← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: CYBER Impact: 9/10

AI Goes Offensive at Scale: 600+ FortiGates Breached in 55 Countries, Six Windows Zero-Days Actively Exploited, MFA-Bypass PhaaS Emerges

A convergence of high-severity threats landed this cycle — an AI-assisted threat actor systematically compromised 600+ FortiGate devices across 55 countries, demonstrating that generative AI is now operational tradecraft for attackers, not just defenders. Microsoft patched six actively exploited zero-days in a single cycle covering Windows Shell, MSHTML, Word, Remote Desktop Services, DWM, and the VPN Connection Manager — any one of which would be a significant Patch Tuesday; six simultaneous is a fire drill. Meanwhile Krebs is reporting on Starkiller, a phishing-as-a-service that defeats MFA by running a live headless Chrome proxy between victim and real site — capturing session tokens in real time — making the "just use MFA" guidance meaningfully weaker for orgs that haven't moved to phishing-resistant auth. The week's signal is clear: the attacker toolchain is being industrialized and AI-accelerated faster than defender toolchains are adapting.

Impact Score
9/10
Key Stories
CYBER
AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries
The Hacker News — First documented large-scale AI-assisted offensive campaign targeting network edge devices at global scale — 55 countries, 600+ devices. Signals that AI-augmented threat actors are moving from proof-of-concept to operational deployment. FortiGate admins need to audit now.
CYBER
Microsoft Patches Six Actively Exploited Zero-Days in February 2026 Patch Tuesday
Krebs on Security — Six simultaneous zero-days all under active exploitation: Windows Shell clickjack bypass (CVE-2026-21510), MSHTML bypass (CVE-2026-21513), Word bypass (CVE-2026-21514), RDS privilege escalation (CVE-2026-21533), DWM elevation (CVE-2026-21519), VPN manager DoS (CVE-2026-21525). Patch urgency is critical — especially Shell and RDS.
CYBER
Starkiller PhaaS Defeats MFA via Live Reverse-Proxy with Headless Chrome
Krebs on Security — Starkiller runs a Docker container with headless Chrome that proxies the real login page in real time — every keystroke, MFA code, and session token captured before forwarding to legitimate site. Bypasses MFA architecturally, not through weakness. FIDO2/passkeys are the only category not defeated. Any org relying on TOTP or push-based MFA is exposed.
CYBER
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
The Hacker News — Supply chain compromise hit Cline, a popular AI-assisted coding CLI. OpenClaw implant deployed to developer machines. Dev toolchain supply chain is now a prime attack surface — particularly AI coding assistants with broad file system access. This is a direct threat to orgs using AI dev tooling.
AI
Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies
The Hacker News — Proof-of-concept showing AI chat platforms can serve as command-and-control infrastructure for malware — blending C2 traffic into legitimate HTTPS flows to trusted domains. Traditional network detection that blocks known C2 infrastructure is blind to this. Requires behavioral detection, not domain blocklists.
Analyst Take
The through-line this cycle is industrialization. Each story represents a different layer of the attack stack getting professionalized and automated. The 600+ FortiGate AI campaign isn't a one-off — it's a proof point that AI has crossed the threshold from tactical assist to operational force multiplier for threat actors. The Cline supply chain hit is particularly concerning for orgs running AI dev tooling with broad filesystem access — those tools are now high-value targets because a single compromise gives attackers reach into every project a developer touches. The Copilot/Grok C2 research is the signal to watch: if attackers start routing C2 through legitimate AI platform traffic, an enormous chunk of enterprise network detection becomes useless overnight. Starkiller is the most immediately actionable story — if Dong or anyone on the team is still recommending TOTP or push-based MFA as a security answer, that guidance needs updating. FIDO2 hardware keys or passkeys are the only architecturally sound answer against live-proxy attacks. Patch the six Microsoft zero-days today, prioritize Windows Shell and RDS. The week's meta-signal: attackers are shipping faster than defenders. The response window referenced in that ThreatsDay bulletin item — "From Exposure to Exploitation: How AI Collapses Your Response Window" — is the right frame for everything happening this cycle.