Apple Patches macOS Flaw Used to Mine Monero on Hijacked Macs
TLDR
- Attackers exploited a macOS Screen Sharing flaw to gain root access and install Monero mining software on internet-facing Macs
- The Dutch National Cyber Security Centre confirmed active exploitation on multiple systems with port 5900 exposed to the internet
- Apple patched the flaw on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9
- CISA upgraded the vulnerability score to 9.8 critical, up from an earlier rating of 7.1
- Changing Screen Sharing passwords does not fix the issue; only Apple’s latest security update does
Attackers exploited a flaw in Apple’s macOS Screen Sharing feature to take over Macs connected to the internet and use them to mine Monero. The Netherlands’ National Cyber Security Centre confirmed the attacks in an updated advisory on Aug. 12.
⚠️ALERT: Critical Apple Screen Sharing flaw exploited to hijack Macs and mine Monero.
The Netherlands’ cyber agency confirms that attackers gained full control of internet-exposed Macs through a simple flaw in Apple’s Screen Sharing feature and installed Monero miners.
… Continue reading the full article at the original source below.
This content is automatically aggregated. Full credit goes to the original publisher (coincentral.com).


