← Back to News
AI Analysis by The Wire
February 21, 2026 Focus: CYBERSECURITY Impact: 9/10

Ransomware Goes Nuclear: BeyondTrust RCE Now Weaponized, Supply Chain Hits Dev Tools, AI Malware Emerges

The past 48 hours have been brutal for defenders. The BeyondTrust RCE vulnerability — already a known critical flaw — has been confirmed by CISA as actively exploited in ransomware campaigns, not just APT intrusions. Web shells, backdoors, and data exfiltration are all in the mix. Japanese semiconductor testing giant Advantest was simultaneously hit by ransomware, disrupting supply chains for chip manufacturers globally. A Mississippi medical center closed all clinics after a ransomware hit — the healthcare sector continues to be a soft target with catastrophic real-world consequences.

On the supply chain and AI threat front, Cline CLI 2.3.0 was compromised in a targeted supply chain attack that silently installed "OpenClaw" malware on developer systems — and a follow-up infostealer is now confirmed to be specifically targeting OpenClaw AI agent config files and gateway tokens. This is a new attack vector: compromise the dev tool, steal the AI agent credentials, own the automation pipeline. Meanwhile, PromptSpy is being called the first Android malware to use generative AI (Gemini) at runtime for persistence — threat actors are now weaponizing the same AI features users trust.

Rounding out the week: PayPal disclosed a data breach exposing user info for 6 months before detection, and a French bank registry breach hit 1.2 million accounts. Three former Google engineers were indicted for transferring trade secrets to Iran. The attack surface is expanding on every axis simultaneously — developer tools, AI infrastructure, financial systems, and critical healthcare.

Impact Score
9/10
Key Stories
BeyondTrust RCE Flaw Now Exploited in Ransomware Attacks
BleepingComputer / CISA
Cline CLI 2.3.0 Supply Chain Attack Installs OpenClaw on Developer Systems
The Hacker News
PromptSpy: First Android Malware to Use Generative AI at Runtime
BleepingComputer
Advantest Ransomware Attack Hits Japanese Semiconductor Giant
BleepingComputer
PayPal Data Breach Exposed User Info for 6 Months Undetected
BleepingComputer
Analyst Take
The OpenClaw story is the one I'm watching most closely — it's a two-stage attack that specifically targets AI developer infrastructure. Stage one: trojanize a popular AI coding tool (Cline). Stage two: deploy an infostealer that goes after AI agent configs, gateway tokens, and MCP server credentials. This is adversaries adapting to the AI-native development workflow in real time. When your AI agent has credentials and tool access, stealing the agent config IS the crown jewels. The BeyondTrust escalation to ransomware use is the other alarm bell — when a vuln jumps from nation-state APT use to commodity ransomware operators, you've hit mass exploitation territory. Defenders have days, not weeks.