{
  "id": 1290679,
  "title": "Hackers exploited macOS Screen Sharing flaw to install Monero miners, Dutch cyber agency says",
  "url": "https://urgent.news/2026/08/16/hackers-exploited-macos-screen-sharing-flaw-to-install-monero-miners",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-16T15:07:00.000Z",
  "source": {
    "name": "The Block",
    "slug": "the-block",
    "url": "https://www.theblock.co/news/defi/2026-08-16-hackers-exploited-macos-screen-sharing-flaw-to-install-monero-miners-dutch-cyber-agency-says-411932"
  },
  "original_language": "en",
  "account": null,
  "summary": "The Dutch National Cyber Security Centre (NCSC-NL) reported that attackers are exploiting a vulnerability in macOS Screen Sharing, tracked as CVE-2026-65400, to compromise Macs with port 5900 exposed to the Internet. According to Tom's Hardware, in every case reported to the agency, attackers obtained root access and installed a Monero cryptocurrency miner.\n\nThe vulnerability, an authentication bypass, was patched by Apple on August 6 in an out-of-band update covering macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The US Cybersecurity and Infrastructure Security Agency (CISA) rated the severity of the vulnerability a critical 9.8/10 on the CVSS scale, as reported by The Block.\n\nNCSC-NL first flagged the vulnerability in an advisory on August 7, urging organizations to update immediately, and revised it on August 12, noting that public proof-of-concept code is now available and that active abuse had been observed on multiple internet-exposed systems.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation",
        "url": "https://urgent.news/2026/08/15/macos-screen-sharing-cve-2026-65400-authentication-bypass-leads-to",
        "published": "2026-08-15T04:23:00.000Z"
      },
      {
        "outlet": "Tom's Hardware",
        "title": "Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks",
        "url": "https://urgent.news/2026/08/16/critical-macos-screen-sharing-flaw-gives-attackers-remote-root-access",
        "published": "2026-08-16T13:00:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}