Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Apple's macOS Screen Sharing Flaw Is Being Exploited in the Wild

The flaw let attackers gain root access without valid credentials, and the Dutch cyber agency said multiple exposed systems were used to install Monero miners.

  • On Aug. 6, Apple released security updates for Tahoe, Sequoia, and Sonoma to address CVE-2026-65400, an authentication flaw that allowed unauthorized remote access to Mac systems.
  • The authentication flaw, caused by improper state management, permitted attackers to bypass security protocols and gain root access to install Monero mining software on compromised Macs.
  • CISA upgraded the vulnerability to a 9.8 critical CVSS score on Aug. 14, while security firm Huntress identified tens of thousands of potentially vulnerable hosts with port 5900 exposed.
  • The National Cyber Security Center confirmed active exploitation on multiple systems on Wednesday, Aug. 12; the NCSC added that "in all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed."
  • Users should apply the latest security patches immediately to protect their systems, while Huntress recommends disabling Screen Sharing and employing a VPN, since changing passwords does not mitigate this authentication vulnerability.
Insights by Ground AI

31 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 87% of the sources are Center
87% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

coinstats.app broke the news on Sunday, August 16, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal