TLDR
- Attackers exploited a macOS Screen Sharing flaw to gain root access and install Monero mining software on internet-facing Macs
- The Dutch National Cyber Security Centre confirmed active exploitation on multiple systems with port 5900 exposed to the internet
- Apple patched the flaw on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9
- CISA upgraded the vulnerability score to 9.8 critical, up from an earlier rating of 7.1
- Changing Screen Sharing passwords does not fix the issue; only Apple’s latest security update does
Attackers exploited a flaw in Apple’s macOS Screen Sharing feature to take over Macs connected to the internet and use them to mine Monero. The Netherlands’ National Cyber Security Centre confirmed the attacks in an updated advisory on Aug. 12.
⚠️ALERT: Critical Apple Screen Sharing flaw exploited to hijack Macs and mine Monero.
The Netherlands’ cyber agency confirms that attackers gained full control of internet-exposed Macs through a simple flaw in Apple’s Screen Sharing feature and installed Monero miners.
Apple… pic.twitter.com/g2VZJGGSaS
— Coin Bureau (@coinbureau) August 17, 2026
In every reported case, the attackers obtained root access and installed Monero mining software on the compromised machines. The Dutch agency did not say how many Macs were affected or name any suspects.
Apple patched the vulnerability, tracked as CVE-2026-65400, on Aug. 6. The fix was included in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
The flaw involves improper state management in the Secure Remote Password authentication process used by macOS Screen Sharing. Security firm Huntress found that an attacker could trick the system into treating an unauthenticated connection as already authenticated, giving them full privileged access.
Because the exploit happens before normal authentication, standard defenses do not work. Changing your Screen Sharing password, disabling VNC authentication or removing user accounts will not stop an attacker from getting in.
Tens of Thousands of Macs Potentially Exposed
Huntress researcher Ryan Dowd ran a Censys search and found tens of thousands of potentially vulnerable hosts. That number reflects Macs exposed to the internet, not confirmed compromises.
The risk is especially high for hosted bare-metal Macs, like Mac minis rented from cloud hosting providers. Some hosting environments automatically enable Screen Sharing on newly set-up machines, leaving them open to attack if Apple’s Aug. 6 patches have not been applied.
The U.S. Cybersecurity and Infrastructure Security Agency initially rated the flaw 7.1 out of 10 when Apple shipped the fix. CISA then raised the score to 9.8 critical on Aug. 14, reflecting no privileges or user interaction required to exploit it.
Why Hackers Chose Monero
Monero has been a recurring target in cryptojacking campaigns. It can be mined using regular computer hardware, unlike Bitcoin which needs specialized rigs. Its private transaction design also makes it harder to trace.
The payoff per machine is limited. The entire Monero network produces around 432 XMR per day, worth roughly $179,000 split among all miners.
Monero traded at around $414 to $415 at the time of reporting, up roughly 1% to 3.7% over 24 hours and about 5% over the past week.
The Dutch NCSC confirmed the exploitation but has not published details about the mining infrastructure, pool addresses or attacker wallets. Further investigation from security teams could reveal how widespread the attacks were before Apple’s fix was released.
Anyone running a Mac with Screen Sharing enabled should install the latest Apple security update immediately.












