Code Defence Cyber security

Apple macOS Screen Sharing flaw CVE-2026-65400 actively exploited to install Monero cryptominers

A critical authentication flaw in the native remote desktop service of a major desktop operating system is undergoing active wild exploitation. Threat actors are targeting exposed instances to bypass authentication barriers and deploy unauthorized cryptocurrency mining payloads.

The vulnerability, tracked as CVE-2026-65400 with a CVSS score of 9.8, impacts Apple macOS Screen Sharing components in releases prior to macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The defect involves an authentication state management flaw within the built-in remote management service handler. Network-adjacent or remote attackers targeting open Screen Sharing ports can bypass credential validation checks to establish interactive sessions, launching persistent XMRig Monero cryptomining daemons that consume host compute resources.

Exposing unauthenticated remote desktop services destroys host isolation and operational performance. Unmonitored exploitation allows threat networks to hijack system CPU capacity, establish secondary command-and-control communication channels, and pivot into adjacent enterprise subnets.

– Apply emergency macOS maintenance updates 26.6.1, 15.7.9, or 14.8.9 released by Apple across all desktop and server assets immediately.

– Disable public internet routing to Screen Sharing services, restricting remote access behind authenticated zero trust reverse proxies.

– Inspect host activity logs for unauthorized process creations associated with Monero or XMRig binaries executing under system service profiles.

– Enforce strict local firewall rules to block inbound TCP port 5900 connections originating from untrusted external networks.

Endpoint remote service security relies on continuous state verification and prompt patch installation to ensure remote management services remain completely insulated from unauthenticated access bypasses. #CodeDefence #Apple #macOS #ScreenSharing #AuthBypass #Cryptomining #EndpointSecurity #AppSec
/

Scroll to Top