Hackers exploit macOS screen sharing vulnerability to mine Monero

NewsSun, 16 Aug 2026 12:09:37 UTC6 hours ago
Hackers exploit macOS screen sharing vulnerability to mine Monero

A remote desktop feature built into every modern Mac has become an open door for hackers, and Dutch cybersecurity officials say the break-in is already happening. Security researchers and government agencies are now warning users about an actively exploited macOS screen sharing vulnerability that lets attackers take control of a computer without ever needing a password, then quietly install cryptocurrency mining software on the machine.

Key takeaways

  • The flaw, tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10 and lets attackers execute code remotely without valid credentials.
  • The Netherlands’ National Cyber Security Centrum (NCSC) confirmed active exploitation on systems where port 5900 was reachable from the internet.
  • Attackers who exploited the bug gained root access and installed Monero crypto miners on affected Macs.
  • Apple patched the issue last week in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
  • Users can reduce risk by disabling Screen Sharing when it’s not in use and installing the latest security update.

High-Severity macOS Vulnerability Allows Remote Code Execution

CVE-2026-65400 is a bug that lets a remote attacker run malicious code on a Mac without needing a username or password. Apple’s built-in Screen Sharing feature, which uses the VNC protocol to let one computer view and control another over a network, is at the center of the problem.

… Continue reading the full article at the original source below.

Read from Source · en.cryptonomist.ch ↗
This content is automatically aggregated. Full credit goes to the original publisher (en.cryptonomist.ch).

Related