Apple urgently fixes a macOS screen sharing bug, revealing that Macs have been used for cryptocurrency mining
Comparatively, according to The Hacker News, the Dutch National Cyber Security Center (NCSC) warned that a recently fixed serious authentication flaw (CVE-2026-65400, CVSS score 9.8) in Apple's macOS screen sharing component has been exploited in the wild, and attackers can access Macs exposed to the Internet (port 5900) without valid credentials and implant an entry-level Bitcoin mining program. Apple fixed the vulnerability with the macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 emergency update on August 6 to strengthen credential verification through improved state management. NCSC confirmed that in multiple attacks, attackers have obtained root privileges and deployed mining software. Security researcher @osxreverser revealed another pre-authentication vulnerability in the same component (also fixed in 26.6), which only requires the target IP to bypass password authentication and can be exploited without a username. According to Calif, the researchers used AI to develop a usable attack program with two vulnerabilities in just 4 hours, showing that AI is drastically shortening the time from finding the vulnerability to developing the attack code. Users are advised to update the system immediately, and turn off the screen sharing function if the update is not possible. This article is sponsored by GENG, Build Your Fortune on GENG (https://geng.one)



