Key Points
- Cybercriminals leveraged a critical macOS Screen Sharing vulnerability to obtain root-level access and deploy Monero mining malware on exposed Mac systems
- The Netherlands’ National Cyber Security Centre verified active attacks targeting systems with TCP port 5900 publicly accessible
- Security patches were released by Apple on August 6 across macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9
- The U.S. Cybersecurity and Infrastructure Security Agency elevated the severity rating to 9.8 critical from an initial 7.1 assessment
- Traditional security measures like password resets for Screen Sharing are ineffective; only Apple’s security patch resolves the vulnerability
Cybercriminals successfully weaponized a security weakness in Apple’s macOS Screen Sharing functionality to commandeer internet-connected Mac computers and deploy them for Monero cryptocurrency mining. The Netherlands’ National Cyber Security Centre validated these intrusions in a security bulletin updated on August 12.
In all documented incidents, threat actors successfully achieved root-level system privileges and deployed Monero mining applications on the targeted devices. The Dutch cybersecurity authority has not disclosed the total number of affected systems or identified potential perpetrators.
Apple addressed the security vulnerability, designated as CVE-2026-65400, through security updates shipped on August 6. The remediation was incorporated into macOS versions Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
The security weakness stems from inadequate state management within the Secure Remote Password authentication mechanism employed by macOS Screen Sharing. Cybersecurity firm Huntress discovered that malicious actors could manipulate the system into recognizing an unauthorized connection as authenticated, thereby granting complete elevated access.
Since the exploitation occurs prior to conventional authentication procedures, typical security controls prove ineffective. Modifying Screen Sharing credentials, disabling VNC authentication protocols, or deleting user profiles will not prevent unauthorized access.
Thousands of Mac Systems at Risk
Security analyst Ryan Dowd from Huntress conducted a Censys database query that identified tens of thousands of potentially susceptible systems. This figure represents internet-exposed Mac machines, not verified breaches.
The exposure is particularly acute for cloud-hosted bare-metal Mac infrastructure, such as Mac mini units available from hosting providers. Certain hosting configurations automatically activate Screen Sharing on freshly provisioned machines, creating vulnerability windows if Apple’s August 6 security updates remain unapplied.
The U.S. Cybersecurity and Infrastructure Security Agency originally assigned a severity score of 7.1 when Apple distributed the security fix. CISA subsequently revised the rating upward to 9.8 critical on August 14, acknowledging that exploitation requires neither elevated privileges nor user interaction.
The Appeal of Monero for Cryptojacking
Monero has consistently appeared in cryptojacking operations. The cryptocurrency supports mining with standard computing processors, contrasting with Bitcoin which demands purpose-built mining equipment. Its privacy-focused transaction architecture additionally complicates tracing efforts.
The economic return per compromised system remains modest. The global Monero network generates approximately 432 XMR daily, translating to roughly $179,000 distributed across all network miners.
Monero was trading between $414 and $415 during reporting, showing gains of approximately 1% to 3.7% in 24-hour trading and roughly 5% weekly appreciation.
While the Dutch NCSC verified the exploitation campaign, it has not released specifics regarding the mining operations, mining pool identifiers, or attacker cryptocurrency wallets. Additional analysis from cybersecurity researchers may illuminate the attack campaign’s scope before Apple’s security patch became available.
Any user operating a Mac system with Screen Sharing functionality activated should apply Apple’s most recent security updates without delay.


