By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

Coinpress

  • Home
  • Press Release
  • Bitcoin
  • Ethereum
  • Altcoin
  • Cryptocurrency
Reading: Hackers Exploit macOS Screen Sharing Flaw To Install Monero Miners
Share
Font ResizerAa

Coinpress

Font ResizerAa
  • Home
    • Home 1
    • Home 2
    • Home 3
    • Home 4
    • Home 5
  • Demos
  • Categories
  • Bookmarks
  • More Foxiz
    • Sitemap
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Coinpress > Blog > Cryptocurrency > Hackers Exploit macOS Screen Sharing Flaw To Install Monero Miners
Cryptocurrency

Hackers Exploit macOS Screen Sharing Flaw To Install Monero Miners

Admin
Last updated: August 18, 2026 5:30 am
Admin
2 days ago
Share
SHARE


Attackers are actively exploiting a high-severity authentication flaw in Apple’s macOS Screen Sharing service, gaining root access to internet-exposed Macs and installing Monero cryptocurrency miners.

The Netherlands’ National Cyber Security Centre has identified active exploitation on multiple systems with port 5900 exposed to the internet. Users running affected macOS versions should install Apple’s August security updates immediately and avoid exposing Screen Sharing directly to the public internet.

Attackers Bypass Screen Sharing Authentication

Tracked as CVE-2026-65400, the vulnerability affects the authentication process used by macOS Screen Sharing. Insufficient state management allowed a network attacker to authenticate without valid credentials, giving an unauthorized user access that should have been rejected.

The Dutch NCSC updated its advisory on August 12 after receiving reports of exploitation across multiple systems. Every affected Mac identified in those reports had port 5900 reachable from the internet, with attackers obtaining root access and deploying a Monero miner.

The agency also confirmed that public proof-of-concept code is available. CVE-2026-65400 carries a CVSS 3 score of 7.1, placing it in the high-severity category rather than the critical range.

Apple’s Screen Sharing configuration uses TCP port 5900 by default for standard connections, making publicly exposed systems a direct target when the vulnerable service is enabled.

Apple Patches Three macOS Versions

Apple patched the Screen Sharing authentication flaw on August 6 with macOS Tahoe 26.6.1. The same correction was released for macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.

The fix strengthens state management during authentication so that Screen Sharing accepts only valid credentials. Macs that do not require remote screen access should have Screen Sharing disabled, while administrators using the service should prevent port 5900 from being directly reachable from the public internet.

Systems that were previously exposed should also be checked for unauthorized access and unexpected processes, particularly cryptocurrency-mining software running with elevated privileges.

macOS Crypto Malware Threats Expand

The exploitation adds another macOS-focused threat to a growing series of attacks involving cryptocurrency infrastructure. A separate campaign uncovered in July used macOS malware to steal Telegram sessions, wallet databases and system credentials before replacing legitimate Ledger and Trezor applications with malicious versions.

Apple devices have also been targeted through software distributed inside official application stores. The SparkKitty malware campaign accessed users’ photo libraries in search of wallet recovery phrases and other sensitive information.

Apple released fixes for CVE-2026-65400 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 on August 6, while the Dutch NCSC continues to classify active exploitation of unpatched, internet-exposed systems as known.

WEMIX$ Contract Breach Mints 5.23M Tokens As Funds Move Across Chains
Base Flips Solana In 24-Hour DEX Volume As L2 Trading Heats Up
Bitcoin And Ether ETFs Draw $239M As July 14 Inflows Return
BlackRock’s Bitcoin ETF Adds $66M As BTC Holds Near $66K
Binance Captures 78% Of Exchange Inflows As Crypto Recovery Turns Trader-Led
Share This Article
Facebook Email Print
Previous Article BitBox Fixes Two Severe Hardware Wallet Vulnerabilities In Dixence Update
Next Article Nike Stock Hits Lowest Close Since 2014 After $223B Market Value Collapse
CoinPress.media is your premier digital hub for real-time cryptocurrency news, official press releases, and the latest market updates. We bridge the gap between complex blockchain data and actionable insights, keeping you ahead of the curve in the fast-moving world of Web3.

Find Us on Socials

© CoinPress.Media - All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?