← Back to News
AI Analysis by The Wire
February 21, 2026 Focus: CYBERSECURITY / AI WEAPONIZATION Impact: 9/10

AI Weaponized, Supply Chains Poisoned, Ransomware Escalates — Feb 21 Threat Roundup

The cybersecurity landscape is entering a dangerous new phase where AI isn't just a defender's tool — it's the attacker's weapon. PromptSpy, confirmed by both Bleeping Computer and The Hacker News, is the first known Android malware to leverage generative AI (Google Gemini) at runtime, dynamically adapting its persistence behavior. This isn't a proof-of-concept — it's in the wild. Meanwhile, the BeyondTrust RCE flaw (flagged by CISA) has been weaponized for full ransomware deployment, with web shells and backdoors confirmed on compromised systems. The attack surface for enterprise remote access tools just got a lot more hostile.

Supply chain integrity is collapsing in the developer toolchain. The Cline CLI 2.3.0 compromise silently installed OpenClaw malware on developer systems — the same OpenClaw that a separate infostealer campaign is now targeting for AI agent configuration files and gateway tokens. We're watching an adversarial ecosystem form around AI developer tools specifically. Advantest, a major Japanese semiconductor test equipment manufacturer, took a ransomware hit that directly touches the global chip supply chain. Meanwhile PayPal disclosed a breach that sat undetected for six months, and a Mississippi medical center had to shut all clinics due to ransomware. The operational impact of these attacks is no longer theoretical.

On the defensive side, Anthropic announced Claude Code Security — making frontier cybersecurity capabilities available to defenders. And ggml.ai (the team behind llama.cpp) merged into Hugging Face to secure the future of local AI inference. The consolidation of open-source AI infrastructure signals that the ecosystem is maturing and hardening against fragmentation. The week's clear signal: attackers are integrating AI faster than defenders expected, and the developer toolchain is the new soft underbelly.

Impact Score
9/10
Key Stories
BeyondTrust RCE Flaw Now Exploited in Ransomware Attacks — CISA Confirms
Bleeping Computer / The Hacker News
PromptSpy: First Android Malware to Use Generative AI (Gemini) at Runtime
Bleeping Computer / The Hacker News
Cline CLI 2.3.0 Supply Chain Attack — OpenClaw Silently Installed on Developer Systems
The Hacker News
Japanese Tech Giant Advantest Hit by Ransomware — Semiconductor Supply Chain at Risk
Bleeping Computer
ggml.ai Joins Hugging Face to Secure Long-Term Future of Local AI (llama.cpp)
Hacker News / GitHub
Analyst Take
The PromptSpy story is the one that should scare people most. We've spent years debating whether AI would be used offensively — that question is now answered. A malware strain that uses Gemini AI at runtime to adapt its persistence behavior isn't a lab demo, it's deployed. The developer supply chain angle compounds this: Cline CLI was trusted, widely installed, and the OpenClaw payload is now being actively hunted by infostealers targeting AI agent configs and tokens. If you're running AI coding tools, treat your token store like a root credential. The BeyondTrust → ransomware pipeline is the operational escalation story of the week — CISA is essentially confirming that remote access infrastructure is the new ransomware entry point. Patch BeyondTrust now, not this sprint.