INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Mac Screen Sharing Vulnerability Exploited in the Wild
| 2026-08-15 07:24 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The vulnerability, tracked as CVE-2026-65400, has been patched by Apple on August 6. This authentication-bypass flaw in macOS Screen Sharing can let an attacker on the network connect without valid credentials. The patch was issued for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. To update macOS, users are advised to use Software Update or upgrade to a newer version of the operating system. Prior to upgrading, it is recommended that users read instructions on how to mitigate exposure to this vulnerability. The Dutch National Cyber Security Centre has issued a warning after being notified of several incidents where a vulnerability in Apple's Screen Sharing feature was exploited to install Monero cryptominers. This highlights the importance of keeping software up-to-date and using security measures such as System Settings or Remote Management to protect against cyber threats.
Technical Mitigations AI-generated
* Enable Screen Sharing only on systems where port 5900 is internet-accessible, such as through a router port-forward or public IP assignment.
* Use the Software Update feature to install macOS Tahoe (26.6.1) and Sequoia (15.7.9), which have been patched for the vulnerability.
* Keep your Mac's Screen Sharing service disabled until you can update it using the Apple menu > System Settings > General > Sharing, then click on "Screen Sharing" and toggle it off if necessary.
* Use a reputable antivirus software like Malwarebytes Premium Security for Mac to protect against malware and cyber threats.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
by•••••.io
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-43777CVE-2026-43777
CVE-2026-65400CVE-2026-65400
CVE-2026-43760CVE-2026-43760
CVE-2026-43779CVE-2026-43779
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
BENELUX
BENELUX
Incident Timeline
2026/07/16
Threat actors exploited a vulnerability in the Screen Sharing Server component of macOS to install Monero miners on targeted internet-exposed Macs.
Click on any entity below to view its context and source!
infrastructure
Macos
Calif, which published
additional information
about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with
macOS Tahoe 26.6
shipped late last month -
CVE-2026-43779
(CVSS score: 9.8) - A logic issue that could allow an app to intercept network connections intended for another process
CVE-2026-43777
(CVSS score: 7.5) -
vulnerability
CVE-2026-43779
Calif, which published
additional information
about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with
macOS Tahoe 26.6
shipped late last month -
CVE-2026-43779
(CVSS score: 9.8) - A logic issue that could allow an app to intercept network connections intended for another process
CVE-2026-43777
(CVSS score: 7.5) -
vulnerability
CVE-2026-43777
Calif, which published
additional information
about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with
macOS Tahoe 26.6
shipped late last month -
CVE-2026-43779
(CVSS score: 9.8) - A logic issue that could allow an app to intercept network connections intended for another process
CVE-2026-43777
(CVSS score: 7.5) -
tactic
T1584.004 - Server
Calif, which published
additional information
about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with
macOS Tahoe 26.6
shipped late last month -
CVE-2026-43779
(CVSS score: 9.8) - A logic issue that could allow an app to intercept network connections intended for another process
CVE-2026-43777
(CVSS score: 7.5) -
general_metric
26.6 macOS Tahoe
Calif, which published
additional information
about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with
macOS Tahoe 26.6
shipped late last month -
CVE-2026-43779
(CVSS score: 9.8) - A logic issue that could allow an app to intercept network connections intended for another process
CVE-2026-43777
(CVSS score: 7.5) -
general_metric
9.8 score
Calif, which published
additional information
about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with
macOS Tahoe 26.6
shipped late last month -
CVE-2026-43779
(CVSS score: 9.8) - A logic issue that could allow an app to intercept network connections intended for another process
CVE-2026-43777
(CVSS score: 7.5) -
general_metric
7.5 score
Calif, which published
additional information
about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with
macOS Tahoe 26.6
shipped late last month -
CVE-2026-43779
(CVSS score: 9.8) - A logic issue that could allow an app to intercept network connections intended for another process
CVE-2026-43777
(CVSS score: 7.5) -
August 6, 2026
Threat actors exploited a post-authentication vulnerability in Apple's macOS to install Monero miners on targeted internet-exposed Macs.
