We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
_cfuvidThis cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators.
Maximum Storage Duration: SessionType: HTTP Cookie
__cf_bm [x7]This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
CookieConsentStores the user's cookie consent state for the current domain
Maximum Storage Duration: 1 yearType: HTTP Cookie
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
We do not use cookies of this type.
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
We do not use cookies of this type.
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
We do not use cookies of this type.
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
List of domains your consent applies to: [#BULK_CONSENT_DOMAINS#]
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.
The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.
This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.
You can at any time change or withdraw your consent from the Cookie Declaration on our website.
Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.
Please state your consent ID and date when you contact us regarding your consent.
Apple has fixed a macOS Screen Sharing vulnerability that hackers have been using to mine Monero on open Macs.
An updated warning by the Netherlands’ National Cyber Security Centre said Apple patched a macOS Screen Sharing vulnerability attackers exploited to gain root access and install Monero mining software on exposed Macs connected to the Internet.
On August 12, the Dutch National Cyber Security Centre reported that it had observed CVE-2026-65400 in use, targeting multiple systems connected to the internet through port 5900. In every instance it had seen, the attacker would have had root access and subsequently installed a Monero miner. The NCSC did not say how many devices were affected by the activity, nor did it name a group.
On August 6, Apple released an update for macOS Tahoe, Sequoia, and Sonoma to address the flaw. The Screen Sharing flaw is a state management error that could allow a network-based attacker to bypass authentication via the service.
Security company Huntress reported that a flaw in the SCRAM (Secure Remote Password) authentication mechanism could allow an unauthenticated connection to be treated as an authenticated connection, allowing for a privilege escalation. As the flaw occurs prior to normal authentication, changing passwords or disabling accounts does not reduce the vulnerability.
Huntress suggested applying Apple’s security updates or disabling Screen Sharing until vulnerable hosts can be updated. Researcher Ryan Dowd did a search on Censys and found tens of thousands of exposed hosts, although this number does not represent the number of infected hosts.
Read More: Zcash Is Making a Comeback: Why ZEC Could Lead Crypto’s Privacy Revival
Hosted bare-metal Macs are especially at risk, as remote Mac provisioning may leave Screen Sharing enabled on freshly provisioned machines. The vulnerability was given a CVSS severity score of 9.8 by CISA. No privileges or user interaction are required to exploit.
According to the Dutch NCSC, in these attacks, the attackers compromised these Macs to use their processing power to mine Monero (rather than stealing wallets). Once the attackers had root access to the compromised Macs, they used the Macs’ processing power to mine Monero. These addresses have not been reported: the miner and mining-pool address, the attackers’ wallets, or the amount of XMR▲$323.54 mined.
Read More: How Digital Platforms are Redefining Trust in Online Finance
Monero’s popularity for cryptojacking, due to its mineability on general purpose hardware, has resulted in it being frequently abused in this manner. It is part of a broader trend of cryptocurrency attacks on macOS, including both crypto-jacking and malware targeting cryptocurrency companies.
At the time of this writing, XMR traded around $417 and appreciated by around 2% against the dollar in 24 hours. Over seven days, XMR appreciated by nearly 6.7%, not reflecting the mining campaign’s size or returns.
Security vendor Huntress noted that the best mitigation for this vulnerability is to patch vulnerable Mac systems, especially ones exposing the Screen Sharing ports directly to the Internet, even if administrators believe it is disabled.
As the campaign is not yet proved, and there are no published public indicators of compromise for the mining infrastructure, later incident response may show how long CVE-2026-65400 was active before the patch was released.