Analyzing the latest cyber threat data, I discovered an alarming attack vector targeting Mac owners. It involves the exploitation of a vulnerability in the Screen Sharing component, which allows attackers not only to gain full control over the device but also to deploy hidden Monero cryptocurrency miners. This is not a theoretical threat—attacks have already been recorded in real time.

Threat Details and Attack Vector

The issue was identified during monitoring by the Dutch National Cyber Security Centre (NCSC). The essence of the exploit lies in the ability to gain unauthorized access to a Mac via Screen Sharing without any authentication. Once in control, an attacker can steal confidential data and use the victim's computing power to mine Monero while remaining undetected.

The severity of the threat is confirmed by the dynamics of the risk assessment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) initially assigned this vulnerability (CVE-2026-65400) a rating of 7.1 out of 10, but just two days later revised it upward to a critical 9.8 points. Such haste in the revision indicates a high likelihood of active exploitation and a large-scale potential for damage.

Apple's Response and Current Patch Status

Apple responded promptly to the incident by releasing patches as part of updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. However, it is worth noting that the "Screen Sharing" feature, although disabled by default, is often activated by users for convenient remote access, which expands the attack surface. A search via Censys, conducted by Huntress researchers, revealed tens of thousands of potentially vulnerable hosts, making this a widespread issue.

I strongly recommend that all macOS users, especially those who use Screen Sharing, immediately install the latest security updates. Delay here is critical: unlike many other threats, this vector allows an attacker to act completely silently, turning your Mac into a mining tool without your knowledge.

My expert perspective: this situation is yet another reminder that even "closed" ecosystems are vulnerable. In the pursuit of remote access functionality, users often ignore basic hygiene measures. I recommend not only updating but also reconsidering the need for Screen Sharing, restricting its access by IP or disabling it altogether if it is not critical to your tasks.