Click on any entity below to view its context and source!
infrastructure
Macos
"A remote viewer can make macOS Screen Sharing read protected files as root.
"
"My last scan shown around 40k open screen sharing hosts on the internet, almost half in the U.S., most are residential IPs but there are many juicy hosts in Murican universities, some companies, a server from BBEdit company," @osxreverser
said
in a subsequent post on X. "Party hard, never expose those services unless behind SSH."
It's worth noting that CVE-2026-65400 is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws.
A username is not a secret, and macOS prints them on the login window.
infrastructure
26.6
"
"My last scan shown around 40k open screen sharing hosts on the internet, almost half in the U.S., most are residential IPs but there are many juicy hosts in Murican universities, some companies, a server from BBEdit company," @osxreverser
said
in a subsequent post on X. "Party hard, never expose those services unless behind SSH."
It's worth noting that CVE-2026-65400 is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws.
organisation
BBEdit
"
"My last scan shown around 40k open screen sharing hosts on the internet, almost half in the U.S., most are residential IPs but there are many juicy hosts in Murican universities, some companies, a server from BBEdit company," @osxreverser
said
in a subsequent post on X. "Party hard, never expose those services unless behind SSH."
It's worth noting that CVE-2026-65400 is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws.
organisation
X. "Party
"
"My last scan shown around 40k open screen sharing hosts on the internet, almost half in the U.S., most are residential IPs but there are many juicy hosts in Murican universities, some companies, a server from BBEdit company," @osxreverser
said
in a subsequent post on X. "Party hard, never expose those services unless behind SSH."
It's worth noting that CVE-2026-65400 is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws.
organisation
SSH
"
"My last scan shown around 40k open screen sharing hosts on the internet, almost half in the U.S., most are residential IPs but there are many juicy hosts in Murican universities, some companies, a server from BBEdit company," @osxreverser
said
in a subsequent post on X. "Party hard, never expose those services unless behind SSH."
It's worth noting that CVE-2026-65400 is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws.
organisation
Content & Media
If immediate patching of the flaw is not possible, it's advised to turn off Screen Sharing by navigating to General > Sharing > Toggle Screen Sharing from "Content & Media."
infrastructure
8.6
An unspecified issue that could a remote attacker to cause a denial-of-service (DoS)
CVE-2026-43760
(CVSS score: 8.6) - An access issue that could allow an app to access user-sensitive data
In a technical breakdown published following the release of the patches, Pesoli described CVE-2026-43760 as a post authentication bug that requires the target Mac to have Screen Sharing or Remote Management enabled with "VNC viewers may control screen with password" configured and the attacker is already in possession of that VNC password.
organisation
DoS
An unspecified issue that could a remote attacker to cause a denial-of-service (DoS)
CVE-2026-43760
(CVSS score: 8.6) - An access issue that could allow an app to access user-sensitive data
In a technical breakdown published following the release of the patches, Pesoli described CVE-2026-43760 as a post authentication bug that requires the target Mac to have Screen Sharing or Remote Management enabled with "VNC viewers may control screen with password" configured and the attacker is already in possession of that VNC password.
organisation
Remote Management
An unspecified issue that could a remote attacker to cause a denial-of-service (DoS)
CVE-2026-43760
(CVSS score: 8.6) - An access issue that could allow an app to access user-sensitive data
In a technical breakdown published following the release of the patches, Pesoli described CVE-2026-43760 as a post authentication bug that requires the target Mac to have Screen Sharing or Remote Management enabled with "VNC viewers may control screen with password" configured and the attacker is already in possession of that VNC password.
organisation
VNC
An unspecified issue that could a remote attacker to cause a denial-of-service (DoS)
CVE-2026-43760
(CVSS score: 8.6) - An access issue that could allow an app to access user-sensitive data
In a technical breakdown published following the release of the patches, Pesoli described CVE-2026-43760 as a post authentication bug that requires the target Mac to have Screen Sharing or Remote Management enabled with "VNC viewers may control screen with password" configured and the attacker is already in possession of that VNC password.
