Briefly
- The Netherlands’ NCSC warned of lively exploitation of a macOS Display screen Sharing vulnerability throughout programs with port 5900 uncovered to the web, the place attackers gained root entry and put in Monero mining applications.
- The flaw stems from defective state administration throughout authentication, letting community attackers log in with out legitimate credentials
- The cryptojacking marketing campaign—which quietly mines privateness coin Monero on victims’ {hardware}—joins a wave of comparable schemes.
Attackers have been exploiting a vulnerability in Apple’s macOS Display screen Sharing characteristic to grab management of Macs and quietly set up cryptocurrency miners, the Netherlands’ nationwide cyber company warned this week.
In an up to date advisory, the Dutch Nationwide Cyber Safety Middle, or NCSC, stated it obtained reviews of lively exploitation throughout a number of programs that had port 5900, utilized by Display screen Sharing, uncovered to the web.

In every case, the attackers gained root entry, the very best stage of management over a machine, and planted a Monero mining program to harness the sufferer’s {hardware}. Monero is a so-called privateness coin, a sort of cryptocurrency that can not be simply traced, in contrast to clear networks similar to Bitcoin or Ethereum. The company flagged that public proof-of-concept code for the flaw is now circulating, reducing the bar for would-be attackers.
The bug, tracked as CVE-2026-65400 and rated 7.1 out of 10 in severity, is an authentication flaw rooted in defective state administration in the course of the login course of. It let network-based attackers slip by way of with out legitimate credentials, accepting authentication makes an attempt that ought to have been rejected.
Apple has since patched the problem, tightening its validation checks in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1. Customers who have not up to date, notably anybody with Display screen Sharing reachable from the open web, stay uncovered.
Monero has lengthy been the coin of alternative for so-called cryptojacking, wherein hijacked machines mine crypto for an attacker who pockets the rewards whereas the sufferer absorbs the electrical energy prices and degraded efficiency. The token’s privateness options make the proceeds far tougher to hint than Bitcoin.
The marketing campaign is the most recent in a gentle stream of schemes turning different folks’s units into crypto revenue.
Simply this month, Bitdefender discovered pirated copies of “The Odyssey” laced with the wallet-draining Lumma Stealer. Decrypt has additionally reported on malware pushed by way of faux CAPTCHA pages routed by way of BNB Chain, the SparkKitty operation that hid wallet-stealing code in cellular apps, malicious “anime woman” wallpapers geared toward Steam players, and crypto-stealing code smuggled right into a booby-trapped Python library.
The NCSC suggests customers apply Apple’s updates promptly and keep away from leaving Display screen Sharing accessible from the web, which gave attackers their opening within the first place.
Day by day Debrief Publication
Begin daily with the highest information tales proper now, plus unique options, a podcast, movies and extra.
