Dutch NCSC warns macOS screen-sharing flaw exploited to install Monero miners
This digest was compiled by AI from multiple sources — links to the originals are below.

The Dutch National Cyber Security Centre warns that a macOS screen-sharing vulnerability tracked as CVE-2026-65400 is being actively exploited, allowing remote attackers to gain root access and install Monero crypto miners when port 5900 is exposed to the internet. Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week, but unpatched systems remain at risk. The current campaign centers on crypto mining, even as security experts warn the flaw could be used for credential theft.
The Vulnerability
Ars Technica reported that the flaw stems from macOS screen-sharing capability and lets remote attackers log in without a password. CVE-2026-65400 carries a severity rating of 7.1 out of 10. An attacker who can reach port 5900 over the internet can execute malicious code and gain full control of a Mac. BleepingComputer reported that public exploit code emerged before the warning.
Exploitation and Impact
The Dutch NCSC observed active abuse in which attackers accessed root privileges and installed Monero miners on compromised Macs. The three macOS versions affected by the vulnerability—Tahoe, Sequoia, and Sonoma—have all received patches. Current attacks focus on cryptocurrency mining, but security experts warn the same flaw could be used for credential theft. Port 5900 remains the primary attack vector for internet-exposed systems.
Patch and Mitigation
Apple shipped patches for macOS Tahoe, Sequoia, and Sonoma last week, according to Ars Technica. The Dutch NCSC and Apple advise users to disable screen sharing when not in use and ensure port 5900 is not exposed to the internet. Safer alternatives include VPN or SSH tunneling for remote connections. Despite the patch, security researchers note that exposed systems can still be compromised if updates are not applied promptly.
What's Next
The next step for administrators is to apply Apple's macOS patches and disable screen sharing on exposed systems. It remains unclear whether attackers will expand beyond Monero mining to credential theft or other malware.
3 sources
Dutch NCSC warns macOS screen-sharing flaw exploited to install Monero miners



