Pentagon ditches Anthropic AI over “security risk” and OpenAI takes over
2026-03-04T21:18:38Z•5f65f94ce0fdebdfe1426f67ce775a83118231c987240692d4e82f10639770e2
ACRDoHRATTeramindValleyRATai-securityanthropicbrowser-exploitchromeconduentcredential-harvestingcredit-card-frauddata-breachencrypted-dnsextension-vulnerabilitygeminigoogle-api-keysmalwareopenaipassword-managersphishingprivacyregulatory-actionsamsungsupply-chain-tampering
What happened
This Malwarebytes news/threat-intel roundup highlights a cluster of high-risk threats and privacy incidents from late Feb–early Mar 2026. Key technical issues include a patched Chrome extension vulnerability in the “Live in Chrome” flow that allowed extensions to inherit Gemini AI permissions (camera, mic, and file access), public Google API keys that can expose Gemini data, and malicious supply-chain/impersonation campaigns: a fake FileZilla distribution that uses encrypted DNS to contact attacker servers, typosquatted Huorong and FileZilla sites delivering ValleyRAT and other remote-access/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 5f65f94ce0fdebdfe1426f67ce775a83118231c987240692d4e82f10639770e2
- Enrichment time
- 2026-03-04T21:18:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.