North Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.

North Carolina Ports has confirmed that it is in the process of restoring its IT systems following a cyberattack that forced a shift to manual operations across all three of its locations. The incident, which began on Tuesday, August 4, 2026, affected facilities in Wilmington, Morehead City, and Charlotte.
A spokesperson for North Carolina Ports stated that an "outside actor or group" had "hacked" their IT system. In response, the organization activated its contingency plan and engaged with multiple state agencies and the U.S. Coast Guard. The breach has reportedly been contained, and recovery efforts are underway.
Despite the system issues, all three port locations maintained a normal operating schedule as of Thursday, August 6, 2026, though operations were being processed manually. Signs posted at port gates since Tuesday had warned companies of potential delays. An external forensics team is collaborating with the internal IT department to assess the damage and restore affected systems. The ports handle over 4 million tons of cargo annually.
North Carolina Ports has not disclosed whether the incident was a ransomware attack, nor has any hacking group publicly claimed responsibility.
The attack comes amid a broader trend of cyber incidents targeting critical infrastructure. Ports in various regions, including the U.S., Europe, and Asia, have been frequent targets for ransomware groups in recent years as they increasingly adopt digital operational technologies. For instance, in 2024, the Port of Seattle experienced a cyberattack that disrupted operations at its airport and seaport, though it refused to pay a ransom.
In response to such incidents, Senator Tom Cotton (R-Ark.) penned a letter on Wednesday, August 5, 2026, to Treasury Secretary Scott Bessent. Cotton urged increased investment in and modernization of American operational technology, highlighting the vulnerability of vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural areas, to cyberattacks. He emphasized that attacks on civilian infrastructure have become a common tactic in modern warfare, with American operational technology being a prime target.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a