Headline: macOS Screen Sharing Flaw Exploited to Deploy Monero Miners — NCSC Warns Users to Patch Now The Netherlands’ National Cyber Security Center (NCSC) has sounded the alarm: attackers are actively exploiting a vulnerability in Apple’s macOS Screen Sharing (VNC) service to take over Macs and install Monero miners. What happened - The flaw (CVE-2026-65400, CVSS 7.1) is an authentication bug caused by faulty state management during the login process. In practice it allowed network-based attackers to bypass authentication and gain root access — the highest privilege level on affected machines. - Victims were compromised when port 5900 (the port used by macOS Screen Sharing) was exposed to the internet. In each reported case attackers installed Monero mining software to siphon CPU/GPU cycles and electricity. - The NCSC says proof-of-concept exploit code is now circulating, making it much easier for opportunistic attackers to mount similar campaigns. Why Monero? Monero (XMR) is a privacy-focused cryptocurrency whose transactions are difficult to trace compared with transparent chains like Bitcoin or Ethereum. Those privacy properties make Monero a frequent choice for “cryptojacking” — hijacking others’ machines to mine coins while the attacker keeps the proceeds and the victim pays the costs. Apple’s response and who’s at risk - Apple has released fixes in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1, tightening validation checks to close the bypass. - Systems that haven’t been updated — especially those with Screen Sharing reachable from the public internet — remain vulnerable. Broader context This campaign is part of an ongoing wave of malware and crypto-theft incidents. Recent examples include pirated software laced with stealers, wallet-draining malware distributed via fake CAPTCHA pages, mobile apps hiding wallet-stealing code, malicious game wallpapers, and malicious Python libraries — all aimed at siphoning funds or compute for attackers. NCSC recommendations (practical steps) - Update immediately to the patched macOS releases listed above. - Don’t expose Screen Sharing (port 5900) to the internet. If you need remote access, use a VPN or Apple’s official remote tools routed securely. - As general hygiene: run OS updates promptly, monitor for unusual CPU or network usage, and harden remote access with firewalls and least-privilege principles. Bottom line If you run macOS and have Screen Sharing or VNC exposed, treat this as urgent. Patch now and block or restrict remote access to avoid becoming fodder for Monero miners. Read more AI-generated news on: undefined/news