Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
CISA rerates macOS Screen Sharing flaw to 9.8 after Monero-mining attacks

CISA rerates macOS Screen Sharing flaw to 9.8 after Monero-mining attacks

CryptopolitanCryptopolitan2026/08/17 14:09
By:Cryptopolitan

CISA upgraded the severity score for a macOS Screen Sharing vulnerability to a critical 9.8 out of 10 on Friday.

Dutch investigators have reported attackers gaining root control of internet-exposed Macs and quietly loading Monero mining software.

From 7.1 to 9.8 in a week

When Apple shipped its fix, CISA listed the bug, tracked as CVE-2026-65400, at 7.1 in the National Vulnerability Database. The agency changed it to 9.8, near the top of the CVSS scale.

The Netherlands’ National Cyber Security Centre took a similar approach. An update on August 12 revised an initial advisory to say that public proof-of-concept code was in circulation and that active abuse had been confirmed.

As of Friday, the flaw had not been included in a federal catalog of known attacked vulnerabilities maintained by the Cybersecurity and Infrastructure Security Agency. Apple’s own CVE record with the Dutch agency still had the older 7.1 rating.

The vulnerability is due to the way Screen Sharing handles authentication. The security company Huntress traced it to a flaw in the service’s use of Secure Remote Password, the protocol used to verify a user’s identity before granting access.

Huntress says the practical effect is that the Mac thinks the outsider has signed in already. The failure occurs prior to any password verification. Resetting or deleting Screen Sharing passwords doesn’t shut the door.

“Anybody who leverages Apple’s Screen Sharing functionality on any supported macOS version needs to apply the most recent security updates immediately,” Huntress researcher Ryan Dowd wrote.

Apple delivered that fix in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 6.

Tens of thousands of rented Macs in range

The NCSC found that victim machines were totally compromised. In each case examined by the researchers, the attacker accessed the system via port 5900, the default Screen Sharing port that remained exposed to the internet.

They then escalated to root privileges and deployed a Monero (XMR) cryptocurrency miner. The Dutch agency did not give the number of systems affected or name a suspect.

Screen Sharing is disabled by default. However, it is a standard tool for working with “bare-metal” Macs, which are physical Apple hardware rented and run inside remote data centers, where much of the exposure is concentrated.

With the internet-scanning tool Censys, Dowd said he found “tens of thousands of potentially vulnerable hosts.” Many, Huntress says, are machines rented by the hour from hosting services.

Cryptopolitan reported on the Reaper malware that hijacks Script Editor to drain wallets and fake macOS troubleshooting posts that lead victims to paste malicious Terminal commands.

Cryptojacking, stealing computing power to turn into coins, has long been a Monero activity. Unlike specialist rigs, Monero coins can be mined on normal CPUs, and its transactions are private by design.

The return per hijacked Mac is small. Monday’s price valued the about 432 XMR a day minted by the Monero network at ~$179,000, distributed across all the miners. XMR was trading at $413.47 on Monday, up about 0.9% over 24 hours.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Wall Street giants’ trading operations show a tale of two extremes: JPMorgan (JPM.US) expects a surge in Q3 performance, while Bank of America (BAC.US) warns of a slowdown

JPMorgan predicts that trading and investment banking income will see double-digit growth in Q3, triggering a rebound in its stock price. Previously, Bank of America warned of flat revenue due to a pullback in financing, leading to a sell-off in the sector.

智通财经2026/09/15 23:26
Wall Street giants’ trading operations show a tale of two extremes: JPMorgan (JPM.US) expects a surge in Q3 performance, while Bank of America (BAC.US) warns of a slowdown

Trillion-dollar defense budget in sight, Guggenheim strongly recommends defense stocks, L3Harris Technologies (LHX.US) is the top large-cap pick

Guggenheim Securities recently initiated coverage of 22 aerospace and defense companies, with an overall positive outlook on defense contractors and aircraft manufacturers, but a cautious attitude toward commercial aviation aftermarket suppliers.

智通财经2026/09/15 23:26
Trillion-dollar defense budget in sight, Guggenheim strongly recommends defense stocks, L3Harris Technologies (LHX.US) is the top large-cap pick

Japan Reportedly Plans to Double Defense Spending to 3.5% of GDP, Ministry of Defense Denies, Yet Japanese Bond Yields Hit 30-Year High

According to reports, Japanese defense officials have expressed their willingness to significantly increase defense spending during meetings with the United States. One proposal is to raise defense spending to 3.5% of GDP within ten years, while another, lower target is 3%. Japanese officials previously stated that this fiscal year's defense and related expenditures are approximately $68.8 billion, equivalent to about 1.9% of Japan's nominal GDP in 2022.

华尔街见闻2026/09/15 22:46