The defining story of this cycle is AI being weaponized at scale by low-skill threat actors. Amazon Threat Intelligence confirmed a Russian-speaking, financially motivated actor used multiple commercial generative AI tools to breach over 600 FortiGate devices across 55 countries between Jan 11 and Feb 18, 2026 — roughly 5 weeks. No zero-days needed. No advanced tradecraft. Just exposed management ports, weak single-factor credentials, and AI doing the heavy lifting: tool development, attack scripting, credential enumeration. The CISO of Amazon described the actor as having "limited technical capabilities" — a chilling signal that GenAI has now fully crossed the threshold from defensive research use to live offensive operations at scale.
The vulnerability front is equally alarming. CISA added two Roundcube webmail flaws to the KEV catalog, including CVE-2025-49113 (CVSS 9.9, RCE via deserialization) — weaponized within 48 hours of public disclosure. CVE-2026-1731 (CVSS 9.9) in BeyondTrust Remote Support is now confirmed in active ransomware campaigns hitting financial services, healthcare, and higher education across the US, France, Germany, Australia, and Canada. Two CVSS 9.9 vulnerabilities in simultaneous active exploitation is not routine noise — that's a coordinated pressure wave.
On the mobile surveillance front, Intellexa's Predator spyware has evolved to hook iOS SpringBoard directly, hiding microphone and camera activity indicators while streaming live feeds to operators. Simultaneously, PromptSpy emerged as the first confirmed Android malware to use Google's Gemini model at runtime, dynamically adapting its persistence behavior per device. The AI arms race isn't coming — it's here, it's live, and defenders are a step behind.