uMaHF0G5M1jYL9t88qHEEkQggU6GJ5wTZlhvItt7
Bookmark

Apple Mac Flaw Exploited to Mine Monero, Emergency Update Issued

A critical macOS Screen Sharing flaw, CVE-2026-65400, is being actively exploited to gain control of internet-exposed Macs and install Monero miners.

A critical security vulnerability in Apple's macOS Screen Sharing feature is being actively exploited by attackers, with compromised Macs reportedly being used to mine Monero cryptocurrency.

The vulnerability, identified as CVE-2026-65400, affects Macs with Apple's Screen Sharing service exposed to the internet. According to reporting on an alert from the Dutch National Cyber Security Centre, attackers have been able to bypass authentication, obtain extensive control of vulnerable machines and install cryptocurrency-mining software. In the cases observed by the agency, the attackers installed Monero miners after compromising the systems.

The development has raised fresh concerns for Mac users and organizations that expose remote-access services to the public internet.

Apple released an emergency security update on Aug. 6 to address the vulnerability. Security researchers and government agencies are now urging users to install the patched versions as quickly as possible, particularly if Screen Sharing is enabled or accessible from @coinbureau outside a trusted network.

Source: Xpost

A Serious Threat to Internet-Exposed Macs

The vulnerability is particularly concerning because Screen Sharing is designed to provide remote access to a Mac.

Apple's Screen Sharing service allows another computer to connect remotely, view the Mac's desktop and control applications, files and other functions. Apple explains that the feature can also allow a remote user to open, move and close files and windows and restart the computer.

The newly exploited flaw affects the authentication process used by the Screen Sharing server.

According to security reporting, attackers can exploit the vulnerability to authenticate without valid credentials. Systems with the Screen Sharing service exposed through TCP port 5900 are particularly at risk because the service can become directly reachable from the internet.

That creates a dangerous scenario for businesses, remote workers and Mac administrators who have configured systems for remote access without sufficiently restricting network exposure.

Attackers Installed Monero Miners

The most notable aspect of the attacks is what happened after attackers gained access.

Rather than simply stealing information or disrupting the affected computers, attackers observed by the Dutch cyber agency installed Monero cryptocurrency miners.

Monero is a privacy-focused cryptocurrency that can be mined using computer processing power. Malicious mining campaigns, commonly known as cryptojacking, secretly use compromised computers to generate cryptocurrency for attackers.

For victims, the consequences can include significantly higher processor usage, slower system performance, increased electricity consumption and accelerated hardware wear.

In a corporate environment, a successful cryptojacking campaign can also consume substantial computing resources across multiple machines.

The Dutch National Cyber Security Centre reported that every exploitation case it had observed involved the installation of a Monero miner, according to security reporting.

Apple Released an Emergency Patch

Apple responded to the vulnerability with an out-of-band security update on Aug. 6.

The affected operating systems received updated versions identified as macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.

The emergency release came shortly after Apple's regular security updates at the end of July.

Apple's security documentation confirms that Screen Sharing Server vulnerabilities have been addressed in recent macOS releases, including flaws involving network connections, denial-of-service conditions and access to sensitive information.

For users, the most important step is straightforward: install the latest available macOS security update.

Apple itself states that keeping software updated is one of the most important measures users can take to protect their devices.

The Vulnerability Has Become More Serious

The severity assessment surrounding CVE-2026-65400 has also changed.

The vulnerability was initially assigned a CVSS score of 7.1. After evidence emerged showing that the attack could be automated and could result in complete system compromise, the score was raised to 9.8, placing it in the critical category.

Security researchers have also demonstrated the vulnerability publicly, and proof-of-concept exploit code has reportedly become available.

That combination increases the risk for systems that remain unpatched.

Once technical details become widely available, attackers do not necessarily need sophisticated resources to begin scanning the internet for vulnerable machines.

Not Every Mac Is Automatically Exposed

Despite the severity of the vulnerability, it is important to understand that not every Mac connected to the internet is necessarily vulnerable in the same way.

The primary concern involves systems where Screen Sharing is enabled and the relevant service is reachable by an attacker.

