toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trade
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android version app
More download options

Hackers exploit macOS Screen Sharing to mine Monero

2026-08-16 15:19

Hackers are exploiting a flaw in Apple’s macOS Screen Sharing service to seize control of internet-reachable Macs and install Monero mining software, according to an updated advisory from the Netherlands’ National Cyber Security Centre (NCSC-NL). The reports place unpatched remote Mac hosts, particularly systems used in server environments, at risk of being turned into unauthorized cryptocurrency miners.

Apple addressed the vulnerability, tracked as CVE-2026-65400, on Aug. 6 with updates for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. Apple said the bug could allow an attacker on the network to access Screen Sharing without a valid password.

NCSC-NL said it had received reports involving multiple exposed systems. Attackers obtained full access to affected Macs and deployed XMR mining software, the agency said, without identifying a suspected group or providing a count of compromised devices.

The incident moves cryptojacking from the more familiar territory of compromised websites and cloud workloads into a specific remote-management weakness affecting Macs that have been deliberately made reachable for administration.

A pre-authentication flaw defeats password changes

Screen Sharing is disabled by default on macOS, limiting exposure for many personal machines. The service is commonly enabled on remotely hosted Macs, including so-called bare-metal systems rented or operated in data centers, where administrators need graphical access without physical hardware nearby.

That setup can create a direct attack path when Screen Sharing is exposed to the public internet. A remote-management feature intended for administrators can become an entry point for automated scans seeking machines that have not received Apple’s August security updates.

Huntress, a cybersecurity firm that investigated the vulnerability, said the flaw can cause a Mac to treat an unknown connection as if it had already been authenticated. Huntress researcher Ryan Dowd said the problem occurs before the authentication stage, meaning that changing Screen Sharing passwords or deleting them would not remove the underlying exposure.

That detail raises the urgency of patching. Credentials often serve as the first response after a remote-access service is suspected of being targeted, but password resets do not correct a software flaw that bypasses the login check itself. Organizations running affected machines would need to install Apple’s updates or disable Screen Sharing until patches can be deployed.

Dowd said a Censys search identified “tens of thousands of potentially vulnerable hosts.” Many appeared to be Macs rented by the hour from hosting providers, he said. Such hosts can be attractive to attackers because they may have reliable network connections, substantial available computing power and configurations designed for remote access.

Severity score increased after Apple’s fix

The U.S. National Vulnerability Database entry for CVE-2026-65400 lists a CVSS severity score of 9.8 out of 10, after initially carrying a 7.1 rating when Apple released its fixes. CVSS, or the Common Vulnerability Scoring System, measures the technical seriousness of a security issue rather than the number of machines compromised.

A 9.8 score falls within the “critical” range and reflects the combination of remote access, the possibility of high-level system control and the lack of a password requirement described by Apple. The issue has not been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, according to the available government tracking record, despite the NCSC-NL reports of attacks.

The absence from that catalog does not change the operational risk for operators with exposed Macs. The NCSC-NL advisory describes active misuse, and the affected service is often found in environments where a successful intrusion can run unnoticed for extended periods.

Why Monero is a frequent cryptojacking target

The attackers in the reported cases installed miners for Monero, whose XMR token is often associated with cryptojacking campaigns. Monero can be mined with ordinary computer processors, unlike cryptocurrencies that generally require specialized mining equipment to compete effectively.

That makes compromised servers, desktops and cloud machines useful raw material for attackers. Rather than acquiring hardware and paying power bills, an intruder can redirect a victim’s computing resources toward mining and retain any proceeds generated by the software.

Monero’s privacy-focused transaction design can also make it harder to trace the movement of mining proceeds once they leave an attacker-controlled wallet. Mining rewards are distributed across participants in the network, so a single compromised Mac may generate limited returns; operators often seek scale by infecting large numbers of machines.

The Monero network issues roughly 432 XMR in daily rewards, according to Monero’s emission schedule. Those rewards are shared among miners, meaning a cryptojacking operation’s income depends on the amount of processing power it can commandeer and how long it remains undetected.

Mining malware can also impose costs beyond electricity. Sustained processor usage can degrade the performance of hosted Macs, interrupt workloads, increase cooling demands and make systems less reliable for customers paying for remote access. In a hosting setting, unexplained CPU load may be the first visible indication that a machine has been compromised.

Remote Mac operators face the most immediate exposure

Organizations operating remotely managed Macs should prioritize the Apple updates for Tahoe, Sequoia and Sonoma, especially where Screen Sharing is exposed beyond a private network. Disabling the feature when it is unnecessary removes the vulnerable service from reach, while firewall rules and VPN-only administration can reduce the number of systems able to initiate connections.

Network administrators can also review Screen Sharing configurations, investigate unusual processor consumption and look for unfamiliar mining-related processes or outbound connections. Because Huntress said the authentication bypass occurs before password validation, password changes should be treated as a supplementary security measure rather than a fix.

The reported attacks offer a practical warning for companies using hosted Mac capacity: remote administration services need the same patching and access controls applied to public-facing servers. A machine configured for convenience can become a source of illicit mining revenue when a critical authentication flaw remains exposed online.


Worried about cryptojacking risks? Strengthen your security basics with Toobit Academy’s guide on crypto safety and protect your assets.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trade
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.