@BrianPay you stated you monitor the Comcast gateway IP, do you not also monitor the AT&T gateway IP? If not then it is no surprise that they are affected at the same time as you are monitoring the Comcast network from both WANs. This also ties in with the MX that only had AT&T connected being okay.
Add a second monitor and remember that although each monitored IP will have graph data for both, only the Comcast IP from the Comcast link and the AT&T IP from the AT&T link are good measures.
It won't fix the issue but should at least confirm if both links are fully affected.
For the VPN users, do they come in on the Comcast link, or do you use DNS round robin with them coming in on both?
If my answer solves your problem please click Accept as Solution so others can benefit from it.