Technology

Dutch Cyber Agency Warns Active macOS Exploits Deploy Crypto Miners via Screen Sharing Flaw

Apple issues urgent fixes across macOS versions as attackers exploit exposed port 5900 to gain root access

Cybersecurity authorities at the Netherlands National Cyber Security Centre have issued a formal alert after receiving reports that an unpatched macOS flaw is actively targeting “multiple systems” across the country. In each documented attack, intruders successfully acquired elevated root access to deploy unauthorized crypto mining software that secretly consumes processor resources.

The underlying vulnerability allows remote adversaries to view a target user’s screen, open local files, and execute arbitrary operations across the victim’s computer. The breach effectively grants attackers the same uninhibited administrative control as if they had physical possession of the machine.

Addressing the threat, Apple has deployed official software updates designed to patch the flaw. While installing the update was previously framed as a proactive measure when the vulnerability remained theoretical, applying the fix has now become an urgent necessity. The security issue affects macOS Tahoe, Sequoia, and Sonoma, with updated builds released across all three versions.

System administrators and users can take additional defensive actions to safeguard their environments. It is possible to disable Apple’s screen sharing feature entirely through the System Settings menu, which successfully cuts off the vulnerability’s entry path. Furthermore, exploits are occurring when network port 5900—the standard port used for Virtual Network Computing protocol traffic—is left exposed to the internet, leading security experts to advise keeping port 5900 closed, particularly while screen sharing.

This active exploitation follows Apple’s initial release of several macOS security patches weeks ago to remediate the vulnerability in its Screen Sharing utility. At that time, cybersecurity researchers had not observed the flaw being leveraged in wild attacks, marking the update as a precautionary “better safe than sorry” distribution. That status shifted following a report from tech outlet Ars Technica, which confirmed that threat groups are now actively using the exploit in the Netherlands.

The incident arrives amid broader risks affecting remote desktop and collaboration applications over recent weeks. Video platform Zoom encountered a similar screen-sharing flaw and subsequently released a patch to remediate the risk. Security teams urge users to remain vigilant and ensure all collaboration tools are fully updated to stay safe out there.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button