{
  "id": 1272284,
  "title": "Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks",
  "url": "https://urgent.news/2026/08/16/critical-macos-screen-sharing-flaw-gives-attackers-remote-root-access",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-16T13:00:00.000Z",
  "source": {
    "name": "Tom's Hardware",
    "slug": "tom-s-hardware",
    "url": "https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners"
  },
  "original_language": "en",
  "account": "On August 12, the Dutch National Cyber Security Centre (NCSC-NL) alerted that attackers are actively leveraging a macOS Screen Sharing vulnerability (CVE-2026-65400) to compromise Macs with port 5900 exposed to the internet. The attackers gained root access and installed a Monero cryptocurrency miner. Apple released a patch on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. However, CISA increased the vulnerability's severity rating from 7.1 to 9.8 critical on August 14, classifying the attack as potentially automatable. CISA first warned about the vulnerability on August 7, urging organizations to update promptly. The NCSC-NL published the advisory on August 7, but public proof-of-concept code became available on August 12, and active exploitation was observed on multiple internet-exposed systems. Technical details were presented at Black Hat conference last week. The vulnerability allows attackers to authenticate to Screen Sharing without valid credentials, potentially gaining full control over the affected system. Users unable to update immediately can disable Screen Sharing in System Settings > General > Sharing. This is the second Screen Sharing patch in a month, following CVE-2026-43760 fixed in late July releases.",
  "summary": "The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation",
        "url": "https://urgent.news/2026/08/15/macos-screen-sharing-cve-2026-65400-authentication-bypass-leads-to",
        "published": "2026-08-15T04:23:00.000Z"
      },
      {
        "outlet": "The Block",
        "title": "Hackers exploited macOS Screen Sharing flaw to install Monero miners, Dutch cyber agency says",
        "url": "https://urgent.news/2026/08/16/hackers-exploited-macos-screen-sharing-flaw-to-install-monero-miners",
        "published": "2026-08-16T15:07:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}