Vulnerability in Mac Allowed Installation of Hidden Monero Miners

cryptonews.ruPublished on 2026-08-17Last updated on 2026-08-17

Abstract

The Dutch National Cyber Security Centre (NCSC) identified a new attack vector targeting Mac devices, exploiting a vulnerability in the Screen Sharing feature. This flaw allowed attackers to gain complete control of a computer, steal data, and install a Monero cryptocurrency miner. Details regarding the number of victims or attackers were not disclosed. The NCSC issued a report on August 12. Initially, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) assigned the threat (CVE-2026-65400) a risk rating of 7.1 out of 10, but raised it to 9.8 two days later. Apple has since patched the vulnerability in updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to the company, the bug could allow unauthorized remote access to a Mac via Screen Sharing. While this feature is disabled by default, it is frequently enabled for remote access, including to Apple devices via remote servers. Researcher Ryan Doud from Huntress urged macOS users to install the latest updates immediately, noting that a scan via Censys revealed tens of thousands of potentially vulnerable hosts.

The Dutch National Cyber Security Centre (NCSC) detected a new vector of online attacks on Mac devices via a vulnerability in Screen Sharing.

The NCSC reported that attackers gained full control of the computer, stole data, and installed a Monero miner. The number of victims and suspected participants in the attacks was not disclosed.

The organization released a report on the vulnerability on August 12. At that time, the U.S. Cybersecurity and Infrastructure Security Agency assigned the threat CVE-2026-65400 a risk rating of 7.1 out of 10, but raised it to 9.8 two days later.

Source: U.S. Cybersecurity and Infrastructure Security Agency.

Apple has already fixed the bug in an update for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to the company's description, due to this bug, an attacker could gain access to a Mac via Screen Sharing without authorization.

The "Screen Sharing" function is disabled by default, but it is often enabled for remote access to Apple devices, including via remote servers.

Huntress researcher Ryan Daud urged macOS users to install the latest updates immediately. According to him, a search via Censys revealed tens of thousands of potentially vulnerable hosts.

Recall that in May, the AI model Claude Mythos helped "white-hat" hackers hack macOS. Researchers were able to bypass Apple's Memory Integrity Enforcement protection mechanism.

end-content

Related Questions

QWhat is the vulnerability in Mac that allowed hidden Monero miners to be installed?

AThe vulnerability was in the Screen Sharing feature, which allowed attackers to gain unauthorized access to a Mac computer.

QWhich agency initially gave the threat a risk rating of 7.1 out of 10, and what was it later raised to?

AThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) initially gave it a rating of 7.1. Two days later, it raised the rating to 9.8 out of 10.

QWhich macOS versions received updates from Apple to fix the Screen Sharing vulnerability?

AApple fixed the bug in updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

QHow many potentially vulnerable hosts were discovered through a search on Censys according to researcher Ryan Daught?

AA search via Censys revealed tens of thousands of potentially vulnerable hosts.

QIn a previous security event mentioned, what did the AI model Claude Mythos help 'white hat' hackers bypass?

AThe AI model Claude Mythos helped 'white hat' hackers bypass Apple's Memory Integrity Enforcement mechanism.

Related Reads

Popular First-Layer Blockchain Network Announces Hard Fork Preparation Plans: 'Code Development Process to Be Completed by the End of 2026!'

The first-layer blockchain network Cardano (ADA) has publicly released its hard fork plan for the "Dijkstra Era," representing the ecosystem's next major technical transformation. According to the roadmap published via Cardano's official channels, the network upgrade process will occur in multiple phases, with the primary goal of completing all core code development by the final quarter of 2026. The first phase involves finalizing all core software development and preparing the mainnet for the upgrade, including updating the Cardano protocol to version 12 and implementing new features. These updates are stated to bring significant improvements to network performance, scalability, and future governance mechanisms. The second phase aims to implement the Ouroboros Peras upgrade, a major innovation to Cardano's consensus mechanism, planned for activation via a hard fork in Q2 2027. Its main goal is to accelerate transaction finality and improve user experience. The Cardano team emphasized that the roadmap dates are targets for completing code development and mainnet preparation. The actual deployment of upgrades on the mainnet will require community approval through Cardano's on-chain governance mechanisms. Experts describe the Dijkstra Era as one of the most significant updates aimed at strengthening Cardano's technical foundation, with investors and developers closely watching the network's evolution over the next two years.

cryptonews.ru5m ago

Popular First-Layer Blockchain Network Announces Hard Fork Preparation Plans: 'Code Development Process to Be Completed by the End of 2026!'

cryptonews.ru5m ago

Trading

Spot
活动图片