Theme:
Light Dark Auto
GeneralPoliticsBusinessTechnologyEnvironmentSportsEntertainment
TECHNOLOGY
Negative Sentiment

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

Read, Watch or Listen

Media Bias Meter
Sources: 21
Left 10%
Center 86%
Right 5%
Sources: 21

Apple has released security updates to patch a critical zero-day vulnerability in its macOS Screen Sharing feature, tracked as CVE-2026-65400. Rated with a CVSS severity score of 9.8 out of 10, the flaw allows unauthenticated remote attackers to obtain root-level access on vulnerable systems. According to advisories from security researcher Alfredo Pesoli and the Dutch National Cyber Security Centre (NCSC-NL), the flaw stems from improper state management within the Secure Remote Password authentication process in the Screen Sharing daemon. Threat actors are actively scanning the internet for exposed systems on default port 5900, bypassing authentication to install unauthorized Monero cryptocurrency miners. Apple addressed the flaw in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Cybersecurity authorities strongly urge administrators and personal users to apply the updates immediately, disable exposed Screen Sharing services, or restrict port 5900 access behind segmented virtual private networks.

Prepared by Jonathan Pierce and reviewed by editorial team.

Timeline of Events

  • On July 12, 2026 researcher Alfredo Pesoli discovered Screen Sharing flaw.
  • On August 2, 2026 Apple developed security patches for supported macOS versions.
  • On August 10, 2026 10:00 AM EST Apple released updates for Tahoe, Sequoia, Sonoma.
  • On August 12, 2026 2:00 PM EST NCSC-NL detected active public port 5900 scans.
  • On August 14, 2026 8:00 AM EST attackers deployed Monero miners on vulnerable Macs.
  • On August 15, 2026 4:00 PM PKT emergency security advisories urged immediate updating.
  • By August 30, 2026 unpatched exposed enterprise Macs risk total network compromise.
  • By September 2026 cyber agencies expect automated botnet attacks to surge.
  • By October 2026 organization compliance audits will mandate port 5900 restrictions.
  • By 2027 Apple will revise authentication state handlers across macOS.

News Intelligence

  • Immediate US impact: Unpatched macOS devices connected directly to internet face immediate takeover.
  • Possible long-term US impact: Widespread unauthorized crypto-mining could compromise enterprise Mac network infrastructure.
  • Most affected groups: Mac users, enterprise IT administrators, network security engineers, remote workers.
  • Reader priority: Prioritize installing official Apple operating system updates over temporary workarounds.
Media Bias
Articles Published:
21
Right Leaning:
1
Left Leaning:
2
Neutral:
18

Explain Framing

Left: Framing emphasizes consumer risk and corporate software security maintenance responsibilities. Center: Framing focuses on technical facts, CVE details, and patch deployment. Right: Framing highlights economic impacts, enterprise infrastructure risks, and cyber threat actors.

Original Source

NCSC-NL published advisory confirming active abuse of macOS port 5900. https://www.ncsc.nl/actueel/advisories/ncsc-2026-0341

Media Bias
Articles Published:
21
Right Leaning:
1
Left Leaning:
2
Neutral:
18
Distribution:
Left 10%, Center 86%, Right 5%
Explain Framing

Left: Framing emphasizes consumer risk and corporate software security maintenance responsibilities. Center: Framing focuses on technical facts, CVE details, and patch deployment. Right: Framing highlights economic impacts, enterprise infrastructure risks, and cyber threat actors.

Original Source

NCSC-NL published advisory confirming active abuse of macOS port 5900. https://www.ncsc.nl/actueel/advisories/ncsc-2026-0341

Coverage of Story:

Related News

Comments

JQJO App
Get JQJO App
Read news faster on our app
GET