← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: CYBERSECURITY Impact: 9/10

AI Goes Fully Offensive: Hacker Breaches 600 Fortinets in 55 Countries Using Generative AI, PromptSpy Android Malware Runs Gemini at Runtime

A Russian-speaking threat actor used multiple generative AI services to systematically compromise 600+ FortiGate firewalls across 55 countries in under five weeks — Amazon's security team issued the warning Friday. Separately, researchers confirmed PromptSpy, the first Android malware to invoke Google's Gemini model at runtime to adapt its persistence behavior per device. The Cline CLI 2.3.0 supply chain attack hit developer systems directly, installing OpenClaw via a trojanized AI coding tool update. Three separate incidents in 72 hours all point to the same inflection: AI has crossed from defender's toolkit to attacker's operational layer.

Impact Score
9/10
Key Stories
CYBERSECURITY
Amazon: AI-Assisted Hacker Breached 600 Fortinet Firewalls in 5 Weeks
BleepingComputer — Russian-speaking actor used generative AI services to automate reconnaissance and exploitation across 55 countries — scale and speed only possible with AI assistance. This is the template for AI-powered mass compromise campaigns going forward.
CYBERSECURITY
PromptSpy: First Android Malware to Use Generative AI at Runtime
BleepingComputer / The Hacker News — PromptSpy calls Google's Gemini API during execution to adapt persistence tactics per device. This is a qualitative leap — malware that reasons about its environment rather than running static evasion logic. Marks a new class of adaptive threat.
CYBERSECURITY
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
The Hacker News — A popular AI coding assistant was weaponized to deliver malware to developer machines. High-value target: compromised dev environments mean access to source code, credentials, and CI/CD pipelines. Developer toolchain integrity is the new attack surface.
CYBERSECURITY
BeyondTrust RCE Flaw CVE-2026-1731 Now Exploited in Ransomware Attacks
BleepingComputer / CISA — CISA confirmed active ransomware exploitation of the BeyondTrust Remote Support RCE. Privileged access management tools being compromised give attackers keys to every system under management — cascading blast radius.
POLICY
OpenAI Debated Calling Police About Suspected Canadian Shooter's Chats
TechCrunch — OpenAI reportedly had internal deliberations about whether to alert law enforcement about a user's ChatGPT conversations before a mass shooting. Sets major precedent for AI platform liability, user privacy vs. public safety trade-offs, and what duty-to-warn means for AI companies.
Analyst Take
The FortiGate and PromptSpy stories together are not coincidence — they represent the formal arrival of AI-augmented offense as a normalized threat actor capability. The FortiGate campaign compressed what used to be weeks of manual reconnaissance into five weeks across 55 countries simultaneously. PromptSpy shows the next step: malware that's not static but adaptive, using the same LLM APIs defenders are paying for. Watch for: (1) More supply chain attacks targeting AI dev tools specifically — Cline CLI won't be the last, because developer machines are treasure chests and AI tools have broad OS access by design. (2) The BeyondTrust escalation to ransomware means PAM tools are now priority targets — any org running privileged access management needs to audit that exposure today. (3) The OpenAI shooter story is the quiet bombshell — it will force a legal and policy reckoning on AI platform liability that no one is ready for. If platforms have a duty to warn, they also have a duty to surveil. That's a constitutional and commercial minefield. The AI offense trend is no longer emerging — it's arrived. Defenders need to assume adversaries have equivalent AI capabilities now.