{"id":18534,"date":"2026-08-19T17:44:36","date_gmt":"2026-08-19T17:44:36","guid":{"rendered":"https:\/\/nile1.com\/en\/?p=18534"},"modified":"2026-08-19T17:44:54","modified_gmt":"2026-08-19T17:44:54","slug":"critical-macos-flaw-exploited-in-cryptomining-attacks-triggers-emergency-apple-updates","status":"publish","type":"post","link":"https:\/\/nile1.com\/en\/2026\/08\/19\/critical-macos-flaw-exploited-in-cryptomining-attacks-triggers-emergency-apple-updates\/","title":{"rendered":"Critical macOS Flaw Exploited in Cryptomining Attacks Triggers Emergency Apple Updates"},"content":{"rendered":"<p>Cybercriminals are actively exploiting a critical 9.8-severity authentication vulnerability in Apple macOS to remotely breach Mac computers without valid credentials, prompting emergency operating system updates from Cupertino. The vulnerability, designated as <a href=\"https:\/\/nile1.com\/en\/2026\/08\/17\/apple-patches-macos-authentication-vulnerability-that-allowed-remote-screen-hijacks\/\" class=\"auto-internal-link\" title=\"Apple Patches macOS Authentication Vulnerability That Allowed Remote Screen Hijacks\">CVE-2026-65400<\/a>, allows unauthorized remote entry into systems that have Apple&#8217;s <a href=\"https:\/\/nile1.com\/en\/2026\/08\/17\/apple-patches-macos-authentication-vulnerability-that-allowed-remote-screen-hijacks\/\" class=\"auto-internal-link\" title=\"Apple Patches macOS Authentication Vulnerability That Allowed Remote Screen Hijacks\">screen sharing<\/a> feature turned on.<\/p>\n<p>The security flaw stems from insufficient state management during the operating system&#8217;s authentication process. Under normal execution, macOS rejects remote connection requests that lack valid administrative credentials. However, CVE-2026-65400 allows attackers to bypass credential validation entirely when negotiating connection requests over local or public networks.<\/p>\n<p>The flaw affects <a href=\"https:\/\/nile1.com\/en\/2026\/07\/29\/google-updates-gemini-for-mac-with-system-wide-voice-triggers-and-contextual-reasoning\/\" class=\"auto-internal-link\" title=\"Google Updates Gemini for Mac with System-Wide Voice Triggers and Contextual Reasoning\">macOS Sequoia<\/a>, Sonoma, and Tahoe, and Apple closed it off in versions 15.7.9, 14.8.9, and 26.6.1, respectively. Unknown criminals have been exploiting the PoC to break into &#8220;multiple&#8221; Mac systems through port 5900, which is open when the Screen Sharing feature is set to on.<\/p>\n<p>TCP port 5900 handles network traffic for macOS Screen Sharing using Virtual Network Computing protocols. Security analysis published by the Netherlands&#8217; National Cyber Security Centre (NCSC-NL) rated the flaw at 9.8 on the Common Vulnerability Scoring System scale, citing a remote network attack vector requiring zero elevated permissions or user interaction.<\/p>\n<p>The cyber-criminals have allegedly abused CVE-2026-65400 to gain root access to macOS and install a Monero cryptomining trojan on vulnerable systems. Most likely, things could have turned much worse: working root access means &#8220;game over&#8221; for any native security protections, plus the ability to essentially implant any kind of malicious code on the compromised system.<\/p>\n<p>The zero-day vulnerability was discovered by Alfredo Pesoli, co-founder and chief executive officer of cybersecurity firm Bynario. Pesoli uncovered the authentication bypass using Atlas, an automated security analysis solution developed by Bynario to detect high-impact software logic flaws.<\/p>\n<p>Apple confirmed the fix across individual support bulletins for macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, giving credit to Pesoli for reporting the issue. Technical details and patch downloads are available through <a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" target=\"_blank\" rel=\"noopener noreferrer\">Apple Security Updates<\/a>. NCSC-NL confirmed that evidence of a functional proof-of-concept exploit was detected spreading across public network channels one week before Apple issued the patch.<\/p>\n<div class=\"related-news-box\">\n<h3 class=\"related-news-title\">Read also:<\/h3>\n<ul class=\"related_news_list\">\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/19\/google-pixel-11-upgrades-camera-array-with-30x-super-zoom-and-new-software-features\/\">Google Pixel 11 Upgrades Camera Array With 30x Super Zoom and New Software Features<\/a><\/li>\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/19\/meta-launches-standalone-meta-ai-desktop-app-for-mac-to-power-business-workflows\/\">Meta Launches Standalone Meta AI Desktop App for Mac to Power Business Workflows<\/a><\/li>\n<li><a href=\"https:\/\/nile1.com\/en\/2026\/08\/19\/uk-and-google-launch-operation-blue-skies-to-test-ai-transatlantic-flight-rerouting\/\">UK and Google Launch Operation Blue Skies to Test AI Transatlantic Flight Rerouting<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals are actively exploiting a critical 9.8-severity authentication vulnerability in Apple macOS to remotely breach Mac computers without valid credentials, prompting emergency operating system updates from Cupertino. The vulnerability, designated as CVE-2026-65400, allows unauthorized remote entry into systems that have Apple&#8217;s screen sharing feature turned on. The security flaw stems from insufficient state management during &hellip;<\/p>\n","protected":false},"author":1,"featured_media":18536,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[5],"tags":[16758,19193,13784,20198,20199,13070],"class_list":["post-18534","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-alfredo-pesoli","tag-cve-2026-65400","tag-macos-sequoia","tag-monero-cryptomining-trojan","tag-ncsc-nl","tag-screen-sharing"],"_links":{"self":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/18534","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/comments?post=18534"}],"version-history":[{"count":2,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/18534\/revisions"}],"predecessor-version":[{"id":18537,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/posts\/18534\/revisions\/18537"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media\/18536"}],"wp:attachment":[{"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/media?parent=18534"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/categories?post=18534"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nile1.com\/en\/wp-json\/wp\/v2\/tags?post=18534"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}