
macOS Screen Sharing Flaw Exploited for Root Access and Monero Mining
Dutch authorities report active attacks on internet-exposed Macs via CVE-2026-65400. CISA has raised the bug's severity to a critical 9.8.
AfroEuropa Newsroom
AfroEuropa desk
The Netherlands' National Cyber Security Centre (NCSC-NL) has warned that attackers are actively exploiting an authentication bypass in macOS Screen Sharing, tracked as CVE-2026-65400.
In an update issued on August 12, the agency said the flaw is being used to compromise Macs that have port 5900 exposed to the internet. According to the NCSC-NL, every incident reported to it involved attackers gaining root access and installing a Monero cryptocurrency miner, as reported by Tom's Hardware. BleepingComputer noted that the warning followed the emergence of public exploit code.
Apple addressed the vulnerability on August 6 in an out-of-band update covering macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The NCSC-NL first published an advisory on August 7, a day after the patch, urging organizations to update without delay. Its August 12 revision added that public proof-of-concept code was now available and that abuse had been seen on multiple internet-exposed systems.
Keep reading
Comcast Launches Xfinity Shield With WiFi-Based Motion Detection
Comcast's new Xfinity Shield platform uses changes in wireless signals to detect movement inside a home without cameras or dedicated sensors.
Other highlights
Google Pixel 11 Reaches Retail as US Carriers Roll Out Deals
The Pixel 11 series moved from pre-order to full availability on August 20, with US carriers including T-Mobile promoting free handset offers tied to plans and trade-ins.
Follow the storyOne newsletter, two continents
The Bridge brings you the tech, startups, and leaders moving between Africa and Europe in one sharp email each morning. No spam, unsubscribe anytime.










