Hackers are exploiting a flaw in Apple’s macOS Screen Sharing service to seize control of internet-reachable Macs and install Monero mining software, according to an updated advisory from the Netherlands’ National Cyber Security Centre (NCSC-NL). The reports place unpatched remote Mac hosts, particularly systems used in server environments, at risk of being turned into unauthorized cryptocurrency miners.
Apple addressed the vulnerability, tracked as CVE-2026-65400, on Aug. 6 with updates for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. Apple said the bug could allow an attacker on the network to access Screen Sharing without a valid password.
NCSC-NL said it had received reports involving multiple exposed systems. Attackers obtained full access to affected Macs and deployed XMR mining software, the agency said, without identifying a suspected group or providing a count of compromised devices.
The incident moves cryptojacking from the more familiar territory of compromised websites and cloud workloads into a specific remote-management weakness affecting Macs that have been deliberately made reachable for administration.
A pre-authentication flaw defeats password changes
Screen Sharing is disabled by default on macOS, limiting exposure for many personal machines. The service is commonly enabled on remotely hosted Macs, including so-called bare-metal systems rented or operated in data centers, where administrators need graphical access without physical hardware nearby.
That setup can create a direct attack path when Screen Sharing is exposed to the public internet. A remote-management feature intended for administrators can become an entry point for automated scans seeking machines that have not received Apple’s August security updates.
Huntress, a cybersecurity firm that investigated the vulnerability, said the flaw can cause a Mac to treat an unknown connection as if it had already been authenticated. Huntress researcher Ryan Dowd said the problem occurs before the authentication stage, meaning that changing Screen Sharing passwords or deleting them would not remove the underlying exposure.
That detail raises the urgency of patching. Credentials often serve as the first response after a remote-access service is suspected of being targeted, but password resets do not correct a software flaw that bypasses the login check itself. Organizations running affected machines would need to install Apple’s updates or disable Screen Sharing until patches can be deployed.
Dowd said a Censys search identified “tens of thousands of potentially vulnerable hosts.” Many appeared to be Macs rented by the hour from hosting providers, he said. Such hosts can be attractive to attackers because they may have reliable network connections, substantial available computing power and configurations designed for remote access.
Severity score increased after Apple’s fix
The U.S. National Vulnerability Database entry for CVE-2026-65400 lists a CVSS severity score of 9.8 out of 10, after initially carrying a 7.1 rating when Apple released its fixes. CVSS, or the Common Vulnerability Scoring System, measures the technical seriousness of a security issue rather than the number of machines compromised.
A 9.8 score falls within the “critical” range and reflects the combination of remote access, the possibility of high-level system control and the lack of a password requirement described by Apple. The issue has not been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, according to the available government tracking record, despite the NCSC-NL reports of attacks.
The absence from that catalog does not change the operational risk for operators with exposed Macs. The NCSC-NL advisory describes active misuse, and the affected service is often found in environments where a successful intrusion can run unnoticed for extended periods.
Why Monero is a frequent cryptojacking target
The attackers in the reported cases installed miners for Monero, whose XMR token is often associated with cryptojacking campaigns. Monero can be mined with ordinary computer processors, unlike cryptocurrencies that generally require specialized mining equipment to compete effectively.
That makes compromised servers, desktops and cloud machines useful raw material for attackers. Rather than acquiring hardware and paying power bills, an intruder can redirect a victim’s computing resources toward mining and retain any proceeds generated by the software.
Monero’s privacy-focused transaction design can also make it harder to trace the movement of mining proceeds once they leave an attacker-controlled wallet. Mining rewards are distributed across participants in the network, so a single compromised Mac may generate limited returns; operators often seek scale by infecting large numbers of machines.
The Monero network issues roughly 432 XMR in daily rewards, according to Monero’s emission schedule. Those rewards are shared among miners, meaning a cryptojacking operation’s income depends on the amount of processing power it can commandeer and how long it remains undetected.
Mining malware can also impose costs beyond electricity. Sustained processor usage can degrade the performance of hosted Macs, interrupt workloads, increase cooling demands and make systems less reliable for customers paying for remote access. In a hosting setting, unexplained CPU load may be the first visible indication that a machine has been compromised.
Remote Mac operators face the most immediate exposure
Organizations operating remotely managed Macs should prioritize the Apple updates for Tahoe, Sequoia and Sonoma, especially where Screen Sharing is exposed beyond a private network. Disabling the feature when it is unnecessary removes the vulnerable service from reach, while firewall rules and VPN-only administration can reduce the number of systems able to initiate connections.
Network administrators can also review Screen Sharing configurations, investigate unusual processor consumption and look for unfamiliar mining-related processes or outbound connections. Because Huntress said the authentication bypass occurs before password validation, password changes should be treated as a supplementary security measure rather than a fix.
The reported attacks offer a practical warning for companies using hosted Mac capacity: remote administration services need the same patching and access controls applied to public-facing servers. A machine configured for convenience can become a source of illicit mining revenue when a critical authentication flaw remains exposed online.
Worried about cryptojacking risks? Strengthen your security basics with Toobit Academy’s guide on crypto safety and protect your assets.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
