By Daily Touch Insights Editorial Team
Editorial Team
View Journalist Profile

CYBERSECURITY & TECHNOLOGY — Hackers are actively exploiting a recently patched macOS vulnerability to gain unauthorized access to computers and install cryptocurrency-mining software, according to the Netherlands' National Cyber Security Centre.

The attacks target a flaw in Apple's built-in Screen Sharing feature. Security researchers and authorities say systems with the relevant service exposed to the internet have already been compromised, with attackers obtaining root access and deploying a Monero cryptocurrency miner. 0


A Built-In Mac Feature Became the Entry Point

The vulnerability affects macOS Screen Sharing, a feature that allows users to remotely control a Mac over a network.

Screen Sharing uses the VNC protocol and normally requires authentication before a remote user can access the computer.

The newly exploited flaw, tracked as CVE-2026-65400, allows a network-based attacker to bypass the normal authentication process.

That means an attacker could potentially gain access without knowing the legitimate user's password. 1


Attackers Are Already Using the Vulnerability

The situation has moved beyond a theoretical security concern.

The Netherlands' National Cyber Security Centre said it received information showing that the vulnerability was being actively exploited against multiple systems where TCP port 5900 was accessible from the internet.

In the reported incidents, attackers obtained root access and installed a Monero cryptocurrency miner.

This makes the vulnerability particularly serious because successful exploitation can give attackers extensive control over an affected Mac. 2


Why Hackers Want Root Access

Root access provides an attacker with a much higher level of control over a computer.

Once attackers obtain that level of access, they can potentially install software, alter system settings, access files and maintain control over the machine.

In the attacks observed so far, criminals used that access to install cryptocurrency-mining software.

The objective is simple: use someone else's computing resources to generate cryptocurrency for the attacker.


What Is a Monero Miner?

Monero is a cryptocurrency designed with a strong emphasis on privacy.

Mining involves using computing resources to perform calculations that support a cryptocurrency network and, in return, potentially earn rewards.

When criminals secretly install mining software on somebody else's computer, the practice is commonly called cryptojacking.

The victim pays the cost through electricity consumption, processor usage, reduced performance and potentially increased hardware wear, while the attacker receives the financial benefit.


The Mac May Become Noticeably Slower

A cryptocurrency miner can consume substantial computing resources.

Users may notice unusually high CPU usage, slower applications, increased fan activity, overheating or reduced battery life.

However, sophisticated attackers may attempt to keep the miner running quietly in the background, making the compromise difficult to notice immediately.

That is why unusual performance problems should not automatically be dismissed as an aging computer.


The Biggest Danger Is Remote Access

The cryptocurrency miner is only one possible consequence of the vulnerability.

The more serious issue is that the flaw can allow unauthorized remote access to a Mac.

Once an attacker gains control, the machine could potentially be used for activities beyond cryptocurrency mining.

Security authorities have not publicly disclosed the full scope of the observed attacks, including whether the vulnerability has been used for other forms of malicious activity. 3


Apple Has Already Released Security Updates

Apple addressed the vulnerability in recent macOS security releases.

The affected versions have been updated through:

  • macOS Tahoe 26.6.1
  • macOS Sequoia 15.7.9
  • macOS Sonoma 14.8.9

Apple's fixes improve the way the system manages authentication and prevent unauthorized authentication attempts against Screen Sharing. 4


Mac Users Should Update Immediately

The most important step for Mac users is to install the latest available security update for their device.

Because exploitation has already been reported, waiting for more information before updating creates unnecessary risk.

Users can check for updates through System Settings → General → Software Update.

Keeping macOS updated is particularly important when a vulnerability affects a service capable of providing remote access.


Screen Sharing Should Not Be Exposed to the Internet

Users who do not need Screen Sharing should consider disabling it.

Apple provides the option under System Settings → General → Sharing → Screen Sharing.

If remote access is necessary, exposing a remote desktop service directly to the public internet creates additional security risks and should be carefully controlled.

The recent attacks demonstrate why remote administration services should be restricted to trusted networks or protected access mechanisms whenever possible.


