Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner
NCSC warns of active macOS vulnerability exploitation for cryptocurrency mining.
Intelligence analysis by Qwen 2.5 (3B)

The National Cyber Security Centre (NCSC) alerts about hackers exploiting a macOS authentication bypass flaw in the Screen Sharing feature, leading to Monero miner deployment.
Hackers found a way to trick your Mac into letting them control it over the internet, and they used this to secretly mine Monero coins for themselves.
Analysis
{"#macos-screen-sharing-flaw":"The NCSC's warning underscores a critical flaw in macOS Screen Sharing, which allows remote desktop control over a network using VNC protocol. This vulnerability was fixed by Apple with the release of macOS Tahoe 26.6.1 and earlier.","monero-miner-deployment":"Attackers have successfully deployed Monero miners on systems where port 5900 was exposed to the internet, gaining root access and bypassing authentication mechanisms.","system-updates-needed":"Users are advised to upgrade their macOS system to address CVE-2026-65400 or disable Screen Sharing if not needed. The Blue Report indicates that only 37% of actions are blocked once attackers have valid credentials."}
Key points
- NCSC warns about active macOS vulnerability exploitation for cryptocurrency mining
- Screen Sharing feature in macOS is vulnerable to authentication bypass
- Attackers gained root access and deployed Monero miner on exposed systems
Once systems are updated or Screen Sharing is disabled, security measures will be more effective in preventing unauthorized access and mining attacks.
If attackers manage to exploit this flaw again, they could gain even deeper control over the system, potentially leading to other forms of malicious activity.


