Dutch NCSC warns exploited macOS flaw let attackers install Monero miners on internet-exposed Macs

Dutch NCSC warns exploited macOS flaw let attackers install Monero miners on internet-exposed Macs

N
News Editor
2026-08-16 13:17:00
The Dutch National Cyber Security Centre (NCSC) has warned that a recently patched authentication flaw in Apple’s macOS Screen Sharing component is already being exploited in the wild, according to The Hacker News. The bug, tracked as CVE-2026-65400 and rated 9.8 on the CVSS scale, allowed attackers to access internet-exposed Macs listening on port 5900 without valid credentials and deploy Monero mining malware. Apple issued emergency fixes on Aug. 6 through macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, saying the patch strengthened credential validation by improving state management. The NCSC said it confirmed multiple attacks in which intruders gained root privileges and installed mining software. Security researcher @osxreverser also disclosed another pre-authentication flaw in the same component, likewise fixed in version 26.6, which could be exploited with only a target IP address and no username. Calif said researchers used AI to build working exploits for the two bugs in just four hours, highlighting how AI is shortening the time between vulnerability discovery and exploit development. Users were advised to update immediately or disable Screen Sharing if patching is not possible.

The Dutch National Cyber Security Centre (NCSC) has warned that a recently patched authentication flaw in Apple’s macOS Screen Sharing component is being exploited in the wild, according to The Hacker News. The vulnerability, CVE-2026-65400, carries a CVSS score of 9.8.

Attackers can reach Macs exposed to the internet on port 5900 without valid credentials and install Monero mining malware. The NCSC said it confirmed multiple attacks in which the intruders obtained root privileges and deployed mining software.

Apple shipped emergency fixes on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. The company addressed the issue by improving state management to strengthen credential validation.

Security researcher @osxreverser also disclosed another pre-authentication flaw in the same component. That issue was also fixed in version 26.6. Based on the disclosure, the bug could be exploited with only a target IP address, allowing password authentication to be bypassed without a username.

Calif said researchers used AI to develop working exploits for the two vulnerabilities in four hours, pointing to a much shorter gap between discovering flaws and producing exploit code. Users were advised to update their systems immediately. If they cannot install the updates, they should disable Screen Sharing.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
40

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.