Update your Mac now: Hackers are actively exploiting a critical flaw to mine crypto


The Netherlands’ National Cyber Security Centre says attackers exploited a Screen Sharing flaw on multiple Macs exposed to the Internet. — Unsplash

Hackers are now actively exploiting a Mac vulnerability that Apple patched earlier this month, according to cybersecurity officials in the Netherlands. The news is yet another reminder of the importance of running updated software on your devices.

The Netherlands’ National Cyber Security Centre says attackers exploited a Screen Sharing flaw on multiple Macs exposed to the Internet. In every reported case, they gained root access – the highest level of control over the computer – and installed Monero cryptocurrency-mining software.

The cryptocurrency Monero is particularly suited to this kind of attack because it is designed to be mined using ordinary computer processors. The attackers are effectively turning compromised Macs into cryptocurrency-mining machines at their owners’ expense.

Tom Hegel, a threat researcher at cybersecurity company SentinelOne’s research arm, SentinelLABS, tells Inc that the Monero miner angle was unsurprising: criminals often use newly public exploits to automate attacks and install miners for “immediate, relatively low-friction monetisation.”

He cautioned that mining may not be the only activity. With root access, attackers could also reach files, credentials, cloud tokens, or other systems. “The miner may simply be the most visible payload,” Hegel says.

The exploitation marks a significant shift since the flaw became publicly known. At the time, Apple told Inc it was “not aware of this issue being exploited outside of test environments.”

For Mac users who have not updated, the message is now more urgent: install the patch.

The vulnerability, tracked as CVE-2026-65400, affects Apple’s built-in Screen Sharing feature, which lets another computer remotely view and control a Mac. Apple fixed it in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.

Users can update under System Settings > General > Software Update. Those who do not use Screen Sharing can disable it under System Settings > General > Sharing.

But businesses whose Macs had Screen Sharing enabled and reachable before they were patched should also check whether those systems were already compromised, Hegel says. “Patching closes the vulnerability, but it does not remove malware or undo actions an attacker may already have taken.”

The attacks observed in the Netherlands involved Macs whose Screen Sharing port was reachable from the public Internet. Most home routers and corporate firewalls block those connections by default, so not every Mac is equally exposed.

Still, the flaw can give an attacker powerful access once a vulnerable machine is reachable. A federal assessment now gives it a 9.8 out of 10 critical severity score, indicating that exploitation can occur without credentials or user interaction.

Phil Stokes, a SentinelOne research engineer who specialises in macOS threats, previously told Inc that Apple’s decision to issue the patch outside its normal update cycle already suggested urgency.

“What matters is whether they can reach the Screen Sharing service,” Stokes said. Dutch officials now say attackers have done so. – Inc./Tribune News Service

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Others Also Read