Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Дата публикации: 14-08-2026 14:59:55

The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]

Основное содержимое страницы с новостью.

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.

The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900.

Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases. The flaw allows network-based attackers to gain access without valid credentials.

image

An attacker could use this access to open applications remotely, access files, change security settings, and perform various other actions.

In an update to the initial advisory, the Dutch agency said it received a report indicating that the vulnerability is being exploited in the wild in attacks where port 5900 is exposed to the internet.

According to the NCSC, the attacker obtained root access to the system and deployed a Monero cryptocurrency miner.

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” reads the Dutch agency's update.

“In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.”

macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:

  • macOS Tahoe 26.6.1
  • macOS Sequoia 15.7.9
  • macOS Sonoma 14.8.9

These releases improve state management mechanisms to enforce correct credential validation and prevent rogue authentication attempts.

Where system updates are not immediately possible, users can use System Settings to disable Screen Sharing (General → Sharing → Screen Sharing) if not needed.

NSCS has not shared any details about the reported attacks, when they started, if they extend beyond cryptocurrency mining, or how many systems have been impacted.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1macOS security flaw lets hackers disable Mac protection tools without a password-5725-06-2026
2Lücke in macOS: Code von vertrauten Apps lässt sich unbemerkt austauschen07.5127-07-2026
3 Dangerous new CrashStealer Mac impersonates Apple's own tools — and bypasses Gatekeeper — to steal your passwords and more -5715-07-2026
4KDE Plasma Affected By Arbitrary Code Execution To Break Sandboxes With "Open New Window"-2702-07-2026
5Apple reveals iPhones are under attack from 'sophisticated' hacks secretly accessing devices: 'Act Now'-2615-01-2026
6Claude Cowork escaped sandbox on Mac, gain full access to all files08.1627-07-2026
7Hackers breached DHS information-sharing network, people familiar say-2730-06-2026
8Max severity SAP Commerce Cloud flaw now targeted in attacks09.2314-08-2026
9CrashStealer malware masquerades as Apple’s crash report tool to raid your Mac-2714-07-2026
10Seven iPhone models compromised by major security breach... is yours on the list?-3720-06-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.31. Источник: www.bleepingcomputer.com.