organisation
LPE
We used that second primitive to install a valid sudoers policy and turn a file-copy operation into a remote root command execution (or an LPE).
organisation
IP
The only prerequisite is knowing the IP address.
organisation
@osxreverser
What's interesting here is that both of them reside in the same source code file, per Calif -
@osxreverser's bug is a single wrong return.
organisation
Mac
Send one or two packets in the right order, and the target Mac machine lets you in.
organisation
Screen Sharing
It works the first time, and it works every time, on every unpatched machine with Screen Sharing enabled.
August 6
Threat actors exploited a vulnerability in Apple's macOS to target and install Monero miners on internet-exposed Macs.
Click on any entity below to view its context and source!
organisation
Apple
The vulnerability, tracked as
CVE-2026-65400
, was patched by Apple on August 6.
Apple
fixed CVE-2026-65400
on August 6 in macOS Tahoe 26.6.1 and earlier releases.
vulnerability
CVE-2026-65400
The vulnerability, tracked as
CVE-2026-65400
, was patched by Apple on August 6.
Apple
fixed CVE-2026-65400
on August 6 in macOS Tahoe 26.6.1 and earlier releases.
infrastructure
Macos
Apple
fixed CVE-2026-65400
on August 6 in macOS Tahoe 26.6.1 and earlier releases.
infrastructure
26.6.1
Apple
fixed CVE-2026-65400
on August 6 in macOS Tahoe 26.6.1 and earlier releases.
organisation
CVE-2026
Apple
fixed CVE-2026-65400
on August 6 in macOS Tahoe 26.6.1 and earlier releases.
2026/08/15
Hackers exploited a macOS Screen Sharing flaw to gain root access and install Monero miners on vulnerable Macs with port 5900 exposed online.
Click on any entity below to view its context and source!
infrastructure
Macos
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has
warned
.
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner.
The shortcoming was addressed as part of an emergency update in
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
earlier this month.
It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials.
macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900.
The patch was issued for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
To update macOS on any supported Mac, use the Software Update feature, which Apple designed to work consistently across all recent versions.
On older macOS, just look for
Software Update
directly.
Before you upgrade to macOS Tahoe 26, please read these
instructions
.
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners.
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online.
The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as
CVE-2026-65400
(CVSS score of 9.8), less than two weeks after Apple shipped the fix.
The bug sits in macOS’s built-in Screen Sharing feature, the remote desktop tool baked into every Mac.
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
This flaw sits in the same source code file as two other Screen Sharing bugs Apple patched a month earlier in macOS 26.6, one of them a genuinely pre-authentication flaw that a researcher going by @osxreverser
described
needing nothing but a target’s IP address to exploit, no password, no username, nothing.
The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner.
The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900.
“In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.”
macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:
macOS Tahoe 26.6.1
macOS Sequoia 15.7.9
macOS Sonoma 14.8.9
These releases improve state management mechanisms to enforce correct credential validation and prevent rogue authentication attempts.
organisation
the Netherlands National Cyber Security Centre
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has
warned
.
organisation
NCSC-NL
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has
warned
.
NCSC-NL says it received reports of active abuse hitting multiple systems where port 5900, the port Screen Sharing runs on, was reachable directly from the internet.
organisation
Apple
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner.
The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as
CVE-2026-65400
(CVSS score of 9.8), less than two weeks after Apple shipped the fix.
infrastructure
26.6.1
The shortcoming was addressed as part of an emergency update in
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
earlier this month.
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
“In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.”
macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:
macOS Tahoe 26.6.1
macOS Sequoia 15.7.9
macOS Sonoma 14.8.9
These releases improve state management mechanisms to enforce correct credential validation and prevent rogue authentication attempts.
infrastructure
15.7.9
The shortcoming was addressed as part of an emergency update in
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
earlier this month.