Public Exploit Code Increased the Risk

The vulnerability became especially concerning after exploit code was made publicly available.

Once working exploit information becomes accessible, the barrier for less sophisticated attackers can fall dramatically.

Criminal groups no longer need to discover the vulnerability independently. They can study publicly available research and adapt it to automated attacks.

This can turn a newly disclosed vulnerability into an active threat much faster than many organizations expect.


Why Port 5900 Matters

Port 5900 is commonly associated with VNC-based remote desktop services, including Screen Sharing.

If such a service is directly reachable from the internet, attackers can scan for exposed systems and attempt to exploit vulnerabilities in the service.

The Dutch NCSC specifically linked the reported exploitation to systems where port 5900 was accessible from the internet. 5

This highlights an important security principle: a vulnerable service does not have to be actively used by a person to become an attack surface.


Businesses Face Greater Risk

The vulnerability could be particularly concerning for businesses that use Macs for sensitive work.

A compromised employee computer can provide attackers with more than computing resources for cryptocurrency mining.

Depending on the attacker's capabilities and the privileges available, a compromised machine could potentially become a starting point for accessing company information or other systems.

Organizations should therefore treat the issue as a security incident rather than simply a performance problem if they discover signs of exploitation.


How to Look for Warning Signs

Mac users should pay attention to unusual changes in system behaviour.

  • Unexpectedly high CPU usage.
  • Fans running heavily when the Mac is idle.
  • Unexplained overheating.
  • Sudden performance degradation.
  • Unexpected applications or processes.
  • Unusual network activity.
  • Screen Sharing being enabled without authorization.

These signs do not prove that a Mac has been compromised, but they can justify further investigation.


Updating Is Better Than Trying to Remove the Miner Later

Once an attacker has obtained root access, simply deleting an unfamiliar mining application may not be enough.

An attacker with privileged access could potentially establish persistence or modify other parts of the system.

That makes prevention particularly important.

Installing Apple's security update and limiting unnecessary remote-access services significantly reduces the opportunity for attackers to exploit the vulnerability.


Cryptocurrency Mining Is Becoming a Common Criminal Objective

Cryptojacking is attractive to cybercriminals because it can generate income without directly stealing money from every victim.

Instead, attackers attempt to compromise large numbers of computers and combine their computing power.

Even relatively small amounts of computing power can become financially valuable when criminals control thousands of machines.

Mac computers are therefore not immune from financially motivated malware simply because Apple's ecosystem has historically experienced fewer traditional malware infections than some other platforms.


The Bigger Lesson for Mac Security

The incident demonstrates that Apple's built-in security features can themselves become targets.

Screen Sharing is designed to provide legitimate remote access, but any service that accepts network connections can potentially become an attack surface.

The lesson is not that Mac users should stop using remote access altogether.

It is that convenience must be balanced with exposure, authentication and timely security updates.


Our Perspective

The most worrying part of this incident is not the Monero mining itself.

Mining cryptocurrency is relatively low-impact compared with some other forms of cybercrime.

The deeper concern is the authentication bypass that allowed attackers to obtain privileged access to machines remotely.

Once criminals have a reliable way into a computer, cryptocurrency mining may simply be the first thing they choose to do.

A security flaw that begins as a crypto-mining problem can become a much larger cybersecurity problem if attackers discover other ways to exploit the access they obtain.


Conclusion

Hackers are actively exploiting a macOS Screen Sharing vulnerability to gain unauthorized access and install Monero cryptocurrency miners on exposed systems.

The Netherlands' National Cyber Security Centre has confirmed exploitation on multiple machines where port 5900 was accessible from the internet, with attackers obtaining root access. 6

Apple has already released security updates for macOS Tahoe, Sequoia and Sonoma that address the vulnerability.

Mac users should install the latest security updates and disable Screen Sharing if they do not need it.

The incident is another reminder that even trusted built-in features can become dangerous attack surfaces when vulnerabilities remain unpatched and remote services are exposed to the internet.