Skip to main content
Security

Breeze Comet targets Brazilian payment infrastructure with custom malware

Breeze Comet targets Brazilian payment infrastructure with custom malware Image: Primary
Google Threat Intelligence Group and Mandiant say the financially motivated Breeze Comet group has targeted Brazilian financial services, retail, and e-commerce organizations since 2024, manipulating payment systems and banking software to make fraudulent transfers. The group has completed at least one heist worth tens of thousands of dollars, according to the report. It gains access through password spraying, impersonated IT-support calls, vulnerable JBoss servers, and compromised websites, then uses custom malware and privileged accounts to access payment applications. The activity has culminated in hundreds of fraudulent transactions, the report says.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Products
AI Products

Lambda reportedly raises $1 billion in private debt for Nvidia GPUs

Cloud provider Lambda has reportedly secured $1 billion in short-term private debt to buy Nvidia GPUs, according to Bloomberg reporting cited by Data Center Dynamics. The company is expected to lease the chips to Microsoft under t...

AI
AI

AWS makes Claude Fable 5.1 available through Bedrock

AWS said Claude Fable 5.1 is available today through Amazon Bedrock and Claude Platform on AWS, including US Geo and Global inference profiles. AWS describes the model as suited to coding, scientific research and enterprise workfl...

Security AI
Security AI

Langflow flaw is being exploited to harvest cloud and AI credentials

Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by Bleepi...

AI Security
AI Security

OpenAI says Astra reached its critical cyber-capability threshold

OpenAI says its forthcoming Astra model has reached the company's threshold for critical cyber capabilities, defined as independently finding and exploiting previously unknown vulnerabilities in real-world software. The company p...

AI
AI

Anthropic releases Fable 5.1 with lower cache-read pricing

Anthropic introduced Claude Fable 5.1, which it says is generally available, alongside the more restricted Claude Mythos 5.1. Anthropic says Fable 5.1 will cost an estimated 25% less than Fable 5 for typical token-billed workloads...