Dutch Cybersecurity Agency Warns of macOS Vulnerability Used to Mine Monero

icon币界网
Share
AI summary iconSummary
Dutch cybersecurity officials issued a vulnerability alert regarding a macOS flaw being exploited to mine Monero. The vulnerability, CVE-2026-65400, allows remote attackers to gain root access via port 5900. Proof-of-concept code is already available, heightening the risk of exploitation. Apple has released patches for macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. Users are advised to update their systems and disable screen sharing on public networks. The incident underscores the importance of timely patching and monitoring in both on-chain news and broader cybersecurity practices.
CoinDesk reports:

This week, the Dutch National Cyber Security Centre warned that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to compromise certain Mac devices exposed to the internet and secretly deploy Monero mining software on them.

The organization stated that it has received multiple reports of active attacks. The affected systems had port 5900 exposed to the public internet, allowing attackers to gain access to the screen sharing service and subsequently obtain root privileges—the highest level of control over the device.

Exploit code for the vulnerability has been publicly released.

This vulnerability, identified as CVE-2026-65400, has a severity score of 7.1. The issue lies in session management during the login authentication process, causing the system to incorrectly accept login requests that should be denied, allowing network attackers to authenticate without valid credentials.

The Dutch National Cyber Security Centre also noted that the public PoC code for this vulnerability has already been circulated, meaning more attackers can replicate the attack technique with lower barriers.

Attackers deployed Monero mining software

In known cases, after gaining control of a device, attackers install Monero mining software to continuously mine using the victim’s hardware resources. Monero, due to its strong anonymity, has long been used in such “cryptojacking” attacks. Compared to public-chain assets like Bitcoin or Ethereum, these earnings are much harder to trace.

These attacks typically do not immediately lock devices but instead consume computing power over an extended period. Victims bear costs such as increased electricity consumption and reduced device performance, while the mining rewards go to the attackers.

Apple has released a patch update.

Apple has fixed this issue in multiple macOS versions, including macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, by strengthening authentication validation to prevent unauthorized login states from being incorrectly approved.

The Dutch National Cyber Security Centre advises users to install updates as soon as possible and to avoid exposing screen sharing services directly to the internet, especially devices with port 5900 still open, which pose a higher risk.

Recently, wallet thefts and malicious mining attacks involving crypto assets continue to rise. In addition to Monero mining programs, security agencies have consistently detected crypto-stealing malware distributed through pirated software, fake CAPTCHA pages, mobile apps, and malicious code repositories.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.