Crypto news

17.08.2026
08:37

A critical vulnerability in macOS opened the path for hidden Monero mining.

social network hacking

An analysis of recent cybersecurity events has revealed a troubling attack vector targeting Mac owners. This involves the exploitation of a vulnerability in the Screen Sharing component, which is part of the macOS operating system. My data, gathered from open sources and technical bulletins, indicates that attackers actively used this flaw to gain full control over devices.

During the attacks, hackers not only stole confidential data but also deployed hidden Monero (XMR) cryptocurrency miners. This approach allows attackers to monetize compromised resources while staying under the radar, since XMR mining does not require significant computing power and is less noticeable to monitoring systems. The exact number of victims and the composition of the criminal groups remain unknown.

The vulnerability, identified as CVE-2026-65400, was officially documented on August 12. The initial risk assessment, assigned by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), was 7.1 points out of 10. However, just two days later, experts revised their findings, raising the severity to 9.8 points, which underscores the seriousness of the threat and the potential ease of its exploitation.

The root of the problem lies in an authorization error in the Screen Sharing function. Under certain conditions, an attacker can gain access to the screen and control of a Mac without entering credentials. Although the feature is disabled by default, many users and administrators enable it for remote work convenience, creating a vast attack surface. Scanning public networks shows that tens of thousands of hosts worldwide are at risk.

Apple responded promptly to the incident, releasing fixes as part of the macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 updates. I strongly recommend that all macOS users immediately install these updates to close the critical flaw.

My comment: This situation is yet another reminder that even ecosystems with strict control, like Apple's, are not immune to serious errors. The growing popularity of hidden mining combined with data theft points to the evolution of cybercrime toward complex attacks, where the main goal is not just to withdraw funds but to gain long-term control over the victim's infrastructure. I recommend not only updating systems but also reconsidering remote access policies, minimizing their use on public networks.