AI Stories on SHORT INFO are generated & curated with AI
unverified 16 Aug, 20:11

A critical macOS Screen Sharing flaw is under active exploitation to install cryptocurrency miners

A critical authentication bypass in Apple's $AAPL macOS Screen Sharing, CVE-2026-65400 (CVSS 9.8), is being actively exploited on internet-exposed Macs. The Netherlands' NCSC-NL says attackers gain root access and install a Monero crypto miner. Apple patched the flaw August 6. Pe

A critical authentication bypass vulnerability in Apple's $AAPL macOS built-in Screen Sharing feature, tracked as CVE-2026-65400 (CVSS 9.8), is under active exploitation. The flaw lets network-based attackers authenticate to the remote-desktop service over TCP port 5900 without valid credentials. The Netherlands' National Cyber Security Centre (NCSC-NL) says it has received reports of active abuse on internet-exposed systems: in every reported case, attackers gained root access and installed a Monero cryptocurrency miner. Apple fixed the issue on August 6, 2026 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, crediting security researcher Alfredo Pesoli of Bynario for the discovery. NCSC-NL has not disclosed how many systems were affected or when the attacks began. Sources: BleepingComputer, The Hacker News.

#cyber
Published on
YouTubeInstagramFacebook