Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
Summary
A critical vulnerability in Apple macOS's Screen Sharing component, identified as CVE-2026-65400, is being actively exploited to install a Monero cryptocurrency miner on internet-exposed Macs. The Netherlands National Cyber Security Centre (NCSC) issued a warning about this exploitation.
IFF Assessment
Active exploitation of a critical vulnerability allows attackers to compromise systems and deploy malware, representing a direct threat to defenders.
Severity
Defender Context
This incident highlights the immediate risk posed by unpatched vulnerabilities, especially those affecting commonly used services like screen sharing. Defenders should prioritize patching systems for CVE-2026-65400 and monitor their networks for signs of unauthorized access or unusual resource utilization, such as cryptocurrency mining.