Mac vulnerability under active exploitation installs crypto miners
Attackers are actively exploiting a high-severity macOS vulnerability that lets them execute malicious code, the Netherlands National Cyber Security Centrum (NCSC) warned. The flaw, tracked as CVE-2026-65400, was patched by Apple on August 7, 2026 for macOS Tahoe, Sequoia, and Sonoma; unpatched systems remain at risk.
The NCSC said it observed the attacks on multiple systems where port 5900 was accessible from the internet. In every observed case, attackers gained root access and installed a Monero crypto miner, which harnesses the Mac's resources to generate cryptocurrency.
Rated 7.1 out of 10, the vulnerability stems from a state management bug in macOS screen sharing, a feature that lets a remote party view and control the machine. Apple said the flaw "may" allow an attacker without credentials to gain access to a Mac.
Details of the vulnerability became public at the Black Hat security conference in early August 2026. Security practitioners advise keeping port 5900 closed; the macOS firewall opens it when screen sharing is enabled, and routers generally block it unless configured otherwise. They recommend using a VPN or SSH tunnel instead, though these options are beyond the capabilities of most users.
The safest practice is to disable screen sharing when it is not needed and enable it only for active sessions. Users can toggle screen sharing in System Settings > General > Sharing. Installing Apple's security update is essential. As of August 14, 2026, there were no indications the exploits had installed anything other than Monero miners, but attackers could use the flaw to deploy credential-stealing malware or other harmful code.
Sources
- Ars TechnicaSecondary
Related
Iranian hackers hit U.S. water utilities in 12 states
Data breaches hit 471M victims in first half of 2026
Apple alerts users in 110 countries to spyware attacks
Meta adds AI scam detection to WhatsApp
US allows private firms to launch cyberattacks in first
LiteLLM supply-chain attack leaks credentials of 2,500+ orgs
Uber Freight probes data breach claim by Helix hackers
Researcher defies Microsoft, releases Windows zero-day ShieldBreak
Trending now
- Iranian hackers hit U.S. water utilities in 12 states
- Google lets users remove AI watermarks
- Europe launch costs triple US as SpaceX dominates
- Lamborghini unveils Revuelto SV, its most powerful production car ever
- Jeff Bezos group buys minority stake in Liverpool FC for $7.1B
- NASA AI predicts solar active regions 12 hours early
- OpenAI exec exodus raises 'huge red flag' ahead of IPO
- Liverpool owners sell 30% stake for £1.65bn to Bezos consortium
Comments
No comments yet. Be the first.