This week, the Dutch National Cyber Security Centre warned that attackers are exploiting a vulnerability in Apple's macOS Screen Sharing feature to compromise certain Mac devices exposed to the internet and secretly deploy Monero mining software on them.
The organization stated that it has received multiple reports of active attacks. The affected systems had port 5900 exposed to the public internet, allowing attackers to gain access to the screen sharing service and subsequently obtain root privileges—the highest level of control over the device.
Exploit code for the vulnerability has been publicly released.
This vulnerability, identified as CVE-2026-65400, has a severity score of 7.1. The issue lies in session management during the login authentication process, causing the system to incorrectly accept login requests that should be denied, allowing network attackers to authenticate without valid credentials.
The Dutch National Cyber Security Centre also noted that the public PoC code for this vulnerability has already been circulated, meaning more attackers can replicate the attack technique with lower barriers.
Attackers deployed Monero mining software
In known cases, after gaining control of a device, attackers install Monero mining software to continuously mine using the victim’s hardware resources. Monero, due to its strong anonymity, has long been used in such “cryptojacking” attacks. Compared to public-chain assets like Bitcoin or Ethereum, these earnings are much harder to trace.
These attacks typically do not immediately lock devices but instead consume computing power over an extended period. Victims bear costs such as increased electricity consumption and reduced device performance, while the mining rewards go to the attackers.
Apple has released a patch update.
Apple has fixed this issue in multiple macOS versions, including macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, by strengthening authentication validation to prevent unauthorized login states from being incorrectly approved.
The Dutch National Cyber Security Centre advises users to install updates as soon as possible and to avoid exposing screen sharing services directly to the internet, especially devices with port 5900 still open, which pose a higher risk.
Recently, wallet thefts and malicious mining attacks involving crypto assets continue to rise. In addition to Monero mining programs, security agencies have consistently detected crypto-stealing malware distributed through pirated software, fake CAPTCHA pages, mobile apps, and malicious code repositories.

