Rented Mac Computers Provide Attackers with Root Access via Screen Sharing Function Login

cryptonews.ru2026-08-17 tarihinde yayınlandı2026-08-17 tarihinde güncellendi

Özet

CISA has elevated the severity rating of a macOS Screen Sharing vulnerability to a critical 9.8 out of 10. The flaw, tracked as CVE-2026-65400, resides in how the feature handles authentication via the Secure Remote Password protocol, potentially allowing an attacker to gain access before password verification occurs. Attackers have already exploited this by targeting internet-exposed Macs, gaining root access via port 5900, and silently installing Monero cryptocurrency mining software. While the Screen Sharing feature is disabled by default, it's commonly used on "bare metal" Macs rented from hosting providers. Security researchers identified tens of thousands of potentially vulnerable hosts online, with many being these hourly-rented machines. Apple has issued patches in macOS versions Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, urging all users to apply updates immediately.

On Friday, CISA raised the severity rating of a macOS screen sharing function vulnerability to critical — 9.8 out of 10.

Dutch investigators reported that attackers gained root privileges on internet-connected Mac computers and stealthily installed Monero mining software.

From 7.1 to 9.8 in a Week

When Apple released the patch, CISA scored this bug, tracked as CVE-2026-65400, at 7.1 in the National Vulnerability Database. The agency then revised the score to 9.8, which is close to the top of the CVSS scale.

The Dutch National Cybersecurity Centre took a similar approach. An August 12th update amended its initial advisory, stating that a publicly available proof-of-concept code is in circulation and active abuse has been confirmed.

As of Friday, this vulnerability had not been added to the federal catalog of Known Exploited Vulnerabilities maintained by the Cybersecurity and Infrastructure Security Agency. Apple's own entry in the Dutch agency's CVE registry still had the older 7.1 rating.

The vulnerability relates to how the Screen Sharing function handles authentication. Huntress trac the cause to a flaw in the service's use of the Secure Remote Password protocol, which is used to verify the user before granting access.

Huntress says that in practice, this causes the Mac to believe an outsider has already logged in. The failure occurs before the password check. Resetting or deleting screen sharing passwords does not eliminate this possibility.

"Anyone using Apple’s Screen Sharing feature on any supported version of macOS must immediately install the latest security updates," wrote Huntress researcher Ryan Doud.

Apple released this patch in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 6th.

Tens of Thousands of Rented Mac Computers Are Affected

The NCSC stated that the victims' computers were fully compromised. In every case examined by researchers, the attacker gained access to the system via port 5900, the standard port for screen sharing, which remained open to the internet.

They then obtained root privileges and deployed a Monero cryptocurrency miner ($XMR). The Dutch agency did not disclose the number of affected systems or name a suspect.

The Screen Sharing function is disabled by default. However, it is a standard tool for managing Macs running on "bare metal," meaning physical Apple hardware rented and used in remote data centers, where most of the risk is concentrated.

According to Doud, using the internet scanning tool Censys, he discovered "tens of thousands of potentially vulnerable hosts." Many of these, Huntress claims, are machines rented by the hour from hosting providers.

Cryptopolitan reported on the Reaper malware, which exploits Script Editor to empty wallets, and macOS malfunctions that prompt victims to insert malicious commands into the Terminal.

Cryptojacking, the theft of computing power to obtain cryptocurrency, has long been a hallmark of Monero. Unlike specialized mining rigs, Monero cryptocurrency can be mined on regular CPUs, and transactions are private by default.

The profit from each hacked Mac is low. On Monday, the price estimated roughly 432 $XMR produced by the Monero network per day to be worth approximately $179,000, distributed among all miners. On Monday, $XMR traded at $413.47, up about 0.9% over the previous 24 hours.

İlgili Sorular

QWhat vulnerability in macOS was escalated to a critical severity rating of 9.8 by CISA?

ACISA escalated the severity rating of a vulnerability in the macOS Screen Sharing function's authentication handling, tracked as CVE-2026-65400, to a critical 9.8 out of 10.

QHow did attackers gain root access to the compromised Mac computers according to the article?

