Vulnerability in Mac Allowed Installation of Hidden Monero Miners

cryptonews.ruPublicado a 2026-08-17Actualizado a 2026-08-17

Resumen

The Dutch National Cyber Security Centre (NCSC) identified a new attack vector targeting Mac devices, exploiting a vulnerability in the Screen Sharing feature. This flaw allowed attackers to gain complete control of a computer, steal data, and install a Monero cryptocurrency miner. Details regarding the number of victims or attackers were not disclosed. The NCSC issued a report on August 12. Initially, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) assigned the threat (CVE-2026-65400) a risk rating of 7.1 out of 10, but raised it to 9.8 two days later. Apple has since patched the vulnerability in updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to the company, the bug could allow unauthorized remote access to a Mac via Screen Sharing. While this feature is disabled by default, it is frequently enabled for remote access, including to Apple devices via remote servers. Researcher Ryan Doud from Huntress urged macOS users to install the latest updates immediately, noting that a scan via Censys revealed tens of thousands of potentially vulnerable hosts.

The Dutch National Cyber Security Centre (NCSC) detected a new vector of online attacks on Mac devices via a vulnerability in Screen Sharing.

The NCSC reported that attackers gained full control of the computer, stole data, and installed a Monero miner. The number of victims and suspected participants in the attacks was not disclosed.

The organization released a report on the vulnerability on August 12. At that time, the U.S. Cybersecurity and Infrastructure Security Agency assigned the threat CVE-2026-65400 a risk rating of 7.1 out of 10, but raised it to 9.8 two days later.

Source: U.S. Cybersecurity and Infrastructure Security Agency.

Apple has already fixed the bug in an update for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to the company's description, due to this bug, an attacker could gain access to a Mac via Screen Sharing without authorization.

The "Screen Sharing" function is disabled by default, but it is often enabled for remote access to Apple devices, including via remote servers.

Huntress researcher Ryan Daud urged macOS users to install the latest updates immediately. According to him, a search via Censys revealed tens of thousands of potentially vulnerable hosts.

Recall that in May, the AI model Claude Mythos helped "white-hat" hackers hack macOS. Researchers were able to bypass Apple's Memory Integrity Enforcement protection mechanism.

end-content

Preguntas relacionadas

QWhat is the vulnerability in Mac that allowed hidden Monero miners to be installed?

AThe vulnerability was in the Screen Sharing feature, which allowed attackers to gain unauthorized access to a Mac computer.

QWhich agency initially gave the threat a risk rating of 7.1 out of 10, and what was it later raised to?

AThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) initially gave it a rating of 7.1. Two days later, it raised the rating to 9.8 out of 10.

QWhich macOS versions received updates from Apple to fix the Screen Sharing vulnerability?

AApple fixed the bug in updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

QHow many potentially vulnerable hosts were discovered through a search on Censys according to researcher Ryan Daught?

AA search via Censys revealed tens of thousands of potentially vulnerable hosts.

QIn a previous security event mentioned, what did the AI model Claude Mythos help 'white hat' hackers bypass?

AThe AI model Claude Mythos helped 'white hat' hackers bypass Apple's Memory Integrity Enforcement mechanism.

Lecturas Relacionadas

Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logistics partners. While user crypto assets remain secure, the incident highlights a recurring pattern in the industry where breaches of customer data from hardware wallet companies lead to sophisticated phishing campaigns, similar to past incidents involving Ledger and Trezor. The vulnerability underscores that security risks often lie not in the wallet's cryptography but in auxiliary web services and third-party integrations.

cryptonews.ruHace 33 min(s)

Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ruHace 33 min(s)

Trading

Spot
活动图片