Thousands of Leaked AWS Keys Remain Active, Giving Attackers Potential Control of Corporate Cloud Accounts

Cybersecurity officials are warning Mac users about active attacks exploiting a recently patched vulnerability in Apple’s built-in Screen Sharing feature.

The Netherlands’ National Cyber Security Centre (NCSC) has confirmed that the vulnerability is being exploited in the wild. In reported incidents, attackers gained root-level access to compromised Macs and subsequently installed software designed to mine Monero cryptocurrency using the victims’ computing resources.

Critical Authentication Bypass

CVE-2026-65400 affects macOS Screen Sharing, a remote-access feature that allows users to control a Mac from another device over a network. The service relies on the VNC protocol and commonly communicates through TCP port 5900.

The vulnerability is particularly concerning because it can allow an attacker on the network to authenticate to Screen Sharing without possessing valid credentials. Apple describes the issue as an authentication flaw caused by improper state management.

When Screen Sharing is exposed directly to the internet, attackers can scan for vulnerable systems and attempt to exploit the service remotely. Security researchers have reported finding tens of thousands of systems with Screen Sharing services reachable from the public internet, highlighting the potential scale of the threat.

Attackers Turn Compromised Macs Into Mining Machines

According to the Dutch NCSC, the observed attacks followed a similar pattern. Once attackers successfully exploited the Screen Sharing vulnerability, they obtained elevated privileges and installed a Monero cryptocurrency miner.

Cryptojacking malware secretly uses a victim’s processor to perform cryptocurrency-mining operations for the attacker. While the technique does not necessarily involve stealing cryptocurrency wallets or banking credentials, it can significantly consume CPU resources, increase electricity usage, slow down systems and potentially reduce hardware lifespan.

The NCSC has not publicly attributed the attacks to a specific hacking group or disclosed the total number of affected systems. However, the confirmation that the vulnerability is already being weaponized makes the issue considerably more urgent for organizations and individuals running exposed Macs.

Apple Releases Security Update

Apple addressed CVE-2026-65400 in macOS Tahoe 26.6.1, released on August 6, 2026. Apple says the update fixes the authentication problem through improved state management and prevents network attackers from authenticating to Screen Sharing without valid credentials.

The vulnerability was credited to security researcher Alfredo Pesoli, who reported the issue through Bynario Atlas.

The emergence of public exploit information has accelerated concerns because attackers can potentially adapt available technical research into working attacks against unpatched machines.

Internet-Exposed Macs Face the Greatest Risk

The immediate concern is for Macs running vulnerable versions of macOS where Screen Sharing is enabled and accessible from the internet. Systems with TCP port 5900 exposed publicly are particularly attractive targets because attackers can reach the remote-access service directly.

Security experts recommend that users install Apple’s latest security updates as soon as possible. Organizations that do not require Screen Sharing should also consider disabling the feature.

For systems that require remote administration, exposing Screen Sharing directly to the public internet should be avoided where possible. Organizations can instead place remote-access services behind appropriate network controls, such as VPNs or other secure access mechanisms.

What Mac Users Should Do

Mac users and administrators should take several immediate steps:

  • Update macOS to a version containing Apple’s security fix.
  • Disable Screen Sharing if the feature is not required.
  • Check whether TCP port 5900 is exposed to the public internet.
  • Monitor systems for unusually high CPU usage or unexplained performance degradation.
  • Investigate unexpected processes, particularly cryptocurrency-mining software.
  • Review network and authentication logs for suspicious Screen Sharing connections.
  • For enterprise environments, consider restricting remote-access services through firewalls, VPNs or other access-control mechanisms.

The incident demonstrates that even legitimate remote-management features can become dangerous attack surfaces when vulnerabilities are discovered and the services are exposed to the internet.

With attackers already using CVE-2026-65400 to compromise Macs and deploy cryptocurrency miners, security teams should treat the vulnerability as an active threat rather than a theoretical risk. Prompt patching and limiting unnecessary internet-facing services remain the most effective defenses.

Irfan Latif

Irfan Latif