The system was restored on 8 September. The aviation network still had a backlog to clear. A sourced timeline and worked recovery example explain the gap.
Google reports Breeze Comet running two waves of fraudulent transactions through Brazilian payment systems. The count is a victim’s, the only money figure is in a different section, and no rail validates intent.
The 91% figure describes the vulnerability catalogue, not the cause of breaches. The only quantified entry-vector number anyone can cite is a 2016 survey of about 222 sites.
Cosmos Labs' own policy calls for private distribution before public disclosure on a network-wide risk. The advisory also never reached the global GitHub database, so no dependency scanner ever raised it.
Ransom demands are collapsing and backups are working. Average recovery cost still rose 11% to $1.7m, and JLR lost five weeks of production for a modelled £1.9bn. The money moved from the ransom to the restore.
A 72-hour clause is not a control, it is an accounting mechanism. The clock starts at the vendor's awareness, which is the one variable your contract cannot set.