bleeping-computer · Crawled Aug 14, 2026
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
1 Malware
Read original article ↗
AI Summary
The Netherlands' National Cyber Security Centre (NCSC) has issued a warning that attackers are actively exploiting a macOS Screen Sharing vulnerability, CVE-2026-65400, to gain unauthorized access to systems with exposed port 5900. The flaw allows network-based attackers to bypass authentication and obtain root access without valid credentials. In confirmed attacks, the threat actors have deployed Monero cryptocurrency miners on compromised systems. Apple has patched the vulnerability in recent macOS updates, including Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
AI-extracted · verify before operational use
Extracted Entities 1 found
MITRE ATT&CK TTPs 7 techniques
T1021.003 Distributed Component Object Model · Lateral Movement T1059 Command and Scripting Interpreter · Execution T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1210 Exploitation of Remote Services · Lateral Movement T1484.001 Group Policy Modification · Defense Evasion T1496 Resource Hijacking · Impact