ByteDance's Seedance 2.0 dropped this week and it's rattling Hollywood. The AI video model uses images, audio, text, and video prompts to generate cinematic-quality scenes with polished motion editing — at lower cost than anything before it. Viral clips have flooded socials and the entertainment industry is watching nervously. Meanwhile the broader AI market is under pressure: disruption mentions in corporate earnings calls nearly doubled quarter-over-quarter, triggering software stock selloffs as LLMs threaten to eat entire service sectors — legal, IT, consulting, logistics. The trillion-dollar AI bull thesis is getting stress-tested.
On the cyber front, February 20-21 is ugly. PromptSpy — the first Android malware to use generative AI at runtime for persistence — is now in the wild. That's a new class of threat. Combine that with an unpatched Microsoft Semantic Kernel RCE (CVSS 9.9), a Windows Admin Center privilege escalation (CVSS 8.8), and a CISA still hobbled by the partial DHS shutdown since Feb 14 — and the attack surface this weekend is wide open. Panera Bread is facing class actions after ShinyHunters exposed 5.1M customer records. Substack disclosed a breach affecting ~680K users that sat undetected from October 2025 until now — exactly the kind of slow-correction pattern that signals managed disclosure, not honest error.
Analyst take: The Substack delayed disclosure is the tell. Five months between breach and notification isn't a technical lag — it's a timeline decision. Per the triangle heuristic we track: slow correction = managed disclosure window, potential OPSEC play. Watch for regulatory action. The generative AI malware angle (PromptSpy) is the bigger long-term story though — once adversaries build runtime AI into their payloads, signature-based defenses are structurally broken.