The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

macOS Screen Sharing Vulnerability CVE-2026-65400 Fuels Monero Miner Campaign

The Perimeter Desk
2026-08-17
# macOS Screen Sharing Vulnerability CVE-2026-65400 Fuels Monero Miner Campaign The current consensus on the wire is simple: Apple has a critical hole in its armor. The discovery of CVE-2026-65400, an authentication vulnerability in macOS Screen Sharing that grants root access, is being framed as a systemic failure of Apple's security posture. Because it’s high-severity and actively exploited in the wild, the narrative suggests we're facing a crisis for every Mac user. The logic holds that if an attacker can bypass authentication and land directly at the root level, the "walled garden" hasn't just been breached—it's been demolished. That would be true if this were a targeted campaign by a sophisticated actor. But look at what’s actually being installed on these machines: Monero miners. Criminals aren't using root access to exfiltrate corporate secrets or pivot into secure enclaves. They're using it to hijack CPU cycles for cryptocurrency. This isn't an APT operation; it's a digital scavenger hunt. The attackers aren't hunting Macs specifically—they're hunting any IP address that has left its VNC port wide open to the public internet. The "catastrophe" here isn't the vulnerability. It's the human decision to expose a remote management tool directly to the web. We've seen this pattern before. In 2017, the WannaCry outbreak didn't happen because SMB was inherently broken; it happened because thousands of organizations left port 445 open to the world. The parallel is exact. The software has a flaw, yes, but the risk only becomes an incident when someone decides that the convenience of not using a VPN outweighs the basic rule of network hygiene. Apple's statement will likely shift from "we are investigating" to "users should ensure their systems are updated," effectively moving the goalposts from a product failure to a user maintenance issue. It's a classic pivot. By focusing on the patch, they avoid talking about why their default Screen Sharing implementation is so enticingly easy to misconfigure. The real question is: who in your organization decided that avoiding a VPN was worth the risk of giving root access to any Monero-hungry bot on the internet? If we treat this as a "Apple failure" story, we ignore the human factor. The incentive for the admin is laziness. Setting up a secure gateway or a Zero Trust tunnel takes effort and budget. Opening a port in the firewall takes ten seconds. When that admin logs into their Mac from a hotel in Lisbon without having to toggle a single switch, they feel like they've won. They haven't. They've just subsidized a miner's electricity bill with their company's hardware. The second-order effect here is the signal this sends to opportunistic attackers. Once a botnet identifies a cluster of internet-exposed Macs, those machines become high-value targets for more than just miners. A compromised Mac with root access isn't just a heater; it's a trusted node inside a corporate network. If an attacker can land on a developer's MacBook that has SSH keys to a production environment, the Monero miner is just the loud distraction while they quietly clone the git repos. Compare this to the actual heavy lifting happening elsewhere this week. While we fret over miners on Macs, TheHatman is selling millions of records stolen from Azure tenants belonging to Fortune 500 companies like McDonald's and Vodafone. Meanwhile, in Poland, a breach at MyDr has potentially exposed the personal information of 19 million people. Those are systemic failures of identity management and supply chain security. The macOS flaw, by contrast, is a failure of common sense. Who benefits from the hype around CVE-2026-65400? The vendors selling "modern" remote access tools and MDR services. They love it when a high-severity CVE hits the news because it allows them to tell you that your current setup is obsolete. It turns a conversation about basic firewall rules into a sales pitch for a new platform. But who benefits if we keep believing this is just an "Apple problem"? The attackers do. As long as the conversation stays focused on the patch and not the port, admins will continue to update their software while leaving the front door wide open. They'll apply the fix, wait three months for the next zero-day, and then act surprised when the CPU spikes again. If we want to stop this, we have to stop praising "fast patching" as the primary defense. Patching is a reactive habit. Network segmentation is a strategy. One thing will tell me if the narrative is shifting: watch the lists of exposed ports on Shodan. If those numbers don't drop, it means we've once again chosen the comfort of the patch over the discipline of the perimeter. We're just swapping one version of a broken door for another, wondering why the house still feels drafty.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. Recent macOS Screen Sharing Vulnerability Exploited in Attacks SecurityWeek
  2. ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More The Hacker News
  3. Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure SecurityWeek
  4. Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware The Hacker News
  5. SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch The Hacker News
  6. Apple Screen Sharing Security, (Mon, Aug 17th) SANS ISC
  7. GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE The Hacker News
  8. Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner The Hacker News

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.