← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: AI / CYBERSECURITY Impact: 9/10

AI Lowers the Skill Floor for Mass Exploitation — 600 FortiGate Breaches, First AI-Native Android Malware, BeyondTrust Ransomware Pivot — Feb 22 Night Edition

Amazon Threat Intelligence has confirmed a Russian-speaking, financially motivated actor used commercial generative AI tools to breach 600+ FortiGate devices across 55 countries in just five weeks — no zero-days, just AI-assisted mass exploitation of weak credentials at scale. Simultaneously, researchers have identified PromptSpy, the first Android malware to use Google's Gemini model at runtime to adapt its own persistence behavior across different devices. The BeyondTrust CVE-2026-1731 (CVSS 9.9) vulnerability has now been explicitly linked to ransomware attacks per CISA, confirming the exploitation-to-extortion pipeline is fully operational. Taken together, today's threat picture signals a structural shift: AI is eliminating the technical skill barrier for high-volume, adaptive attacks.

Impact Score
9/10
Key Stories
CYBERSECURITY
AI-Assisted Hacker Breached 600+ FortiGate Firewalls in 55 Countries in 5 Weeks
Amazon Threat Intelligence / BleepingComputer — Russian-speaking financially motivated actor with limited technical skills used commercial GenAI tools across the full attack lifecycle — tool development, credential stuffing, lateral movement. No CVEs exploited. Pure credential abuse + AI amplification. This is the democratization-of-cyberattack story in its clearest form yet.
AI / MALWARE
PromptSpy: First Known Android Malware to Use Generative AI at Runtime
BleepingComputer — PromptSpy calls Google's Gemini model during execution to adapt persistence behavior to the specific device it's running on. This is not AI-generated malware — the malware itself is AI-powered at runtime. First of its kind. Watch for copycat variants across iOS and desktop platforms.
VULNERABILITY
BeyondTrust CVE-2026-1731 (CVSS 9.9) Now Confirmed in Active Ransomware Campaigns
CISA / Palo Alto Unit 42 — Unit 42 tracked the exploitation chain from initial access through web shells, C2 deployment, lateral movement, and data exfiltration. Sectors hit: financial, legal, healthcare, higher education across US, France, Germany, Australia, Canada. Full ransomware pivot now confirmed by CISA.
CYBERCRIME
FBI: ATM Jackpotting Surge Cost Americans $20M+ in 2025
FBI / BleepingComputer — Malware-driven ATM cash-out attacks spiked significantly in 2025. Physical infrastructure crime is resurging alongside cyber extortion. Not a headline grab — signals organized crime diversifying revenue streams.
DATA BREACH
French Ministry of Finance Breach Exposes 1.2 Million Bank Registry Accounts
BleepingComputer — French government bank registry compromised. 1.2 million accounts. Government financial infrastructure is a tier-1 target — this breach's downstream identity fraud potential is high given the financial sensitivity of the data.
Analyst Take
The FortiGate story is the most important data point this week — and not because of the scale (600 devices is bad but not catastrophic). It matters because of the actor profile. Amazon's analysis describes someone with limited technical capabilities who compensated entirely by delegating the complex parts of an attack to commercial AI. No exploits. No sophisticated tradecraft. Just AI-assisted credential abuse at machine speed. If that playbook is replicable — and it obviously is — the threat landscape just got materially wider overnight. Every organization running exposed management ports with single-factor auth should treat this as active warning, not background noise. The PromptSpy story compounds this signal from a different angle: we now have malware that uses AI to think for itself at runtime. These two stories together mark a before/after line. Before: AI helps humans write attacks. After: AI is embedded in the attack itself. Dong should watch the BeyondTrust exploitation chain closely — the sectors targeted (finance, legal, healthcare) overlap with dongcmd.com's likely user base, and CVSS 9.9 with confirmed ransomware pivot means any unpatched BeyondTrust deployment is a ticking clock.