Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner
The Dutch National Cyber Security Center (NCSC) has warned that threat actors are actively exploiting an authentication bypass vulnerability in macOS after public exploit code became available.
The security flaw, tracked as CVE-2026-65400, affects macOS Screen Sharing, Apple’s built-in remote desktop feature. The service enables remote access and control over a network using the Virtual Network Computing (VNC) protocol through TCP port 5900.
Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier supported releases. The vulnerability allows attackers on the network to bypass authentication and gain access without valid credentials.
Once access is obtained, an attacker may be able to remotely launch applications, view or modify files, change security settings, and perform other actions on the compromised Mac.
In an update to its initial advisory, the Dutch cybersecurity agency said it had received reports of active exploitation against systems with TCP port 5900 exposed directly to the Internet.
According to the NCSC, attackers gained root privileges on affected macOS systems and installed a Monero cryptocurrency miner.
“NCSC has received notification that active exploitation of this vulnerability has been observed on multiple systems that have access to port 5900 from the Internet,” the agency said in its latest advisory.
“In all of these cases, root was accessed and a Monero crypto miner was deployed on the affected systems.”
Apple users should update their Macs to one of the following versions, which include fixes for CVE-2026-65400:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
These updates improve the system’s state-management mechanisms to enforce valid credential checks and block unauthorized authentication attempts.
If installing an update is not immediately possible, users should disable Screen Sharing when it is not required. The setting can be found under System Settings → General → Sharing → Screen Sharing.
The NCSC did not disclose additional details about the attacks, including when exploitation began, whether the campaigns have expanded beyond cryptocurrency mining, or how many systems have been compromised.
The overall prevention score can hide what happens after an attacker gains initial access. When threat actors use valid credentials, the effectiveness of your defenses can drop sharply.
Blue Report 2026 evaluates defense techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




