Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. [...]
Source: BleepingComputer · August 14, 2026 at 5:55 PM · AI-assisted report
KUALA LUMPUR, 15 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
Hackers Target macOS Users via Screen Sharing Flaw to Install Monero Miner
Market Impact
KUALA LUMPUR, Aug 14 — Hackers are exploiting a macOS authentication bypass vulnerability to gain unauthorized access and deploy cryptocurrency mining malware, the Netherlands’ National Cyber Security Centre (NCSC) has warned.
The flaw, tracked as CVE-2026-65400, resides in macOS Screen Sharing, a built-in remote desktop feature that operates over the VNC protocol on TCP port 5900. Apple addressed the issue in macOS Tahoe 26.6.1, released on August 6, by improving state management to enforce proper credential validation. However, the NCSC confirmed that exploit code has since been made public, enabling active attacks.
According to the Dutch agency, threat actors are leveraging the vulnerability to gain root access on exposed systems, where port 5900 is accessible from the internet. In observed incidents, attackers deployed a Monero cryptocurrency miner after compromising the machines. The NCSC stated that multiple systems have been affected, though it did not disclose the number of incidents, their timeline, or whether additional malicious activities occurred beyond cryptocurrency mining.
The flaw allows network-based attackers to bypass authentication requirements entirely, granting them the ability to remotely open applications, access files, modify security settings, and execute arbitrary commands. While Apple’s patch mitigates the risk, users who cannot immediately update their systems are advised to disable Screen Sharing via System Settings (General → Sharing → Screen Sharing).
The NCSC has not provided further technical details on the attacks, including how the exploit is being propagated or whether the campaign has broader objectives. Security experts note that once attackers gain valid credentials or elevated access, traditional prevention measures often become less effective, as seen in broader industry assessments of defense efficacy.
For the Malaysian market, the incident underscores the importance of timely software updates and network security configurations, particularly for users and enterprises relying on macOS systems. While no direct impact on local businesses has been reported, the widespread use of macOS in creative and enterprise sectors could make local users potential targets if similar vulnerabilities are exploited in the region.
In the technology sector, companies providing managed IT services or cybersecurity solutions in Malaysia may see increased demand for vulnerability assessments and endpoint protection services. The incident also highlights the growing trend of cryptojacking attacks, where threat actors abuse computing resources for illicit mining activities.
Looking ahead, security teams are expected to prioritize patch management and network segmentation to mitigate risks associated with exposed remote access services. The NCSC’s advisory serves as a reminder for organizations to review their exposure of port 5900 and other commonly targeted services to prevent unauthorized access.
Related: Apple