Key Takeaways
Hackers are turning vulnerable Macs into Monero mining machines by exploiting a critical flaw in Apple’s built-in Screen Sharing feature.
The vulnerability, tracked as CVE-2026-65400, allows an attacker to authenticate to Screen Sharing without valid credentials. Apple released fixes on Aug. 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
LATEST: 🚨 Hackers exploited a critical flaw in Apple's Screen Sharing feature to install Monero miners on internet-exposed Macs, says the Netherlands’ National Cyber Security Centre. pic.twitter.com/R6J5eYhSCh
— CoinMarketCap (@CoinMarketCap) August 17, 2026
Apple described the bug as an authentication problem caused by flawed state management. What initially appeared to be another macOS security patch has since become more urgent as evidence of real-world attacks has surfaced.
+81
Bitcoin
Ethereum
Tether
Build'N'Build
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Monero
Stellar
Cosmos
Filecoin
Ethereum Classic
Aptos
Immutable
Unstoppable Ecosystem Token
Arbitrum
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
THORChain
Stacks
Arweave
Sui
Uniswap
Pepe
Ondo
Mantle
Bittensor
Kaspa
Celestia
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Bonk
Flare
Sei
JITO
JasmyCoin
PancakeSwap
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Algorand
Flow
Curve DAO Token
MultiversX
Zcash
Basic Attention Token
Enjin Coin
Ethena
Hedera Hashgraph
VeChain
Conflux Network
XDC Network
Tether Gold
Bitget Token
Polygon Ecosystem Token
Pi Network
OKB
+76
Bitcoin
Ethereum
Tether
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polygon Matic
Polkadot
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Stellar
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render
The Graph
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
Sui
Conflux Network
Lido Staked ETH
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
Bonk
Tether Gold
JITO
JasmyCoin
Core
Floki Inu
Ethereum Name Service
SushiSwap
1inch Network
Tezos
Algorand
Flow
Trust Wallet Token
Curve DAO Token
MultiversX
Basic Attention Token
Enjin Coin
Ethena
Ethena Staked USDe
Build'N'Build
Kava.io
Celestia
Sei
IOTA
Frax
+217
Bitcoin
Ethereum
Tether
Build'N'Build
USD Coin
Solana
Ripple
Dogecoin
Cardano
Toncoin
Shiba Inu
Avalanche
TRON
Chainlink
Polkadot
Polygon Matic
Wrapped Bitcoin
Litecoin
Dai
NEAR Protocol
Bitcoin Cash
Monero
Stellar
Cosmos
Filecoin
Ethereum Classic
Aptos
Hedera Hashgraph
Immutable
Optimism
Arbitrum
VeChain
The Sandbox
Decentraland
Axie Infinity
Injective Protocol
Render Token
The Graph
Maker
Aave
Chiliz
Helium
PAX Gold
Compound
Lido DAO Token
THORChain
Stacks
Arweave
Sui
Conflux Network
Lido Staked ETH
Bitget Token
Wrapped Ethereum
OKB
Uniswap
Pepe
Ondo
Mantle
First Digital USD
Bittensor
Kaspa
Celestia
XDC Network
Artificial Superintelligence Alliance
Jupiter
Quant
Worldcoin
PayPal USD
Bonk
Flare
Tether Gold
Sei
JITO
JasmyCoin
PancakeSwap
Core
Floki Inu
Ethereum Name Service
SushiSwap
Kava.io
1inch Network
Tezos
Algorand
Flow
Trust Wallet Token
Curve DAO Token
KuCoin Token
MultiversX
Gitcoin
Zcash
IOTA
Basic Attention Token
Frax
Ethena
Ethena USDe
Fasttoken
Pi Network
SATS
Adventure Gold
Audius
Alchemy Pay
Arkham
API3
Bounce Token
Altlayer
Aergo
Amp
Aevo
ARPA Chain
Astar
Ark
Ankr
AirSwap
Alpaca Finance
Blur
Badger DAO
Bancor
BakeryToken
Biconomy
Chromia
Celer Network
Celo
Shentu
Civic
Convex Finance
Cartesi
Cyber
COTI
DigiByte
DIA
ether.fi
FUNToken
FLUX
Firo
Ampleforth
Golem
GMX
Gnosis
Moonbeam
Holo
IoTex
ICON
Illuvium
JUST
Kadena
Liquity
Livepeer
Lisk
Memecoin
Manta Network
Treasure
Mask Network
MetisDAO
Origin Protocol
ORDI
Ontology
Osmosis
Powerledger
Phala Network
Pendle
Portal
Pyth Network
ConstitutionDAO
