
Monero miner spotted via macOS Screen Sharing authentication flaw
The Netherlands’ NCSC warns attackers are exploiting a macOS Screen Sharing authentication bypass (CVE-2026-65400) to gain root access, with exploits observed on systems exposing port 5900 to the Internet. Once in, attackers can run apps, access files, and deploy a Monero cryptocurrency miner. Apple patched the vulnerability in macOS Tahoe 26.6.1 and newer releases (also Sequoia 15.7.9 and Sonoma 14.8.9). Users should update to the patched releases or disable Screen Sharing if not needed, as details on scope and impact remain limited.
