The threat landscape just crossed a threshold that security professionals have been dreading. Amazon Threat Intelligence confirmed a Russian-speaking actor used commercial generative AI tools to breach 600+ FortiGate devices across 55 countries in just five weeks — no zero-days needed. The attacker exploited exposed management ports and weak single-factor auth, but let AI handle tool development, attack planning, and execution at scale. This is the "unsophisticated actor made dangerous by AI" scenario now confirmed in production, not theory.
The vulnerability front is equally brutal. CISA added two Roundcube flaws to KEV — including CVE-2025-49113 (CVSS 9.9), a deserialization RCE that attackers weaponized within 48 hours of public disclosure. BeyondTrust's CVE-2026-1731 (CVSS 9.9) is now confirmed in active ransomware campaigns — Unit 42 caught attackers deploying VShell, web shells, backdoors, and running lateral movement across finance, healthcare, and legal sectors. Two separate CVSS 9.9 flaws being actively exploited simultaneously is a bad day for every patch team on earth.
The AI offensive capability story got a new chapter with PromptSpy — the first confirmed Android malware to use generative AI at runtime, leveraging Google Gemini to adapt persistence behavior across different devices. Meanwhile Predator spyware updated its iOS implant to hook SpringBoard directly, killing mic and camera activity indicators while streaming audio and video. The Cline CLI 2.3.0 supply chain attack (compromised npm token, installed OpenClaw on dev machines) rounds out a feed that is essentially a checklist of every attack surface that matters right now.