Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
macOS Screen Sharing Flaw Exploited for Cryptomining

macOS Screen Sharing Flaw Exploited for Cryptomining

Posted on August 17, 2026 By CWS

Security researchers have identified that a newly patched macOS vulnerability is being exploited by cybercriminals to gain root access and install cryptominers on targeted systems. The flaw, known as CVE-2026-65400, presents a significant authentication problem within the Screen Sharing feature, allowing unauthorized remote logins.

Vulnerability Details and Exploit

Apple addressed this high-severity issue on August 6 with updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. However, the Dutch National Cyber Security Centrum (NCSC) reported active exploitation of the flaw shortly after the patch was released. This rapid exploitation was enabled by the availability of a public proof-of-concept exploit.

The NCSC highlighted that the vulnerability allows threat actors to gain root access and deploy Monero miners on vulnerable systems. The exploitation primarily occurs on computers where port 5900 is open and accessible via the internet.

Apple’s Response and Security Measures

In response to the threat, Apple has enhanced its state management processes to ensure proper validation of login credentials, aiming to prevent unauthorized access attempts. Yet, the simplicity of the attack, which only requires the attacker to know a user’s account name, remains a concern as account names are typically displayed on the login screen.

AI security firm Calif noted that the bug’s exploitation hinges on naming an account, a task made easier by macOS’s default display settings. Despite the patch, the vulnerability’s ease of exploitation underscores the importance of applying updates promptly.

Additional Vulnerabilities and Warnings

This vulnerability is not isolated; in July, Apple addressed several other issues in the screensharingd daemon, one of which was particularly severe, enabling unauthenticated remote code execution. Security expert osxreverser revealed that an estimated 40,000 macOS systems with Screen Sharing enabled were at risk, emphasizing the potential scale of the threat.

The exposed systems could be compromised without user interaction, allowing attackers to establish a reverse shell or manipulate root-level tasks. This highlights the ongoing need for vigilance and regular system updates to mitigate such security risks.

Related vulnerabilities, such as those in Adobe Commerce and WordPress, further illustrate the critical nature of timely patch management to protect against evolving cyber threats.

Security Week News Tags:AI security, Apple, Cryptomining, CVE-2026-65400, Cybersecurity, Exploitation, macOS, NCSC, Patch, root access, screen-sharing, Security, Vulnerability

Post navigation

Previous Post: Evooo1Bot Botnet Exploits Edge Devices with DDoS Attacks
Next Post: Z.ai Launches GLM-5.3 with Enhanced Coding and Security

Related Posts

Joey Melo Discusses AI Hacking Techniques Joey Melo Discusses AI Hacking Techniques Security Week News
Fencing and Pet Company Jewett-Cameron Hit by Ransomware Fencing and Pet Company Jewett-Cameron Hit by Ransomware Security Week News
Connex Credit Union Data Breach Impacts 172,000 People Connex Credit Union Data Breach Impacts 172,000 People Security Week News
Locked Shields 2026: Global Cyber Defense Unites 41 Nations Locked Shields 2026: Global Cyber Defense Unites 41 Nations Security Week News
All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher Security Week News
JetBrains Fixes Major Security Flaw in TeamCity JetBrains Fixes Major Security Flaw in TeamCity Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WordPress Malware Resurfaces with Self-Healing Backdoor
  • AI Impacts Cyber Attack Speed, Fundamentals Remain Key
  • CISA Identifies Critical Flaw in Cisco SD-WAN Manager
  • Zimbra Mail Server Vulnerability Exploited by Hackers
  • Hackers Exploit Zimbra Flaw Before Official Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WordPress Malware Resurfaces with Self-Healing Backdoor
  • AI Impacts Cyber Attack Speed, Fundamentals Remain Key
  • CISA Identifies Critical Flaw in Cisco SD-WAN Manager
  • Zimbra Mail Server Vulnerability Exploited by Hackers
  • Hackers Exploit Zimbra Flaw Before Official Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark