are a core trust mechanism and Intellexa just demonstrated they can be ghosted silently. Watch for follow-on reporting on that one.