Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Behind the Blog: Endless Scam Parade

    August 14, 2026

    Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

    August 14, 2026

    The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

    August 14, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
    News

    Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

    adminBy adminAugust 14, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

    The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.

    The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900.

    Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases. The flaw allows network-based attackers to gain access without valid credentials.

    image

    An attacker could use this access to open applications remotely, access files, change security settings, and perform various other actions.

    In an update to the initial advisory, the Dutch agency said it received a report indicating that the vulnerability is being exploited in the wild in attacks where port 5900 is exposed to the internet.

    According to the NCSC, the attacker obtained root access to the system and deployed a Monero cryptocurrency miner.

    “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” reads the Dutch agency’s update.

    “In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.”

    macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:

    • macOS Tahoe 26.6.1
    • macOS Sequoia 15.7.9
    • macOS Sonoma 14.8.9

    These releases improve state management mechanisms to enforce correct credential validation and prevent rogue authentication attempts.

    Where system updates are not immediately possible, users can use System Settings to disable Screen Sharing (General → Sharing → Screen Sharing) if not needed.

    NSCS has not shared any details about the reported attacks, when they started, if they extend beyond cryptocurrency mining, or how many systems have been impacted.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
    Next Article Behind the Blog: Endless Scam Parade
    admin
    • Website

    Related Posts

    News

    Behind the Blog: Endless Scam Parade

    August 14, 2026
    News

    The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

    August 14, 2026
    News

    Infosec News Nuggets — August 14, 2026 – AboutDFIR

    August 14, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    Behind the Blog: Endless Scam Parade

    August 14, 2026

    Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

    August 14, 2026

    The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

    August 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.