
Attackers are exploiting a high-severity macOS vulnerability to install Monero crypto miners on exposed systems.
Dutch officials warn that a high-severity macOS vulnerability (CVE-2026-65400) allowing remote code execution is under active exploitation to install Monero crypto miners on exposed systems.
AI-generated summary
A vulnerability tracked as CVE-2026-65400 affects macOS screen sharing, allowing remote access when port 5900 is exposed to the internet.
Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”
Do you know if your screen sharing is on?
The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.
A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last week’s Black Hat security conference. Apple said last week that CVE-2026-65400 “may” allow an attacker without credentials to gain access to a Mac. It’s unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.
As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren’t within the capabilities of most users.
The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week’s security update is also a must.
Right now, there are no indications exploits are being used to install anything other than Monero miners, which surreptitiously harness a Mac’s resources to perform mathematical operations that generate the cryptocurrency for the attacker. A bigger risk is that attackers might exploit the vulnerability to install malware that steals credentials or performs other more nefarious activities.

The Pebble Time 2, a rebooted indie smartwatch by founder Eric Migicovsky and Core Devices, offers a retro-inspired, community-driven alternative to mainstream smartwatches with its e-paper display, long battery life, and extensive library of user-created apps.

Michael Polansky, co-founder of Outer Biosciences, is emerging from years of stealth to discuss his startup's AI-driven approach to dermatology. The company uses living human skin tissue to test cosmetic and pharmaceutical ingredients, aiming to accelerate discovery.

Sapporo-based startup Letara has raised ¥2.6 billion ($16 million) to scale its hybrid rocket propulsion technology. The company, which spun out of Hokkaido University, aims to supply satellite makers, launch companies, and defense sectors with its proprietary systems.

As Meta AI glasses gain popularity, concerns over nonconsensual recording have led to bans in public venues and the rise of hobbyist-developed detection apps. These tools use Bluetooth signals to help people identify nearby smart glasses, though they remain imperfect solutions.

TikTok has reached a settlement regarding COPPA violations, described as one of the largest recoveries in the history of such cases.

Nvidia research reveals that software wrappers or 'harnesses' surrounding AI models are more crucial than the underlying model itself for long-horizon tasks, allowing Claude Opus 5 to score 100% on the ARC-AGI-3 benchmark.