Pentagon ditches Anthropic AI over “security risk” and OpenAI takes over

2026-03-04T21:18:38Z5f65f94ce0fdebdfe1426f67ce775a83118231c987240692d4e82f10639770e2
ACRDoHRATTeramindValleyRATai-securityanthropicbrowser-exploitchromeconduentcredential-harvestingcredit-card-frauddata-breachencrypted-dnsextension-vulnerabilitygeminigoogle-api-keysmalwareopenaipassword-managersphishingprivacyregulatory-actionsamsungsupply-chain-tampering

What happened

This Malwarebytes news/threat-intel roundup highlights a cluster of high-risk threats and privacy incidents from late Feb–early Mar 2026. Key technical issues include a patched Chrome extension vulnerability in the “Live in Chrome” flow that allowed extensions to inherit Gemini AI permissions (camera, mic, and file access), public Google API keys that can expose Gemini data, and malicious supply-chain/impersonation campaigns: a fake FileZilla distribution that uses encrypted DNS to contact attacker servers, typosquatted Huorong and FileZilla sites delivering ValleyRAT and other remote-access/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
5f65f94ce0fdebdfe1426f67ce775a83118231c987240692d4e82f10639770e2
Enrichment time
2026-03-04T21:18:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.