AAttackers gained root access by exploiting the Screen Sharing vulnerability to access systems via port 5900, which was left open to the internet on the victim computers.

QWhat specific malware did the attackers deploy after compromising the Mac systems?

AAfter gaining root access, the attackers deployed a Monero cryptocurrency mining software (cryptojacking malware) on the compromised Mac systems.

QAccording to a Huntress researcher, how many potentially vulnerable hosts were found using an internet scanning tool?

AA Huntress researcher, using the Censys internet scanning tool, found 'tens of thousands of potentially vulnerable hosts,' many of which were machines rented by the hour from hosting providers.

QWhich macOS versions received the security patch from Apple to fix this Screen Sharing vulnerability?

AApple released the security patch in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 6th to fix this vulnerability.

İlgili Okumalar

Trump-Backed Company World Liberty Financial Partners with Chinese AI Company of Limited Access to Provide Artificial Intelligence Services

According to a Reuters report, Trump-backed cryptocurrency company World Liberty Financial is linked to WorldClaw, a Hong Kong-based platform providing access to Chinese AI models that the U.S. government has flagged as security threats. WorldClaw's platform features AI models from Chinese companies like Alibaba, Baidu, Z.ai, DeepSeek, and Moonshot, some of which are designated by U.S. entities as tied to the Chinese military or subject to export restrictions. The connection is facilitated by World Liberty's dollar-pegged stablecoin, $USD1, which is accepted for payment on WorldClaw. The Trump family benefits from interest generated by the stablecoin's reserves, and token sales have earned them over $1.4 billion. A World Liberty executive previously advised WorldClaw on integrating $USD1. Security experts warn that using these Chinese AI models could expose users to surveillance or malicious code. WorldClaw claims over 10,000 users and processes 50 million queries daily, partly due to the lower cost of Chinese models. Both companies and the White House deny any conflict of interest, stating the platform helps American AI firms access international markets and that listing models does not imply endorsement. External critics, however, argue it is hypocritical to profit from Chinese AI tools while the U.S. government aims to counter the rise of Chinese AI.

cryptonews.ru40 dk önce

Trump-Backed Company World Liberty Financial Partners with Chinese AI Company of Limited Access to Provide Artificial Intelligence Services

cryptonews.ru40 dk önce

Moscow's Mining Ban Takes Effect: What Will Be the Consequences?

Mining has been banned in Moscow, the Moscow region, and parts of the Kursk region from August 15, with the prohibition set to last until December 31, 2032. The measure, requested by regional authorities, aims to prevent electricity shortages caused by energy-intensive mining equipment. This follows the legalization of cryptocurrency mining in Russia in November 2024, with restrictions now in place across 16 regions. Initially a blanket ban, an exception was introduced in March 2025 for miners using their own power generation, such as gas piston units or diesel generators, independent of the national grid. Major industry players had already begun shifting to on-site gas generation near gas fields to bypass grid limitations. While a trend emerged in 2025 to combine mining with AI computing infrastructure, this was complicated by authorities granting data centers (with a ban on mining inside them) preferential status as communication facilities. Experts state the new Moscow-area ban will significantly reshape Russia's mining geography but have a minimal global impact on Bitcoin's hash rate. The primary consequence will be a stronger industry shift to regions with energy surpluses, clear connection terms, and willingness to handle such loads. Moscow was already a contentious location due to high competition for power from data centers, industry, and urban infrastructure. For the Kursk region, the ban is also linked to infrastructure stability in border areas. The ban accelerates a market split. Large, legal operators will relocate equipment or seek sites with self-generation, while smaller or semi-legal miners operating in urban or industrial networks face higher costs and potential displacement into illegality. Industry participants note that post-2024 legalization had an unintended effect, with some major companies closing due to financial issues. Russian miners also face global pressures like low Bitcoin prices relative to mining costs, rising electricity prices, and the approaching 2028 halving, forcing some to shut down equipment.

cryptonews.ru43 dk önce

Moscow's Mining Ban Takes Effect: What Will Be the Consequences?

cryptonews.ru43 dk önce

İşlemler

Spot
活动图片