Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Internet-exposed macOS users
Incident: Active exploitation of a critical macOS authentication flaw to deploy Monero miners.
Impact: Full root-level system compromise and unauthorized resource utilization.
Attacker: Unidentified threat actors
Analysis: Attackers are leveraging CVE-2026-65400 to bypass authentication in the Screen Sharing service, specifically targeting systems with port 5900 exposed to the internet. This critical flaw allows for unauthorized root-level access, which is currently being used to deploy cryptocurrency mining software. The incident underscores the rapid weaponization of authentication vulnerabilities in modern operating systems.
Recommendations: Update macOS to versions 26.6.1, 15.7.9, or 14.8.9 immediately.; Disable Screen Sharing in System Settings if remote access is not required.; Block port 5900 at the network perimeter to prevent unauthorized external access.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source