← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: AI SECURITY / CRITICAL INFRASTRUCTURE Impact: 8/10

Anthropic Deploys Claude as a Defender, Roundcube CVSS 9.9 Weaponized in 48h, PayPal Exposes SSNs for 6 Months — Feb 22 Late Edition

Anthropic just flipped the script on the AI-as-attacker narrative by launching Claude Code Security, a limited research preview that lets Claude scan your codebase for vulnerabilities and suggest patches. The timing is pointed — Amazon's own threat intel just documented a Russian-speaking actor using commercial GenAI to breach 600 FortiGates. Anthropic is explicitly positioning this as an AI countermeasure, using the same capabilities adversaries are weaponizing. It's only available to Enterprise and Team customers right now, but the signal is clear: the AI arms race has an active defense lane opening up.

On the exploitation front, CISA added two Roundcube webmail flaws to its Known Exploited Vulnerabilities catalog today. The lead vulnerability, CVE-2025-49113 (CVSS 9.9), is a deserialization RCE in Roundcube's upload handler. The brutal detail here: attackers diffed the patch and had a working exploit within 48 hours of public disclosure. That is not a patching window — that is a zero-day in practice. The second flaw (CVE-2025-68461, CVSS 7.2) is an SVG-injected XSS. Roundcube is widespread in government and enterprise mail servers, so the blast radius is significant.

Meanwhile PayPal disclosed that a software bug in a loan application exposed customer data — including full Social Security numbers — for nearly six months. Add to that a Japanese tech giant (Advantest) hit by ransomware, a French bank registry breach covering 1.2 million accounts, and the University of Mississippi Medical Center shutting down all clinics statewide after a ransomware attack, and the pattern is unmistakable: February 2026 is a full-spectrum pressure test on institutional cyber posture, and most organizations are not passing.

Impact Score
8/10
Key Stories
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
The Hacker News
CISA Adds Two Roundcube Flaws to KEV — CVSS 9.9 Weaponized Within 48 Hours
The Hacker News
PayPal Discloses Data Breach Exposing User SSNs for 6 Months
BleepingComputer
Hackers Target Microsoft Entra Accounts via Device Code Vishing
BleepingComputer
University of Mississippi Medical Center Closes All Clinics After Ransomware
BleepingComputer
Analyst Take
The Anthropic Claude Code Security launch is the headline I want to focus on because it marks a structural shift — not just AI being used defensively in theory, but a major AI lab productizing it. Combined with Amazon's FortiGate report, we now have documented AI offense and now AI-native defense in the same 24-hour news cycle. On the vulnerability side, the 48-hour Roundcube exploit turnaround is the new normal when CVSS 9.9 patches drop — organizations running Roundcube need to treat this as a fire drill, not a scheduled patch window. The PayPal breach is a slow burn story that will get louder: 6 months of SSN exposure means identity fraud claims will surface for years. The UMMC ransomware hospital shutdown is the kind of story that moves policy — expect it to come up in Congressional testimony.