
macOS Screen Sharing Flaw Exploited for Root Access and Monero Mining
Dutch authorities report active attacks on internet-exposed Macs via CVE-2026-65400. CISA has raised the bug's severity to a critical 9.8.
AfroEuropa Newsroom
AfroEuropa desk
The Netherlands' National Cyber Security Centre (NCSC-NL) has warned that attackers are actively exploiting an authentication bypass in macOS Screen Sharing, tracked as CVE-2026-65400.
In an update issued on August 12, the agency said the flaw is being used to compromise Macs that have port 5900 exposed to the internet. According to the NCSC-NL, every incident reported to it involved attackers gaining root access and installing a Monero cryptocurrency miner, as reported by Tom's Hardware. BleepingComputer noted that the warning followed the emergence of public exploit code.
Apple addressed the vulnerability on August 6 in an out-of-band update covering macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The NCSC-NL first published an advisory on August 7, a day after the patch, urging organizations to update without delay. Its August 12 revision added that public proof-of-concept code was now available and that abuse had been seen on multiple internet-exposed systems.
Keep reading
Iranian National Extradited From Montenegro Over University Hacking Campaign
An Iranian-Turkish man accused of involvement in a years-long hacking operation targeting universities worldwide has been extradited to the United States.
Other highlights
Modder Adds NVIDIA Pascal GPU Support to Windows XP
A modded driver called Forceware 382.69 brings GeForce GTX 10-series cards, including the TITAN Xp, to 32-bit Windows XP.
Follow the storyOne newsletter, two continents
The Bridge brings you the tech, startups, and leaders moving between Africa and Europe in one sharp email each morning. No spam, unsubscribe anytime.










