Skip to main content
Security

Breeze Comet targets Brazilian payment infrastructure with custom malware

Breeze Comet targets Brazilian payment infrastructure with custom malware Image: Primary
Google Threat Intelligence Group and Mandiant say the financially motivated Breeze Comet group has targeted Brazilian financial services, retail, and e-commerce organizations since 2024, manipulating payment systems and banking software to make fraudulent transfers. The group has completed at least one heist worth tens of thousands of dollars, according to the report. It gains access through password spraying, impersonated IT-support calls, vulnerable JBoss servers, and compromised websites, then uses custom malware and privileged accounts to access payment applications. The activity has culminated in hundreds of fraudulent transactions, the report says.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

SonicWall reports exploited SMA1000 zero-days and releases fixes

SecurityWeek reported that SonicWall urged SMA1000 customers to patch two zero-day vulnerabilities the vendor says have been exploited. CVE-2026-83548 is a pre-authentication SSRF flaw in the Appliance Work Place interface that ca...

Security AI
Security AI

Langflow flaw is being exploited to harvest cloud and AI credentials

Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by Bleepi...

Security
Security

Attackers exploit Artifactory authentication-bypass flaw

Threat actors began exploiting CVE-2026-82329 in JFrog Artifactory on September 1, according to watchTowr. The critical authentication-bypass flaw can allow an unauthenticated network attacker to obtain administrative privileges u...

AI Security
AI Security

OpenAI says Astra reached its critical cyber-capability threshold

OpenAI says its forthcoming Astra model has reached the company's threshold for critical cyber capabilities, defined as independently finding and exploiting previously unknown vulnerabilities in real-world software. The company p...