← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: AI-WEAPONIZED THREATS / CRITICAL VULNERABILITIES Impact: 9/10

AI Goes Fully Weaponized: 600 FortiGates Breached by GenAI Actor, Dual CVSS 9.9 Exploits Active, PromptSpy Becomes First AI-Powered Android Malware — Feb 22 Midday Edition

The threat landscape just crossed a threshold that security professionals have been dreading. Amazon Threat Intelligence confirmed a Russian-speaking actor used commercial generative AI tools to breach 600+ FortiGate devices across 55 countries in just five weeks — no zero-days needed. The attacker exploited exposed management ports and weak single-factor auth, but let AI handle tool development, attack planning, and execution at scale. This is the "unsophisticated actor made dangerous by AI" scenario now confirmed in production, not theory.

The vulnerability front is equally brutal. CISA added two Roundcube flaws to KEV — including CVE-2025-49113 (CVSS 9.9), a deserialization RCE that attackers weaponized within 48 hours of public disclosure. BeyondTrust's CVE-2026-1731 (CVSS 9.9) is now confirmed in active ransomware campaigns — Unit 42 caught attackers deploying VShell, web shells, backdoors, and running lateral movement across finance, healthcare, and legal sectors. Two separate CVSS 9.9 flaws being actively exploited simultaneously is a bad day for every patch team on earth.

The AI offensive capability story got a new chapter with PromptSpy — the first confirmed Android malware to use generative AI at runtime, leveraging Google Gemini to adapt persistence behavior across different devices. Meanwhile Predator spyware updated its iOS implant to hook SpringBoard directly, killing mic and camera activity indicators while streaming audio and video. The Cline CLI 2.3.0 supply chain attack (compromised npm token, installed OpenClaw on dev machines) rounds out a feed that is essentially a checklist of every attack surface that matters right now.

Impact Score
9/10
Key Stories
AI-Assisted Hacker Breaches 600+ FortiGate Devices in 55 Countries
Amazon Threat Intelligence / The Hacker News
Roundcube CVSS 9.9 RCE (CVE-2025-49113) Weaponized in 48 Hours — Added to CISA KEV
The Hacker News / CISA
BeyondTrust CVE-2026-1731 (CVSS 9.9) Now Fueling Ransomware — Web Shells, Backdoors, Data Theft
BleepingComputer / Palo Alto Unit 42
PromptSpy: First Android Malware to Use Generative AI at Runtime
BleepingComputer
Predator Spyware Hooks iOS SpringBoard to Kill Mic and Camera Indicators
BleepingComputer
Analyst Take
Three threads converging hard right now. First: AI as force multiplier for low-skill attackers is no longer hypothetical — the FortiGate campaign is the textbook case and it will be studied and replicated. Second: the dual CVSS 9.9 active exploitation situation (Roundcube + BeyondTrust simultaneously) is what patch fatigue looks like from the attacker's side — they know teams can't move fast enough. Third: PromptSpy crossing the GenAI-at-runtime threshold on mobile is the leading edge of a new malware generation that adapts in real time. The Cline CLI supply chain hit is a reminder that dev tooling is the new soft underbelly — one compromised npm token and you've got OpenClaw on thousands of developer machines. If your org hasn't done a dev dependency audit in 90 days, that's the most actionable thing on this list.