February 2026 Security Roundup: AI Abuse, FortiGate Compromises, and ATM Attacks
In his February 2026 security roundup, ESET Chief Security Evangelist Tony Anscombe highlights critical cybersecurity trends driven by opportunistic threat actors. A major incident involved the compromise of over 600 FortiGate devices across 55 countries, where attackers exploited weak authentication and exposed management ports rather than specific software vulnerabilities, leveraging commercial generative AI tools to scale their operations. Additionally, ESET researchers identified PromptSpy, the first known Android malware utilizing generative AI for context-aware user interface manipulation, marking a significant evolution in mobile threats. The report also notes an FBI warning regarding a surge in malware-fueled jackpotting attacks targeting ATMs in the United States. Furthermore, the industry is analyzing a recent report by Poland’s CERT on cyberattacks against more than 30 critical infrastructure organizations, with ESET providing technical analysis of the Dynowiper malware used in these incidents. These events underscore the growing misuse of AI in cybercrime and the persistent risks associated with poor security hygiene and critical infrastructure vulnerabilities.
Wire timeline
February 2026 Security Roundup: AI Abuse, FortiGate Compromises, and ATM Attacks
In his February 2026 security roundup, ESET Chief Security Evangelist Tony Anscombe highlights critical cybersecurity trends driven by opportunistic threat actors. A major incident involved the compromise of over 600 FortiGate devices across 55 countries, where attackers exploited weak authentication and exposed management ports rather than specific software vulnerabilities, leveraging commercial generative AI tools to scale their operations. Additionally, ESET researchers identified PromptSpy, the first known Android malware utilizing generative AI for context-aware user interface manipulation, marking a significant evolution in mobile threats. The report also notes an FBI warning regarding a surge in malware-fueled jackpotting attacks targeting ATMs in the United States. Furthermore, the industry is analyzing a recent report by Poland’s CERT on cyberattacks against more than 30 critical infrastructure organizations, with ESET providing technical analysis of the Dynowiper malware used in these incidents. These events underscore the growing misuse of AI in cybercrime and the persistent risks associated with poor security hygiene and critical infrastructure vulnerabilities.
WeLiveSecurity