Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

Summary

A critical vulnerability in Apple macOS's Screen Sharing component, identified as CVE-2026-65400, is being actively exploited to install a Monero cryptocurrency miner on internet-exposed Macs. The Netherlands National Cyber Security Centre (NCSC) issued a warning about this exploitation.

IFF Assessment

FOE

Active exploitation of a critical vulnerability allows attackers to compromise systems and deploy malware, representing a direct threat to defenders.

Severity

9.8 Critical

Defender Context

This incident highlights the immediate risk posed by unpatched vulnerabilities, especially those affecting commonly used services like screen sharing. Defenders should prioritize patching systems for CVE-2026-65400 and monitor their networks for signs of unauthorized access or unusual resource utilization, such as cryptocurrency mining.

Read Full Story →