Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands’ National Cyber Security Centre says CVE-2026-65400 in macOS Screen Sharing is being actively exploited after public exploit code appeared. Attackers are using exposed port 5900 to gain root access and install a Monero miner on affected systems. #CVE-2026-65400 #macOS #NCSC #Monero

Keypoints

  • Hackers are exploiting a macOS authentication bypass vulnerability in the wild.
  • The flaw affects macOS Screen Sharing over VNC on TCP port 5900.
  • Apple fixed CVE-2026-65400 in macOS Tahoe 26.6.1 and related releases.
  • Attackers can gain access without valid credentials and obtain root privileges.
  • The NCSC observed compromised systems being used to deploy a Monero miner.

Read More: https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/