← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: AI + CYBERSECURITY Impact: 9/10

AI Democratizes Mass Exploitation: Low-Skill Actor Breaches 600 FortiGate Devices in 55 Countries Using Commercial AI

Amazon Threat Intelligence confirmed a Russian-speaking, financially motivated actor — described as having "limited technical capabilities" — used multiple commercial generative AI tools to breach over 600 FortiGate firewalls across 55 countries in just 5 weeks (Jan 11–Feb 18). No zero-days required: AI compensated for skill gaps to exploit exposed management ports and weak credentials at unprecedented scale. Simultaneously, researchers discovered PromptSpy, the first Android malware to use generative AI (Google Gemini) at runtime to adapt its persistence behavior per device — marking a genuine inflection point in AI-native offensive tooling. Anthropic's counter-move: Claude Code Security launched in limited preview to scan codebases for vulnerabilities using the same AI capabilities adversaries are weaponizing.

Impact Score
9/10
Key Stories
AI + CYBERSECURITY
AI-Assisted Hacker Breaches 600 FortiGate Firewalls in 5 Weeks Across 55 Countries
BleepingComputer / Amazon Threat Intelligence — Low-skill actor used commercial AI to achieve nation-state-level operational scale — fundamental shift in threat landscape democratization
AI / MOBILE MALWARE
PromptSpy: First Android Malware to Use Generative AI (Gemini) at Runtime
BleepingComputer — AI-native malware that adapts persistence per device in real-time — establishes new malware architecture paradigm for 2026
BeyondTrust CVE-2026-1731 (CVSS 9.9) Now Exploited in Ransomware Campaigns — Financial, Healthcare, Legal Sectors Hit
CISA / BleepingComputer / Palo Alto Unit 42 — Critical RCE in privileged access management tool pivoting to ransomware across 6 countries — BeyondTrust is tier-1 enterprise infrastructure
DATA BREACH
PayPal Breach: Software Bug Exposed Customer SSNs and Personal Data for 6 Months
BleepingComputer — Loan application processing error silently exposed SSNs — duration (6 months) signals inadequate monitoring of data pipeline outputs
MOBILE / SPYWARE
Predator Spyware Hooks iOS SpringBoard to Silently Hide Mic and Camera Indicators
BleepingComputer — Intellexa's Predator now suppresses iOS privacy indicators during active surveillance — the green/orange dots Apple advertised as protection are bypassed
Analyst Take
Tonight's briefing has a single coherent thesis: the AI skill-gap is closed. The FortiGate story is the clearest proof yet — a low-capability actor achieved what would have required a mid-tier nation-state team 3 years ago, simply by delegating the technical work to commercial AI. 600 devices, 55 countries, 5 weeks. That's not a campaign — that's a production pipeline. PromptSpy doubles down on this: AI-native malware that uses Gemini to reason about its own persistence strategy per device is a new threat class entirely, not an incremental upgrade. The defender response (Anthropic's Claude Code Security) is directionally correct but in limited preview — the offense is already at scale. Watch for the FortiGate actor TTP to get cloned by other low-skill groups within weeks. The Predator/iOS story deserves a separate flag: if Apple's hardware-enforced privacy indicators can be silently suppressed at the SpringBoard layer, every privacy guarantee Apple markets is now a qualified statement. That's a regulatory story waiting to happen in the EU. BeyondTrust ransomware pivot confirms that critical-access infrastructure (PAM tools) is now primary ransomware entry vector — any org using BeyondTrust RS/PRA needs emergency patch verification today.