Updated: US Coast Guard is probing a cyberattack that disrupted North Carolina ports
Meta undercuts AI coding rivals on price, Meta AI model breaches test containment, OpenAI agents built a secret message board, Snowflake hacker pleads guilty, Researchers crack AI browsers, Ransom Cartel mastermind gets 16 years, Chinese spyware goes commercial, DPRK hackers hit 1,600 orgs, more

Metacurity is the cybersecurity news you'd need hours to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
The US Coast Guard's cyber division is leading the federal response to a cyberattack that disrupted information technology systems at the North Carolina State Ports Authority this week, according to a source knowledgeable about port operations, as investigators work to determine whether the intrusion was the work of ransomware operators or a nation-state actor.
The source said the Coast Guard is "running point" on the investigation. While emphasizing that no attribution has been made, the source said early speculation within the maritime community likely focuses on either a ransomware attack or activity linked to Chinese threat actors.
North Carolina Ports confirmed that it had experienced a cybersecurity incident affecting its information technology systems serving the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Terminal. The authority said cargo operations continue but warned customers to expect delays while contingency procedures remain in place.
The ports authority said it detected unauthorized activity on its network, isolated affected systems and launched an investigation with outside cybersecurity specialists and law enforcement. Public statements have not identified the type of malware involved or named a suspected threat actor.
If confirmed, the incident would represent the latest cyber disruption affecting critical US transportation infrastructure and comes as federal officials have spent years warning that American ports are increasingly attractive targets for both financially motivated cybercriminals and foreign intelligence services.
The Coast Guard has assumed an increasingly prominent role in maritime cybersecurity in recent years. In 2025, it issued updated guidance requiring the reporting of cyber incidents affecting the Marine Transportation System, while broader federal efforts have expanded the Coast Guard's responsibilities for overseeing cyber risk at ports and maritime facilities.
Chinese concerns add context
The attack also revives longstanding concerns about China's potential access to US port infrastructure.
In 2023, I broke the news that senior US maritime officials were studying cybersecurity risks associated with Chinese-manufactured ship-to-shore cranes after intelligence and security officials raised concerns that the equipment could provide opportunities for espionage or disruption. The reporting highlighted growing unease inside the federal government over China's dominant position in the global crane market.
Those concerns later became a central element of the Biden administration's maritime cybersecurity strategy. In early 2024, the administration announced a series of actions designed to strengthen port cybersecurity, including a Coast Guard maritime cybersecurity directive, investment in domestically manufactured cargo cranes and additional scrutiny of Chinese-made port equipment.
Although there is no evidence linking the North Carolina incident to Chinese-manufactured cranes or to Chinese government actors, the attack underscores why US officials have spent years attempting to reduce cyber risks across the nation's maritime transportation infrastructure.
North Carolina Ports has not disclosed how the attackers gained access, whether data was stolen or encrypted, or when it expects all systems to be fully restored.
Update: Metacurity heard from Coast Guard public affairs officer Luke Pinneo, who said via email that "Because the investigation is ongoing, the details I can provide are limited. I can confirm that the Coast Guard is aware, and in coordination with our partner agencies, we are continuing to monitor." (Cynthia Brumfield / Metacurity)
Related: Port Technology, Queen City News, Index Box, WXII, WCNC, WECT, Splash 247