OpenClaw Security Crisis: Detecting AI Agent Risks

You’ve probably heard of OpenClaw. This open source AI agent quickly became one of the fastest growing repositories in GitHub’s history, gaining over 135,000 stars within a few weeks. However, this led to the first major AI agent security crisis of 2026. Reco helps you identify whether an AI agent is present in your environment. […]
AI-assisted attackers compromise over 600 FortiGate devices in 55 countries

Russian-speaking, financially motivated attackers have been observed leveraging commercial generative artificial intelligence (AI) services to compromise more than 600 FortiGate devices in 55 countries. This is according to new findings from Amazon Threat Intelligence, which observed activity from January 11, 2026 to February 18, 2026. CJ Moses, chief information security officer (CISO) at Amazon Integrated […]
Anthropic launches Claude Code Security, an AI-powered vulnerability scan

Rabi LakshmananFebruary 21, 2026Artificial Intelligence / DevSecOps Artificial intelligence (AI) company Anthropic has begun rolling out new security features in Claude Code that can scan users’ software codebases to find vulnerabilities and suggest patches. This feature, called Claude Code Security, is currently available in limited research preview for Enterprise and Team customers. “By scanning codebases […]
CISA Adds Two Actively Exploited Round Cube Flaws to KEV Catalog

Ravi LakshmananFebruary 21, 2026Vulnerability/patch management The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws affecting the Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows. CVE-2025-49113 (CVSS score: 9.9) – Untrusted data deserialization vulnerability that allows remote […]
EC-Council Expands AI Certification Portfolio to Strengthen the Responsiveness and Security of U.S. AI Talent

With $5.5 trillion in global AI risks exposed and 700,000 U.S. workers in need of reskilling, four new AI certifications and the CISO v4 certification will help bridge the gap between AI adoption and workforce readiness. EC-Council, creator of the world-renowned Certified Ethical Hacker (CEH) credential and a global leader in applied cybersecurity education, today […]
BeyondTrust vulnerabilities used for web shells, backdoors, and data leaks

Ravi LakshmananFebruary 20, 2026Vulnerability/Cyber attack Threat actors are exploiting recently disclosed critical security flaws affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products to This vulnerability is tracked as CVE-2026-1731 (CVSS score: 9.9) and allows an attacker to execute operating system commands in the context of a site user. In a report released […]
Cline CLI 2.3.0 Supply Chain Attack Installs OpenClaw on Developer Systems

In yet another software supply chain attack, the open-source artificial intelligence (AI)-powered coding assistant Cline CLI was updated to secretly install OpenClaw, a self-hosted autonomous AI agent that has become extremely popular over the past few months. “On February 17, 2026 at 3:26 AM PT, an unauthorized party published an update to the Cline CLI […]
ClickFix campaign exploits compromised sites to deploy MIMICRAT RAT

Rabi LakshmananFebruary 20, 2026Malware/Threat Intelligence Cybersecurity researchers have revealed details of a new ClickFix campaign that exploits compromised legitimate sites to deliver a previously undocumented remote access Trojan (RAT) called MIMICRAT (also known as AstarionRAT). “This campaign demonstrates a high level of operational sophistication, with compromised sites across multiple industries and geographies serving as the […]
New metrics shaping cyber insurance in 2026

hacker newsFebruary 20, 2026Cyber insurance / password security With one in three cyberattacks now involving the compromise of an employee account, insurance companies and regulators are placing great importance on identity posture when assessing cyber risk. However, for many organizations, these assessments remain largely opaque. Factors such as password hygiene, privileged access management, and multi-factor […]
Ukrainian citizen sentenced to 5 years in prison for North Korean IT worker fraud case

Ravi LakshmananFebruary 20, 2026Cybercrime/Law Enforcement A 29-year-old Ukrainian national has been sentenced to five years in prison in the United States for aiding North Korea’s information technology (IT) worker fraud scheme. In November 2025, Oleksandr “Alexandr” Dydenko pled guilty to wire fraud conspiracy and aggravated identity theft for stealing the identities of U.S. citizens and […]