Polkastarter
Qtum
iExec RLC
Rocket Pool
Reserve Rights
Ronin
Ravencoin
Starknet
Storj
Status
Spell Token
Sun (New)
SuperVerse
Toko Token
Theta Fuel
Tellor
Tensor
LayerZero
Usual
Eigenlayer
Hamster Kombat
Catizen
Berachain
KAITO
Pudgy Penguins
Solayer
Bio Protocol
ChainGPT
Cookie DAO
Solv Protocol
Alchemix
Bitcoin SV
Movement
DeXe
Binance Staked SOL
Nexo
Wrapped eETH
Hyperliquid
Casper
Zilliqa
Secret
Nervos Network
TrueUSD
BitTorrent
Mina
Dash
STEPN
Gemini Dollar
UNUS SED LEO
Synthetix
APEcoin
Gala
Theta Network
Fantom
Cronos
Internet Computer
Binance USD
The Netherlands’ National Cyber Security Centre said on Aug. 12 that it had received reports of the vulnerability being exploited across multiple systems where port 5900, used by Screen Sharing, was exposed to the internet.
In every case reported to the agency, attackers gained root access and installed a Monero cryptocurrency miner. Public proof-of-concept code is also available, increasing the risk that more attackers could reproduce the exploit.
Root access gives an attacker extensive control over a Mac. In the attacks identified so far, that control was used for cryptojacking, where a victim’s computing power is quietly redirected to mine cryptocurrency for someone else.
Security firm Huntress found that CVE-2026-65400 affects the Secure Remote Password authentication process used by Screen Sharing. A flaw in the process can cause an unauthenticated connection to be treated as authenticated, allowing malicious code to run without the attacker first logging into the machine.
Hosted Macs may be especially exposed because remote-access services such as Screen Sharing are more commonly enabled on machines used for remote workloads. Huntress said internet scans show tens of thousands of potentially exposed systems.
The vulnerability’s risk rating has also climbed sharply.
CISA now assigns CVE-2026-65400 a 9.8 critical CVSS score, with the assessment showing that exploitation requires no prior privileges or user interaction and can result in major confidentiality, integrity and availability losses.
Mac users running Screen Sharing should update to Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9.
For users who cannot update immediately, disabling Screen Sharing removes the exposed service. Changing a Screen Sharing password alone is not enough because the vulnerability can be exploited before normal authentication takes place.
So far, authorities have not disclosed how many Macs have been compromised or how much Monero attackers have mined through infected machines.
Dr. Guneet Kaur is a senior editor at CCN.com and a Science Fellow at Exponential Science. She is a fintech and blockchain expert with extensive experience in digital finance education, blockchain ecosystems, and cryptocurrency markets. She has worked with global media such as Cointelegraph, as well as education and blockchain platforms, to design and lead strategic content and learning initiatives. As an educator and assessor for top-tier executive programs, she bridges real-world fintech trends with academic insight.
Dr. Kaur is also a published researcher and peer reviewer across fintech and data science journals, including Financial Innovation Journal and International Journal of Big Data Intelligence and Applications. Her work spans data-driven analysis, Web3 innovation, and technical content development. With a strong foundation in both industry and academia, she translates complex financial technologies into practical applications, empowering learners, professionals, and institutions across the rapidly evolving digital finance landscape.
You’re All Set!
Thanks for signing up. We’ll be in touch soon with the latest insights.
