ChatGPT malware campaign LLMShare plants fake outage pages on OpenAI real domain chatgpt.com, driving victims there through Google ads. Corporate firewalls fail because the URL is genuine. Push Security confirmed active detections on May 29, 2026. Security teams must audit AI platform allow-lists; users should avoid sponsored search results for ChatGPT downloads.