INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Mac Screen Sharing Vulnerability Exploited in the Wild

| 2026-08-15 07:24 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The vulnerability, tracked as CVE-2026-65400, has been patched by Apple on August 6. This authentication-bypass flaw in macOS Screen Sharing can let an attacker on the network connect without valid credentials. The patch was issued for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. To update macOS, users are advised to use Software Update or upgrade to a newer version of the operating system. Prior to upgrading, it is recommended that users read instructions on how to mitigate exposure to this vulnerability. The Dutch National Cyber Security Centre has issued a warning after being notified of several incidents where a vulnerability in Apple's Screen Sharing feature was exploited to install Monero cryptominers. This highlights the importance of keeping software up-to-date and using security measures such as System Settings or Remote Management to protect against cyber threats.
Technical Mitigations AI-generated
* Enable Screen Sharing only on systems where port 5900 is internet-accessible, such as through a router port-forward or public IP assignment. * Use the Software Update feature to install macOS Tahoe (26.6.1) and Sequoia (15.7.9), which have been patched for the vulnerability. * Keep your Mac's Screen Sharing service disabled until you can update it using the Apple menu > System Settings > General > Sharing, then click on "Screen Sharing" and toggle it off if necessary. * Use a reputable antivirus software like Malwarebytes Premium Security for Mac to protect against malware and cyber threats.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

by•••••.io
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-43777CVE-2026-43777 CVE-2026-65400CVE-2026-65400 CVE-2026-43760CVE-2026-43760 CVE-2026-43779CVE-2026-43779
Target & Sectors
NORTH_AMERICA NORTH_AMERICA BENELUX BENELUX
Incident Timeline
‎2026/07/16
Threat actors exploited a vulnerability in the Screen Sharing Server component of macOS to install Monero miners on targeted internet-exposed Macs.
infrastructure Macos
vulnerability CVE-2026-43779
vulnerability CVE-2026-43777
tactic T1584.004 - Server
general_metric 26.6 macOS Tahoe
general_metric 9.8 score
general_metric 7.5 score
‎August 6, 2026
Threat actors exploited a post-authentication vulnerability in Apple's macOS to install Monero miners on targeted internet-exposed Macs.
infrastructure Macos
infrastructure 26.6
organisation BBEdit
organisation X. "Party
organisation SSH
organisation Content & Media
infrastructure 8.6
organisation DoS
organisation Remote Management
organisation VNC
organisation LPE
organisation IP
organisation @osxreverser
organisation Mac
organisation Screen Sharing
‎August 6
Threat actors exploited a vulnerability in Apple's macOS to target and install Monero miners on internet-exposed Macs.
organisation Apple
vulnerability CVE-2026-65400
infrastructure Macos
infrastructure 26.6.1
organisation CVE-2026
‎2026/08/15
Hackers exploited a macOS Screen Sharing flaw to gain root access and install Monero miners on vulnerable Macs with port 5900 exposed online.
infrastructure Macos
organisation the Netherlands National Cyber Security Centre
organisation NCSC-NL
organisation Apple
infrastructure 26.6.1
infrastructure 15.7.9
infrastructure 14.8.9
organisation Screen Sharing
organisation Macs
organisation The Dutch National Cyber Security Centre
organisation Mac
organisation Bynario Atlas
organisation IP
organisation NCSC
organisation VNC
organisation TCP
organisation Remote Management
organisation Select
organisation Apple’s Screen Sharing
organisation CPU
organisation GPU
organisation Cryptomining
organisation System Preferences
organisation Update Now
organisation Select System Settings
organisation Malwarebytes Premium Security for Mac
organisation SecurityAffairs
organisation NSCS
organisation The Blue Report 2026
Tactical Metrics
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎26.6.1
Software Version
Metrics
infrastructure
‎15.7.9
Software Version
Metrics
infrastructure
‎14.8.9
Software Version
Metrics
infrastructure
‎8.6
Software Version
Metrics
infrastructure
‎26.6
Software Version