← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: AI-ASSISTED ATTACKS & CRITICAL VULNERABILITIES Impact: 9/10

AI Goes Offensive at Scale: 600 FortiGates Breached by GenAI Actor, CVSS 9.9 BeyondTrust Hit by Ransomware, Predator Spyware Kills iOS Indicators — Feb 22 Morning Edition

The past 24 hours confirm what security teams have been dreading: AI is no longer just a defensive tool — it's actively being weaponized by financially motivated threat actors at unprecedented scale. Amazon Threat Intelligence disclosed that a Russian-speaking actor with limited technical skills used multiple commercial generative AI services to breach 600+ FortiGate devices across 55 countries in just five weeks (Jan 11–Feb 18). No zero-days were needed. The attacker used AI to exploit exposed management ports and weak single-factor credentials — basic hygiene failures, amplified by AI-driven automation. This is the new threat model: script kiddies with AI copilots punching at nation-state scale.

On the vulnerability front, the BeyondTrust CVE-2026-1731 (CVSS 9.9) story just escalated. CISA has confirmed the RCE flaw is now being actively exploited in ransomware campaigns targeting financial services, healthcare, legal, and higher education across the US, France, Germany, Australia, and Canada. Palo Alto Unit 42 documented the full kill chain: reconnaissance, web shells, C2 backdoors, lateral movement, and data theft. Meanwhile, two Roundcube webmail flaws (including another CVSS 9.9 deserialization RCE) have been added to CISA's KEV catalog after attackers weaponized one within 48 hours of patch disclosure.

The spyware beat is equally alarming. Intellexa's Predator spyware now hooks directly into iOS SpringBoard to suppress the green mic/camera indicator dots while actively streaming audio and video — a significant operational security defeat for iOS users who rely on those indicators as trust signals. Separately, PayPal disclosed a data breach where a software error in a loan application exposed sensitive customer data including Social Security numbers for nearly six months. And in an AI-positive development, Anthropic launched Claude Code Security in limited preview — an AI-powered codebase vulnerability scanner that identifies issues traditional tools miss. The dual-use irony is not lost on anyone.

Impact Score
9/10
Key Stories
AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries
The Hacker News / Amazon Threat Intelligence
BeyondTrust RCE Flaw (CVE-2026-1731, CVSS 9.9) Now Exploited in Ransomware Attacks
BleepingComputer / CISA
Predator Spyware Hooks iOS SpringBoard to Hide Mic and Camera Activity
BleepingComputer / Elastic Security Labs
PayPal Discloses Data Breach Exposing User Info Including SSNs for 6 Months
BleepingComputer
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
The Hacker News / Anthropic
Analyst Take
The FortiGate story is the headline of the week, not the day. Amazon's disclosure reframes the entire threat landscape: we're past the point where "sophisticated actor" means "nation-state with custom tooling." A financially motivated actor with no exploitation skills just hit 600 enterprise firewalls in 55 countries using off-the-shelf AI tools and basic credential attacks. The attack surface isn't zero-days — it's your exposed management ports and your users who never got MFA enabled. The BeyondTrust ransomware escalation and the Roundcube 48-hour weaponization timeline both reinforce the same lesson: patch windows are collapsing. Defenders now have hours, not days. The Predator spyware iOS development is a reminder that mobile trust signals are not guarantees — if your device is compromised at a deep enough level, the OS's own UI can be turned against you. The Anthropic Claude Code Security launch is genuinely promising as a defensive countermeasure, but the dual-use risk is real and acknowledged. The week's meta-theme: AI is compressing both attack timelines and attacker skill requirements simultaneously. Organizations still operating on legacy patch cadences and single-factor auth are running out of runway fast.