Cybercriminals successfully weaponized a security weakness in Apple’s macOS Screen Sharing functionality to commandeer internet-connected Mac computers and deploy them for Monero cryptocurrency mining operations. The Dutch National Cyber Security Centre validated these attacks in a revised security bulletin issued on August 12.
Across all documented incidents, threat actors successfully acquired root-level system privileges and deployed Monero mining applications on hijacked devices. The Dutch cybersecurity authority declined to specify the total number of compromised Macs or identify potential threat actors.
Apple addressed the security gap, designated as CVE-2026-65400, with patches released on August 6. The remediation was distributed through macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
The vulnerability stems from flawed state management within the Secure Remote Password authentication mechanism employed by macOS Screen Sharing. Cybersecurity firm Huntress discovered that malicious actors could manipulate the system into recognizing an unauthorized connection as pre-authenticated, thereby granting complete elevated access.
Since the exploitation occurs prior to conventional authentication procedures, typical security measures prove ineffective. Resetting Screen Sharing credentials, deactivating VNC authentication, or eliminating user profiles will not prevent unauthorized access.
Huntress security researcher Ryan Dowd conducted a Censys scan that identified tens of thousands of potentially susceptible endpoints. This figure represents internet-exposed Macs, not verified compromises.
The threat level is particularly elevated for cloud-hosted bare-metal Mac infrastructure, such as Mac minis leased from hosting providers. Certain hosting platforms automatically activate Screen Sharing on freshly provisioned machines, creating exposure windows when Apple’s August 6 security updates remain unapplied.
The U.S. Cybersecurity and Infrastructure Security Agency originally assigned the vulnerability a 7.1 severity score when Apple distributed the patch. CISA subsequently escalated the rating to 9.8 critical on August 14, acknowledging that exploitation requires neither elevated privileges nor user interaction.
Monero remains a preferred choice for cryptojacking operations. The cryptocurrency supports mining with standard computing hardware, contrasting with Bitcoin, which demands specialized equipment. Its privacy-focused architecture additionally complicates transaction tracing efforts.
Individual machine profitability remains modest. The complete Monero network generates approximately 432 XMR daily, representing roughly $179,000 distributed across the entire mining ecosystem.
Monero was trading between $414 and $415 during reporting, showing gains of approximately 1% to 3.7% across 24 hours and roughly 5% over the preceding week.
The Dutch NCSC verified active exploitation but withheld specifics regarding mining infrastructure, pool addresses, or attacker wallet identifiers. Ongoing security research may illuminate the attack campaign’s scope before Apple’s remediation became available.
Mac users with Screen Sharing functionality enabled should deploy Apple’s latest security patches without delay.
The post Critical macOS Security Flaw Exploited for Monero Cryptocurrency Mining appeared first on Blockonomi.