This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com
NewsLayer PulseLIVEBTC$63,974+1.43%ETH$1,906+1.23%SOL$75.84+0.46%XRP$1+0.35%DOGE$0.0704+0.55%ADA$0.1744-1.30%Total Cap$2.29T+0.74%Layer Index44 Neutral
BreakingExternal ReportingUpdated 2時間前

Hackers Exploit macOS Screen Sharing Bug to Mine Monero

Hackers are exploiting a newly patched flaw in Apple’s Mac screen-sharing feature to take control of vulnerable computers and secretly mine Monero, according to the Netherlands’ National Cyber Security Centre (NCSC-NL).

Hackers Exploit macOS Screen Sharing Bug to Mine Monero
Publisher DailyCoin 2 分で読める
Image via DailyCoin
翻訳中…

Layer Index

44

↑ 2 pts in 24h

Hackers are exploiting a newly patched flaw in Apple’s Mac screen-sharing feature to take control of vulnerable computers and secretly mine Monero, according to the Netherlands’ National Cyber Security Centre (NCSC-NL).

The agency confirmed on August 13 that attackers are actively exploiting the vulnerability, tracked as CVE-2026-65400. 

Sponsored

Crypto Prediction Markets

18+ · Gambling involves risk. Play responsibly.

The flaw allows attackers to bypass authentication in macOS Screen Sharing and gain high-level access to affected Macs, which they can then use to install cryptocurrency-mining malware.

The attack is a form of cryptojacking: instead of stealing cryptocurrency from a wallet or exchange, criminals hijack someone else’s computing power and use it to generate crypto.

Apple released an emergency security update on August 6. But Macs that have not been patched — particularly those with Screen Sharing exposed directly to the internet — remain at risk.

How the Mac attack works

The vulnerability affects screensharingd, the macOS component responsible for the operating system’s built-in remote-access feature.

The flaw allows a network-based attacker to get past Screen Sharing’s normal authentication checks without valid credentials. Once access is obtained, attackers can gain root-level control of the Mac and install additional software.

NCSC-NL said that in every compromise it observed, attackers installed a Monero miner.

Security researchers at Huntress also found that common attempts to secure Screen Sharing, such as changing the password or removing authorized accounts, do not prevent exploitation of the underlying vulnerability. Patching the operating system or disabling Screen Sharing entirely is required to close the attack path.

Huntress noted that the risk is compounded by the rise of hosted bare-metal Mac services, such as cloud-based Mac minis, which often ship with Screen Sharing enabled by default. A search on the internet-scanning platform Censys turned up tens of thousands of potentially vulnerable hosts tied to such providers, according to Huntress.

Apple’s fixes cover macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.

Why Monero?

Monero (XMR) can be mined using general-purpose computer processors, and its privacy features can make some transactions more difficult to trace.

XMR uses a proof-of-work algorithm called RandomX, which is designed to run on general-purpose CPUs rather than the specialized mining hardware commonly used to mine Bitcoin and some other cryptocurrencies.

For attackers, this can reduce the cost of running a mining operation. They can use victims’ computing power and electricity to mine Monero rather than purchasing and operating their own hardware.

Monero also has privacy features designed to obscure the identities of parties to transactions, making some transactions more difficult to trace. Those features have drawn increased regulatory scrutiny in some jurisdictions, particularly in the context of anti-money-laundering measures.

Why This Matters

Attackers can use victims’ Macs and electricity to mine crypto, shifting the cost of the mining operation to the victim. The extra CPU usage can also slow the affected computer and increase energy consumption.

Dive into DailyCoin’s hottest crypto news today:
Trezor Warns of Phishing Risk After 14,000-Customer Data Leak
How Stablecoin Regulation Drives Blockchain Innovation 2026

DailyCoin's Vibe Check: Which way are you leaning towards after reading this article?

Never miss a market move

Get the biggest crypto stories, price insights, and DailyCoin exclusives in your inbox.

速報

速報を見逃さない

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by DailyCoin

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

関連記事