Apple's Screen Sharing feature is normally used for trusted remote connections, and the service can be disabled when it is not required.

Users can check Screen Sharing through System Settings, General and Sharing. Apple provides controls that allow users to turn the feature on or off and specify which users are permitted to access the Mac.

For organizations, additional network controls can reduce exposure by preventing remote desktop services from being directly accessible from the public internet.

Why Monero Is Attractive to Attackers

The use of Monero in the attacks is also significant.

Cryptocurrency mining malware has been used for years because attackers can potentially monetize compromised computers without immediately stealing files or demanding a ransom.

Instead, the malware runs silently in the background and uses the victim's processor to perform mining operations.

Monero has historically attracted mining-related malware campaigns because of its privacy features and its ability to be mined using conventional computing hardware.

A compromised Mac may therefore become part of an attacker's broader mining operation without the owner immediately realizing what has happened.

Warning signs can include unusually high CPU usage, fans running constantly, reduced performance and unexplained increases in power consumption.

Coin Bureau Highlights the Security Risk

The latest Apple vulnerability has also attracted attention within the cryptocurrency community, including from the X account @coinbureau.

The incident is particularly relevant to crypto users because the attack demonstrates how cybersecurity vulnerabilities can be directly connected to cryptocurrency mining.

While the incident is primarily a macOS security issue, it also highlights a broader problem facing the digital-asset industry: attackers continue to search for ways to turn compromised computers into sources of cryptocurrency revenue.

What Mac Users Should Do Now

Mac users should not wait to update their computers if they have not already installed Apple's latest security releases.

Those who do not need Screen Sharing should consider disabling it. Apple provides a direct option under System Settings, General and Sharing to turn the feature off.

Organizations should also review their firewall and remote-access configurations to determine whether TCP port 5900 or other remote-management services are unnecessarily exposed to the public internet.

If a Mac was exposed and shows unusual processor activity after the vulnerability became actively exploited, administrators should investigate the system rather than assuming the performance problem is harmless.

Security teams should also look for unauthorized processes, unexpected network connections and cryptocurrency-mining activity.

A Warning for Mac Security

The latest campaign serves as a reminder that Apple's operating system is not immune to serious security vulnerabilities.

The fact that attackers have already exploited CVE-2026-65400 makes the situation more urgent than a theoretical security flaw. The availability of a security patch means users now have a clear way to reduce their exposure.

For Mac owners, updating the operating system is the most important immediate step.

For companies, the incident highlights the risks of exposing remote-access services directly to the internet.

And for the wider cryptocurrency industry, the campaign demonstrates how quickly cybercriminals can turn a software vulnerability into a source of cryptocurrency revenue.

With active exploitation already reported and the vulnerability's severity now rated critical, leaving an unpatched Mac exposed to the internet could carry a significant security risk.


hoka.news – Not Just  Crypto News. It’s Crypto Culture.

Writer @Victoria

Victoria Hale is a writer focused on blockchain and digital technology. She is known for her ability to simplify complex technological developments into content that is clear, easy to understand, and engaging to read.

Through her writing, Victoria covers the latest trends, innovations, and developments in the digital ecosystem, as well as their impact on the future of finance and technology. She also explores how new technologies are changing the way people interact in the digital world.

Her writing style is simple, informative, and focused on providing readers with a clear understanding of the rapidly evolving world of technology.

Check out other news and articles on Google News

Disclaimer:

The articles on HOKA.NEWS are here to keep you updated on the latest buzz in crypto, tech, and beyond—but they’re not financial advice. We’re sharing info, trends, and insights, not telling you to buy, sell, or invest. Always do your own homework before making any money moves.

HOKA.NEWS isn’t responsible for any losses, gains, or chaos that might happen if you act on what you read here. Investment decisions should come from your own research—and, ideally, guidance from a qualified financial advisor. Remember:  crypto and tech move fast, info changes in a blink, and while we aim for accuracy, we can’t promise it’s 100% complete or up-to-date.

Stay curious, stay safe, and enjoy the ride! hoka.news