All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Hackers Exploit macOS Flaw for Monero Mining

Created at 17 Aug · 1:36 PM1 source↑ Market-relevant
IN SHORT

The Netherlands' NCSC has warned of active exploitation of a macOS Screen Sharing vulnerability. Attackers are gaining root access to systems with port 5900 exposed to the internet and installing Monero mining programs.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

5900port used by Screen Sharing
7.1/10flaw severity rating

Who's Involved

NCSC
Netherlands' National Cyber Security Center warning of exploitation
Apple
Developer of macOS and provider of patches
Hackers Exploit macOS Flaw for Monero Mining

↳ Why This Matters

This vulnerability allows attackers to compromise user privacy and system resources, turning personal computers into tools for illicit cryptocurrency mining without the owner's knowledge or consent, while also highlighting ongoing risks associated with exposed network services.

Key facts

  • Hackers are exploiting a macOS Screen Sharing vulnerability to mine Monero.
  • The flaw allows network attackers to gain root access without valid credentials.
  • Systems with port 5900 exposed to the internet are particularly vulnerable.
  • Apple has released patches for the vulnerability in recent macOS updates.
  • Monero is a privacy coin often used in cryptojacking schemes.

Hackers are actively exploiting a vulnerability in Apple's macOS Screen Sharing feature to gain control of Macs and secretly mine the privacy coin Monero. The Netherlands' National Cyber Security Center (NCSC) issued a warning, noting that systems with port 5900, used by Screen Sharing, exposed to the internet were targeted. Attackers were able to achieve root access, the highest level of control, and install cryptocurrency mining software.

The vulnerability, tracked as CVE-2026-65400, has a severity rating of 7.1 out of 10. It is an authentication flaw caused by faulty state management, allowing network attackers to log in without proper credentials. The circulation of public proof-of-concept code has lowered the barrier for exploitation.

Apple has since addressed the issue by releasing patches in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. However, users who have not updated their systems, especially those with Screen Sharing accessible online, remain at risk.

Monero is a preferred cryptocurrency for cryptojacking due to its privacy features, which make it difficult to trace the origin of mined coins. This campaign is part of a broader trend of malicious actors hijacking devices for cryptocurrency profits, with recent examples including malware in pirated books and fake CAPTCHA pages.

Frequently asked questions

The vulnerability is in the macOS Screen Sharing feature and allows network attackers to gain root access without valid credentials due to faulty state management during authentication.

Monero is a privacy-focused cryptocurrency designed to make transactions difficult to trace, making it a common choice for cryptojacking operations.

The vulnerability affects systems that have not been updated with the latest security patches for macOS Sequoia, Sonoma, and Tahoe.

Users should update their macOS to the latest version and ensure that Screen Sharing is not exposed to the public internet.

What Happens Next

01Users are advised to apply Apple's latest security updates promptly.
02Users should avoid leaving Screen Sharing accessible from the open internet.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

A vulnerability in macOS Screen Sharing is being exploited by hackers.
Attackers are gaining root access to affected systems.
Monero mining programs are being installed on compromised machines.
The flaw stems from faulty state management during authentication.
Proof-of-concept code for the flaw is circulating.
Apple has released patches for the vulnerability.
Users with Screen Sharing accessible from the internet remain exposed if unpatched.

Sources

T1
Hackers Are Abusing a macOS Screen Sharing Flaw to Secretly Mine MoneroDecrypt

Related Stories

Pirated 'The Odyssey' Copies Deliver Crypto-Stealing Malware
17 Aug · 12:36 PM
Trump-backed firm partners with AI venture using Chinese models
17 Aug · 10:06 AM
China State Broadcaster Warns of AI-Gamed Answers Misleading Investors
17 Aug · 1:06 AM
Wearables Race Beyond Fitness to Integrate With Healthcare Systems
17 Aug · 1:06 PM
ByteDance and Hollywood Trade Group Agree on AI Copyright Safeguards
17 Aug · 2:23 PM