Key Points
- Cybercriminals leveraged a macOS Screen Sharing security weakness to obtain administrative privileges and deploy Monero cryptocurrency mining applications on vulnerable Macs
- The Netherlands’ National Cyber Security Centre verified ongoing attacks targeting systems with TCP port 5900 accessible from the public internet
- Apple released security fixes on August 6 across macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9
- CISA elevated the threat severity rating to 9.8 critical from an initial assessment of 7.1
- Traditional mitigation strategies like password resets for Screen Sharing prove ineffective; only Apple’s official patch resolves the security gap
Cybercriminals successfully weaponized a security weakness in Apple’s macOS Screen Sharing functionality to commandeer internet-connected Mac computers and deploy them as cryptocurrency mining nodes for Monero. Dutch cybersecurity authorities published confirmation of these intrusions in a refreshed security bulletin issued on August 12.
Security investigators discovered that in all documented incidents, threat actors successfully escalated their access to root-level privileges before deploying Monero mining applications on the breached systems. The Dutch government cybersecurity division has not disclosed the total count of affected devices or identified potential threat actors.
Apple addressed the security vulnerability, designated as CVE-2026-65400, through patches released on August 6. The security remediation was distributed across macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 releases.
The security defect stems from flawed state management within the Secure Remote Password authentication mechanism utilized by macOS Screen Sharing. Cybersecurity researchers at Huntress discovered that malicious actors could manipulate the system into misidentifying an unauthenticated session as properly authenticated, thereby granting complete elevated access.
Since the attack vector executes prior to standard authentication procedures, conventional security measures prove ineffective. Modifying Screen Sharing credentials, disabling VNC authentication methods, or removing user profiles cannot prevent unauthorized access through this exploit.
Massive Attack Surface Discovered
Security analyst Ryan Dowd from Huntress conducted internet-wide scanning using Censys and identified tens of thousands of systems potentially susceptible to exploitation. This figure represents internet-exposed Mac computers rather than confirmed breach victims.
The exposure risk proves particularly acute for cloud-hosted bare-metal Mac infrastructure, including Mac mini units available through hosting service providers. Certain hosting platforms automatically activate Screen Sharing on freshly provisioned machines, creating immediate vulnerability windows when Apple’s August 6 security updates remain unapplied.
The United States Cybersecurity and Infrastructure Security Agency assigned an initial severity rating of 7.1 when Apple distributed the remediation. CISA subsequently escalated the assessment to 9.8 critical on August 14, acknowledging that exploitation requires neither elevated privileges nor user interaction.
Monero’s Appeal to Cryptojackers
Monero continues to feature prominently in unauthorized cryptocurrency mining operations. The digital currency supports mining through standard computing processors, contrasting with Bitcoin mining which demands purpose-built hardware. Monero’s built-in privacy features additionally complicate blockchain forensics and transaction tracing.
Individual machine profitability remains modest. The global Monero network generates approximately 432 XMR daily, representing roughly $179,000 in value distributed across the entire mining ecosystem.
Monero exchanged between approximately $414 and $415 during the reporting period, reflecting gains of roughly 1% to 3.7% across 24 hours and approximately 5% over seven days.
While the Dutch NCSC verified the exploitation campaigns, they have not released technical details regarding the mining infrastructure, pool destinations, or cryptocurrency wallet addresses associated with the attacks. Additional forensic analysis from security organizations may illuminate the campaign’s scope prior to Apple’s patch deployment.
Mac users who have enabled Screen Sharing should apply Apple’s most recent security updates without delay.





