← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: AI-WEAPONIZED CYBERSECURITY Impact: 9/10

AI Goes Fully Operational: GenAI Breaches 600 FortiGates, CVSS 9.9 Double-Tap Active, Predator Hides Behind iOS Lock Screen — Feb 22 Early Morning Edition

The defining story of this cycle is AI being weaponized at scale by low-skill threat actors. Amazon Threat Intelligence confirmed a Russian-speaking, financially motivated actor used multiple commercial generative AI tools to breach over 600 FortiGate devices across 55 countries between Jan 11 and Feb 18, 2026 — roughly 5 weeks. No zero-days needed. No advanced tradecraft. Just exposed management ports, weak single-factor credentials, and AI doing the heavy lifting: tool development, attack scripting, credential enumeration. The CISO of Amazon described the actor as having "limited technical capabilities" — a chilling signal that GenAI has now fully crossed the threshold from defensive research use to live offensive operations at scale.

The vulnerability front is equally alarming. CISA added two Roundcube webmail flaws to the KEV catalog, including CVE-2025-49113 (CVSS 9.9, RCE via deserialization) — weaponized within 48 hours of public disclosure. CVE-2026-1731 (CVSS 9.9) in BeyondTrust Remote Support is now confirmed in active ransomware campaigns hitting financial services, healthcare, and higher education across the US, France, Germany, Australia, and Canada. Two CVSS 9.9 vulnerabilities in simultaneous active exploitation is not routine noise — that's a coordinated pressure wave.

On the mobile surveillance front, Intellexa's Predator spyware has evolved to hook iOS SpringBoard directly, hiding microphone and camera activity indicators while streaming live feeds to operators. Simultaneously, PromptSpy emerged as the first confirmed Android malware to use Google's Gemini model at runtime, dynamically adapting its persistence behavior per device. The AI arms race isn't coming — it's here, it's live, and defenders are a step behind.

Impact Score
9/10
Key Stories
AI-Assisted Hacker Breached 600+ FortiGate Devices in 55 Countries in 5 Weeks
TheHackerNews / BleepingComputer
CISA Adds Two Roundcube Flaws to KEV: CVSS 9.9 RCE Weaponized in 48 Hours
TheHackerNews
BeyondTrust CVE-2026-1731 (CVSS 9.9) Now in Active Ransomware Campaigns
TheHackerNews / BleepingComputer
Predator Spyware Hooks iOS SpringBoard to Hide Mic and Camera Indicators
BleepingComputer
PromptSpy: First Android Malware to Use Generative AI at Runtime
BleepingComputer
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
TheHackerNews
Analyst Take
This cycle's throughline is simple: AI has become the great equalizer for threat actors. The FortiGate breach proves you no longer need tradecraft to run a global campaign — you need a GenAI subscription and patience. Two simultaneous CVSS 9.9 exploits in active ransomware use is the vulnerability equivalent of a two-front war. Predator hiding behind iOS UI indicators and PromptSpy using Gemini at runtime signal that the attack surface is now dynamic and AI-adaptive in ways that traditional static defenses cannot match. Anthropic's Claude Code Security launch is the right instinct — fight AI offense with AI defense — but the gap between attacker iteration speed and enterprise patch cycles remains dangerous. The 48-hour weaponization window on Roundcube should be the benchmark every security team uses for their SLA targets. If you can't patch faster than that, you're permanently reactive.