LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents
security

Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate

North Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.

zeroday.news ·

North Carolina Ports has confirmed that it is in the process of restoring its IT systems following a cyberattack that forced a shift to manual operations across all three of its locations. The incident, which began on Tuesday, August 4, 2026, affected facilities in Wilmington, Morehead City, and Charlotte.

A spokesperson for North Carolina Ports stated that an "outside actor or group" had "hacked" their IT system. In response, the organization activated its contingency plan and engaged with multiple state agencies and the U.S. Coast Guard. The breach has reportedly been contained, and recovery efforts are underway.

Despite the system issues, all three port locations maintained a normal operating schedule as of Thursday, August 6, 2026, though operations were being processed manually. Signs posted at port gates since Tuesday had warned companies of potential delays. An external forensics team is collaborating with the internal IT department to assess the damage and restore affected systems. The ports handle over 4 million tons of cargo annually.

North Carolina Ports has not disclosed whether the incident was a ransomware attack, nor has any hacking group publicly claimed responsibility.

The attack comes amid a broader trend of cyber incidents targeting critical infrastructure. Ports in various regions, including the U.S., Europe, and Asia, have been frequent targets for ransomware groups in recent years as they increasingly adopt digital operational technologies. For instance, in 2024, the Port of Seattle experienced a cyberattack that disrupted operations at its airport and seaport, though it refused to pay a ransom.

In response to such incidents, Senator Tom Cotton (R-Ark.) penned a letter on Wednesday, August 5, 2026, to Treasury Secretary Scott Bessent. Cotton urged increased investment in and modernization of American operational technology, highlighting the vulnerability of vital infrastructure like water systems, power facilities, and industrial plants, particularly in rural areas, to cyberattacks. He emphasized that attacks on civilian infrastructure have become a common tactic in modern warfare, with American operational technology being a prime target.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind

breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

cybersecurity

China Launches Cybersecurity Review of Palo Alto Networks Products

China's Cyberspace Administration has initiated a cybersecurity review of Palo Alto Networks' products sold within the country, citing national security concerns. The review, based on national security and cybersecurity laws, lacks specific details regarding the reasons or potential impact. Palo Alto Networks has stated that its operations and product delivery in the region remain unaffected for now.

ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.