
The Netherlands National Cyber Security Centrum issued a warning earlier this week regarding active exploitation of a macOS vulnerability affecting multiple systems. The agency noted that attackers gained root-level access on compromised machines and deployed Monero cryptocurrency miners on systems where port 5900 was accessible from the Internet.
The vulnerability, designated CVE-2026-65400 and rated 7.1 out of 10 in severity, affects the macOS screen sharing functionality. The flaw involves a state management bug that enables remote attackers to view screens and control keyboards and mice on targeted machines. Apple released patches for the vulnerability last week covering macOS Tahoe, Sequoia, and Sonoma versions. Security firm Bynario was credited with discovering and reporting the flaw, with technical details presented at last week’s Black Hat security conference.
The exploitation occurs when port 5900, which is opened by the macOS firewall when screen sharing is enabled, is exposed to internet access. Most routers and firewalls typically block this port by default unless explicitly configured otherwise. Security experts recommend disabling screen sharing when not actively in use, enabling it only when necessary, and employing alternative connection methods such as VPN or SSH tunneling to mitigate risk.
Current observed exploits have focused on deploying Monero miners that hijack system resources for cryptocurrency generation. However, security analysts warn of broader potential risks, including the possible installation of credential-stealing malware or other malicious payloads. Users are advised to install the latest security updates from Apple and to adjust screen sharing settings through System Settings to minimize exposure to the vulnerability.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI