Threat Intelligence

Critical macOS Screen Sharing Bug Actively Exploited to Install Crypto Miners

The Hacker News · 15 Aug 2026
Key Takeaway Update all Macs to the latest macOS version immediately and disable Screen Sharing or restrict it from internet access unless absolutely necessary.

The Netherlands National Cyber Security Centre (NCSC) has issued a warning that a recently patched macOS vulnerability is being actively exploited in real-world attacks. Tracked as CVE-2026-65400 and rated 9.8 out of 10 in severity, the flaw affects the Screen Sharing component of macOS and allows an attacker already on the same network to bypass authentication controls.

Attackers are reportedly using this vulnerability to gain unauthorised access to Macs that have Screen Sharing exposed to the internet, then installing a Monero cryptocurrency miner. While cryptomining malware may seem less dangerous than ransomware or data theft, its presence indicates a broader security failure: any attacker able to install mining software could just as easily install more damaging tools, steal data, or move deeper into a business network.

Apple has already released a patch for this vulnerability, meaning businesses using Macs are protected simply by keeping their systems up to date. However, any organisation that has delayed applying recent macOS updates, or that has Screen Sharing enabled and accessible from the internet, remains at risk. Small businesses using Macs for daily operations should treat this as a reminder that remote access features, if left exposed, are a common target for opportunistic attackers.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.