Hackers Actively Exploiting Patched macOS Screen Sharing Vulnerability (CVE-2026-65400) to Install Cryptominers
The Netherlands' National Cyber Security Centre (NCSC) has issued a warning that a recently patched macOS security flaw, CVE-2026-65400, is being actively exploited. Attackers are bypassing authentication to gain root access and install Monero cryptominers on systems where port 5900 is internet-accessible. Apple released patches for this authentication bypass vulnerability in macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1) on August 6, 2026.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai