AI News Feed
Market watch
Cybersecurity

MacOS Screen Sharing Flaw Exploited in Cryptojacking Attacks Within Days of Disclosure

A critical macOS Screen Sharing vulnerability, CVE-2026-65400, is being actively exploited in cryptojacking attacks, with Dutch authorities reporting Monero miners planted via exposed port 5900.

Apple released an out-of-band fix soon after disclosure, which security researchers described as a sign of the vulnerability’s critical nature. The patch was included in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1. The flaw was also showcased at the 2026 Black Hat conference, with a video demonstration made public a few days later.

Dutch security officials were the first to report active exploitation. The Netherlands National Cyber Security Centrum (NCSC) said in a report that active abuse had been observed on several systems where port 5900 was accessible from the internet. In those cases, attackers gained root access and placed a Monero crypto miner. Monero is a privacy-focused cryptocurrency using a proof-of-work algorithm optimized for general-purpose CPUs, making it attractive for cryptojacking. While the specific miner was not named, XMRig is the most commonly used tool for mining Monero.

The best protection is installing Apple’s patch immediately. Users unable to do so should disable Screen Sharing in System Settings > General > Sharing, or block port 5900 on routers and firewalls. The NCSC emphasized that exploitation only occurs when port 5900 is exposed to the internet. No group has claimed responsibility, and there is no evidence the flaw has been used for other purposes, though it could theoretically be used for data exfiltration, malware deployment, or ransomware attacks.