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
“In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.”
macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:
macOS Tahoe 26.6.1
macOS Sequoia 15.7.9
macOS Sonoma 14.8.9
These releases improve state management mechanisms to enforce correct credential validation and prevent rogue authentication attempts.
infrastructure
14.8.9
The shortcoming was addressed as part of an emergency update in
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
earlier this month.
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
“In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.”
macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:
macOS Tahoe 26.6.1
macOS Sequoia 15.7.9
macOS Sonoma 14.8.9
These releases improve state management mechanisms to enforce correct credential validation and prevent rogue authentication attempts.
organisation
Screen Sharing
macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900.
The bug sits in macOS’s built-in Screen Sharing feature, the remote desktop tool baked into every Mac.
Where system updates are not immediately possible, users can use System Settings to disable Screen Sharing (General → Sharing → Screen Sharing) if not needed.
organisation
Macs
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online.
organisation
The Dutch National Cyber Security Centre
The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as
CVE-2026-65400
(CVSS score of 9.8), less than two weeks after Apple shipped the fix.
The Dutch National Cyber Security Centre (NCSC) issued a
warning
after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install
Monero cryptominers
.
organisation
Mac
The bug sits in macOS’s built-in Screen Sharing feature, the remote desktop tool baked into every Mac.
An attacker could view and control the Mac remotely because that is the function Screen Sharing provides.
organisation
Bynario Atlas
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
organisation
IP
This flaw sits in the same source code file as two other Screen Sharing bugs Apple patched a month earlier in macOS 26.6, one of them a genuinely pre-authentication flaw that a researcher going by @osxreverser
described
needing nothing but a target’s IP address to exploit, no password, no username, nothing.
Practical exposure requires Screen Sharing to be enabled, so the highest-risk systems are those where port 5900 is internet-accessible, typically through a router port-forward, public IP assignment, or hosting-provider setup.
organisation
NCSC
The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
The Dutch National Cyber Security Centre (NCSC) issued a
warning
after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install
Monero cryptominers
.
“The NCSC has received a
security advisory
indicating that active exploitation of this vulnerability has been observed on multiple systems where port 5900 was accessible from the internet.
organisation
VNC
The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900.
organisation
TCP
The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900.
organisation
Remote Management
Also check
Remote Management
on that same Sharing page.
organisation
Select
Select
General
in the sidebar, then click
Software Update
on the right.
organisation
Apple’s Screen Sharing
The Dutch National Cyber Security Centre (NCSC) issued a
warning
after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install
Monero cryptominers
.
organisation
CPU
The criminals likely chose Monero mining because it does not depend on heavily specialized, application-specific integrated circuits (ASICs), but can be done with any CPU or GPU.
organisation
GPU
The criminals likely chose Monero mining because it does not depend on heavily specialized, application-specific integrated circuits (ASICs), but can be done with any CPU or GPU.
organisation
Cryptomining
Cryptomining isn’t necessarily the worst an attacker could do.
organisation
System Preferences
Choose
System Settings
(or
System Preferences
on older versions).
organisation
Update Now
If updates are available, click
Update Now
(or
Upgrade Now
for major new versions) and follow the on-screen instructions.
organisation
Select
System Settings
Select
System Settings
.
organisation
Malwarebytes Premium Security for Mac
Macs need protection too
Malwarebytes Premium Security for Mac
stops threats and protects your Mac and personal files from hackers and cybercriminals.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Monero)
organisation
NSCS
NSCS has not shared any details about the reported attacks, when they started, if they extend beyond cryptocurrency mining, or how many systems have been impacted.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Tactical Metrics
Metrics
infrastructure
Macos
Affected Product
Click for context!
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has
warned
.
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner.
The shortcoming was addressed as part of an emergency update in
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
earlier this month.
…about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with
macOS Tahoe 26.6
shipped late last month -
CVE-2026-43779
(CVSS score: 9.8) - A logic issue that could allow an app t…
"A remote viewer can make macOS Screen Sharing read protected files as root.
