Security News

Cybersecurity news aggregator

🍎
HIGH Attacks SecurityWeek

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

A critical authentication bypass vulnerability (CVE-2026-65400, CVSS 9.8) in macOS Screen Sharing allows remote attackers to gain root access by simply providing a valid username without a password. Affected versions are macOS 14.0 through 14.8.8, 15.0 through 15.7.8, and 26.0 through 26.6.0. Apple has patched the flaw in macOS versions 14.8.9, 15.7.9, and 26.6.1, and immediate patching is critical as active exploitation deploying cryptominers has been observed.
Read Full Article →

Vulnerabilities Recent macOS Screen Sharing Vulnerability Exploited in Attacks Threat actors gained root access to the vulnerable systems and deployed a Monero miner. By Ionut Arghire | August 17, 2026 (4:47 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Threat actors are exploiting a recently patched macOS vulnerability to gain root access and deploy cryptominers. The exploited bug, tracked as CVE-2026-65400, is a high-severity authentication issue in Screen Sharing that allows remote attackers to log in without valid credentials. Apple disclosed the flaw on August 6, when it rolled out fixes in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Roughly a week later, the Dutch National Cyber Security Centrum (NCSC) warned that in-the-wild exploitation has started, fueled by the existence of a public proof-of-concept (PoC) exploit. “The NCSC has received a notification showing that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the internet,” NCSC says. Threat actors have been exploiting the security defect to gain root access to the vulnerable systems and install a Monero miner, it says. Advertisement. Scroll to continue reading. “Apple has improved state management mechanisms to enforce correct validation of login credentials and prevent unauthorized authentication attempts,” NCSC notes. According to AI security firm Calif, the flaw allows a remote attacker to authenticate to a macOS system that has Screen Sharing enabled by simply naming an account. “Naming an account is the one thing the bug needs. It is not much of a barrier. A username is not a secret, and macOS prints them on the login window,” Calif notes. CVE-2026-65400, however, is not the only recently patched vulnerability in screensharingd, the daemon responsible for managing Screen Sharing connections. In late July, Apple patched at least four other issues in it, including three that have CVE identifiers. Reportedly, the fourth, which was silently addressed, was the most severe of them, as it allowed unauthenticated attackers to gain remote code execution as root. According to security researcher osxreverser , the issue could be exploited to take over any macOS with Screen Sharing enabled, as long as the attacker knew its IP address and SIP was disabled. The flaw reportedly did not require user interaction and could allow an attacker to plant a reverse shell and a root crontab through the same connection. On August 8, osxreverser warned that approximately 40,000 internet-accessible macOS systems had Screen Sharing enabled, meaning that they were potentially exposed to attacks. Related: Hackers Exploiting Unpatched GeoServer Zero-Day Related: Adobe Commerce Bug Targeted Immediately After Disclosure Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability Related: Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Hackers Exploiting Unpatched GeoServer Zero-Day AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions Adobe Commerce Bug Targeted Immediately After Disclosure WordPress 7.0.4 Patches Remote Code Execution Vulnerability Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Critical VMware vCenter Vulnerability in Attackers’ Crosshairs Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ Mindgard Raises $30 Million to Protect AI Systems Latest News Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure Fortune 500 Companies Hit in Azure Data Theft Campaign In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities Trivy, Not LiteLLM Behind the 2,500 Org Compromise Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal 1.6 Million Likely Impacted by RingCentral Data Breach Over 1,000 Charities Hit by Beacon CRM Data Breach 14,000 Trezor Customers Impacted by Data Breach at ShipMonk Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move Erika Dean has been appointed Chief Information Security Officer at Tricentis. C1 has named Jeff St. Clair Chief Revenue Officer. John Opala has joined Ralph Lauren as Chief Information Security Officer. More People On The Move Expert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Share this article