Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation

macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation 1. Basic Information Severity: Critical Title: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner Source: BleepingComputer Published Date: 2026-08-14 Updated Date: N/A Original Article: Original Article Related Sources: Apple Security , NCSC-NL NCSC-2026-0280 Malware: Monero…

An authentication vulnerability in macOS Screen Sharing, CVE-2026-65400, has been exploited by hackers to gain root access and install a Monero cryptocurrency miner. This flaw allows attackers to connect to the Screen Sharing service from the internet and authenticate without valid credentials. Once authenticated, they can launch applications, access files, and modify security settings.

In some cases, attackers have managed to obtain root access. To mitigate this risk, it is recommended to update macOS to the latest versions (Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9, or later), disable Screen Sharing if not needed, block TCP/5900 from the internet, and monitor for suspicious activities like root processes and Monero miner installations.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix

AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix 1. Basic Information Severity: High Article Title: AmnesiaStealer: a multi-stage Rust-based macOS infostealer that…

  • AmnesiaStealer is macOS-specific infostealer targeting Chromium browsers
  • Distributed via fake GitHub ClickFix page tricking users into executing shell script
  • Steals login passwords, Keychain data, documents, browser info using CDP control

SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE

SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE 1. Basic Information Severity: Critical Article Title: Max severity SAP Commerce Cloud flaw now targeted in attacks…

  • Critical flaw CVE-2026-58231 allows unauthenticated RCE in SAP Commerce Cloud.
  • Active exploit attempts confirmed three days after security patch release.
  • Potential risk of compromised systems due to numerous associated IP addresses.

More from Saturday 15 August →