…ose services unless behind SSH."
It's worth noting that CVE-2026-65400 is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws.
A username is not a secret, and macOS prints them on the login window.
It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials.
macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900.
The patch was issued for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
To update macOS on any supported Mac, use the Software Update feature, which Apple designed to work consistently across all recent versions.
On older macOS, just look for
Software Update
directly.
Before you upgrade to macOS Tahoe 26, please read these
instructions
.
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners.
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online.
The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as
CVE-2026-65400
(CVSS score of 9.8), less than two weeks after Apple shipped the fix.
The bug sits in macOS’s built-in Screen Sharing feature, the remote desktop tool baked into every Mac.
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
This flaw sits in the same source code file as two other Screen Sharing bugs Apple patched a month earlier in macOS 26.6, one of them a genuinely pre-authentication flaw that a researcher going by @osxreverser
described
needing nothing but a targ…
The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner.
The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900.
Apple
fixed CVE-2026-65400
on August 6 in macOS Tahoe 26.6.1 and earlier releases.
“In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.”
macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:
macOS Tahoe 26.6…
Metrics
infrastructure
26.6.1
Software Version
The shortcoming was addressed as part of an emergency update in
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
earlier this month.
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
Apple
fixed CVE-2026-65400
on August 6 in macOS Tahoe 26.6.1 and earlier releases.
…users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:
macOS Tahoe 26.6.1
macOS Sequoia 15.7.9
macOS Sonoma 14.8.9
These releases improve state management mechanisms to enforce correct…
Metrics
infrastructure
15.7.9
Software Version
The shortcoming was addressed as part of an emergency update in
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
earlier this month.
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
…o upgrade their system to one of the following releases, which address CVE-2026-65400:
macOS Tahoe 26.6.1
macOS Sequoia 15.7.9
macOS Sonoma 14.8.9
These releases improve state management mechanisms to enforce correct credential validation a…
Metrics
infrastructure
14.8.9
Software Version
The shortcoming was addressed as part of an emergency update in
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
earlier this month.
Apple patched this issue with the release of
macOS Tahoe 26.6.1
,
macOS Sequoia 15.7.9
, and
macOS Sonoma 14.8.9
, crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery.
…to one of the following releases, which address CVE-2026-65400:
macOS Tahoe 26.6.1
macOS Sequoia 15.7.9
macOS Sonoma 14.8.9
These releases improve state management mechanisms to enforce correct credential validation and prevent rogue authe…
Metrics
infrastructure
8.6
Software Version
An unspecified issue that could a remote attacker to cause a denial-of-service (DoS)
CVE-2026-43760
(CVSS score: 8.6) - An access issue that could allow an app to access user-sensitive data
In a technical breakdown published following the re…
Metrics
infrastructure
26.6
Software Version
…ose services unless behind SSH."
It's worth noting that CVE-2026-65400 is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws.
Intelligence Sources
BleepingComputer
2026-08-14
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
BleepingComputer
Security Affairs
2026-08-15
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Security Affairs
Malware Bytes
2026-08-17
The Hacker News
2026-08-15
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-18T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
33x
organisation
Identified Entity
the Netherlands National Cyber Security Centre
entity
5x
infrastructure
Software Version
26.6.1
version
4x
timeline
Temporal Reference
August 6, 2026
date
4x
vulnerability
Exploited CVE
CVE-2026-65400
cve
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
general metric
Macos Tahoe
27
macos tahoe
2x
general metric
Score
10
score
2x
target region
Target Country
United States
country
Contextual Telemetry
Context Block
10 METRICS
source region
Origin Country
Netherlands
country
infrastructure
Affected Product
Macos
software
industry
Targeted Sector
Media
sector
general metric
Unspecified Issue
9
unspecified issue
attribution
Attributing Entity
CVE-2026
authority
tactic
Cyber Operation Type
Lateral Movement
tactic
general metric
Researcher
40,000
researcher
vulnerability
CVSS Score
10
score
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.