Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple and a Hacker's Future

My computer got compromised by a hacker who exploited a critical macOS vulnerability. Dutch officials have warned that this high-severity flaw, tracked as CVE-2026-65400, is actively being exploited on multiple machines with internet-accessible port 5900. Attackers can execute malicious code, access root, and install Monero crypto miners.

Apple patched the vulnerability last week for macOS Tahoe, Sequoia, and Sonoma. The weakness stems from a bug in the macOS screen sharing feature, which allows remote parties to view the screen and control the keyboard and mouse while a system is on.

The vulnerability became public at Black Hat security conference. Apple said CVE-2026-65400 "may" enable an attacker without credentials to gain access to a Mac. Apple credited security firm Bynario for reporting the issue.

In my case, the always-on Mac Mini running only Claude and Codex saved me from potential disaster. I built an agent, Gecko, to track projects and gather information. It caught the malware by monitoring interactions and stopping commands when I invoked Claude. I used Claude to identify when the malware accessed the system for exactly four seconds, created a future detection tool, and wiped the Mac Mini.

Apple is wary of AI agents having full disk access on Macs, as the company released a developer note warning about the risks of granting such extensive permissions. I am concerned about the future implications of Apple's solution, but the Mac Mini's headless, always-on nature makes it an ideal host for my persistent agent, providing crucial protection against this vulnerability.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at stratechery.com →

More in Tech

I Wanted a Better Way to Discover New Products, So I Built LaunchStall

There are a lot of great products being built by indie hackers, developers, and small teams. The problem isn't always building the product. The problem is getting people to discover it.

  • LaunchStall aims to improve product discovery by limiting weekly editions to 10 launches.
  • Users can upvote, comment, save, and build a streak of discoveries on the platform.
  • Paid products receive verification and priority placement, but ranking is based solely on upvotes.

Every app on your Mac is talking to the internet - I built a map of it (zero telemetry)

Your Mac makes hundreds of outbound connections every hour — updaters, analytics SDKs, crash reporters, CDNs. None of it is visible unless you go looking. lsof -i gives you a wall of IPs.

  • Snitch visualizes all outbound connections from Mac apps to the internet
  • Connections are grouped by process and displayed on a live graph
  • Privacy-focused tool monitors only local connections (127.0.0.1)

More from Monday 5 October →