BREEZE COMET Did Not Steal Card Numbers. It Manipulated the Payment System
Google and Mandiant say BREEZE COMET compromises the identities, certificates, applications, and networks authorized to move money through Brazil's payment systems.
In-depth red team tactics, blue team strategy — and privacy-first security tools that run entirely in your browser. No accounts. No telemetry. No data leaves your machine.
Google and Mandiant say BREEZE COMET compromises the identities, certificates, applications, and networks authorized to move money through Brazil's payment systems.
Unit 42 reports that a human attacker used AI agents to move from an exposed API to cloud, identity, source code, secrets, and CI/CD control in under ten hours. The evidence shows acceleration, not a magical new exploit.
Google says an exploit for CVE-2026-85046 exists in the wild. Defenders need to deploy Chrome 152.0.7977.82 or .83 and verify the running version across managed and unmanaged endpoints.
CVE-2026-83548 and CVE-2026-83549 are being exploited against SonicWall SMA1000 appliances. Patching closes the flaws, but exposed gateways still need compromise assessment and credential recovery.
Berlin's stolen government data has been released after an extortion deadline expired. The next phase is credential rotation, exposure analysis, victim notification, and long-term fraud monitoring.
Taalas' HC1 hardcodes Llama 3.1 8B into silicon for extraordinary inference speed. The same design turns model updates, provenance, and incident response into hardware lifecycle problems.
CISA KEV activity and a fresh critical Artifactory authentication bypass show why package repositories need incident-grade monitoring, not just routine patching.