macOS Screen Sharing Exploit Enables Root Access and Monero Mining

TL;DR. Threat actors are exploiting a recently patched macOS Screen Sharing vulnerability, CVE-2026-65400, to gain root access and install Monero miners on vulnerable systems. - The high-severity bug allows remote attackers to log in without valid credentials, impacting macOS Tahoe, Sequoia, and Sonoma. - Apple released fixes on August 6, but exploitation began roughly a week later, fueled by a public proof-of-concept. - The Dutch NCSC warned of active abuse on systems where port 5900 was internet-accessible.

Sources

Back to QLANKR News