Tag

Cve 2026 65400

All articles tagged with #cve 2026 65400

Monero miner spotted via macOS Screen Sharing authentication flaw
technology10 days ago

Monero miner spotted via macOS Screen Sharing authentication flaw

The Netherlands’ NCSC warns attackers are exploiting a macOS Screen Sharing authentication bypass (CVE-2026-65400) to gain root access, with exploits observed on systems exposing port 5900 to the Internet. Once in, attackers can run apps, access files, and deploy a Monero cryptocurrency miner. Apple patched the vulnerability in macOS Tahoe 26.6.1 and newer releases (also Sequoia 15.7.9 and Sonoma 14.8.9). Users should update to the patched releases or disable Screen Sharing if not needed, as details on scope and impact remain limited.

Active macOS Screen Sharing Flaw Lets Attackers Gain Root Access
technology10 days ago

Active macOS Screen Sharing Flaw Lets Attackers Gain Root Access

A high-severity macOS flaw (CVE-2026-65400) in the screen-sharing feature is under active exploitation, allowing remote attackers to gain root access when port 5900 is exposed to the Internet. Affected systems can be controlled remotely, with attackers potentially installing malware or stealing data. Apple has patched the vulnerability for macOS Tahoe, Sequoia, and Sonoma. For now, reports indicate attackers are using the flaw to deploy Monero miners; best defenses include turning off screen sharing when not in use, blocking port 5900, and applying the latest updates or connecting via VPN/SSH when needed.