Hackers took advantage of Apple's macOS screen sharing vulnerability to gain root privileges on the exposed Mac and install Monero mining software.
The Dutch National Cyber Security Center released a report on August 12 saying that it has received multiple attacks on Mac devices that are actively exploiting the vulnerability. By gaining root privileges and installing Monero (XMR) mining software, the attacker exposed the screen sharing service through port 5900.
Vulnerability details
The vulnerability number is CVE-2026-65400, and the CVSS severity score is 7.1. The root cause lies in a state management flaw in the screen sharing authentication process, which can be exploited by attackers without a valid password. Apple has strengthened verification checks on August 6 and released fixes for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 versions. The Dutch National Cyber Security Center pointed out that public proof-of-concept codes have begun to circulate, lowering the threshold for attackers to target systems that still expose screen-sharing services to the Internet. Unrepaired Mac devices are still at risk.
Monero mining hijacking risk
Such attacks are crypto-hijacking operations, in which attackers use other people's computing resources to mine cryptocurrency while retaining the benefits generated by the hijacked hardware, while the costs are borne by the victim. Monero remains attractive to such abuses because of its privacy characteristics, which make fund transfers more difficult to track than transactions on transparent blockchain. This provides attackers with a way to turn continued access to hijacked hardware into hard-to-track mining revenue.
Bitdefender recently discovered that pirated copies of the Odyssey contained Lumma Stealer malware; other reported attacks used fake CAPTCHA pages, SparkKitty mobile apps, game-themed wallpapers, and tampered Python packages. Some attacks also route malicious pages through BNB Chain. Attack methods are constantly changing.
Crypto-hijacking has repeatedly focused on Monero because attackers can spread mining across numerous hijacked devices without having to steal funds directly from the victim's wallets. Although the entry points are different, the underlying pattern is the same: hijacking the hardware, consuming its resources, and directing mining proceeds to addresses controlled by the attacker.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
XMR