Apple · Federal Reserve (FED) · The Block
Hackers exploited macOS Screen Sharing flaw to install Monero miners, Dutch cyber agency confirms
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
Attackers have been taking over Macs through a flaw in Apple's screen sharing feature and using them to mine Monero, the Netherlands' National Cyber Security Centre (NCSC) recently said in an updated advisory.
Key facts
- XMR traded at $415.82 on Sunday, up about 3.7% over the past 24 hours, 's Monero Price page
- Federal cybersecurity agency CISA initially rated the flaw 7.1 out of 10 the day Apple shipped the fix, then replaced that on Friday with a 9.8, near the top of the 10-point scale, according
- Apple patched the flaw on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9
- Apple and the NCSC did not immediately respond to The Block's requests for comment
Summary
The NCSC said it received a report of attacks on multiple Macs that were reachable through the internet. Apple patched the flaw on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. Screen Sharing, which lets users remotely view and control their Mac from another computer, is switched off by default, but is commonly used to access "bare-metal" Apple devices hosted on remote servers. "Anybody who leverages Apple's Screen Sharing functionality on any supported macOS version needs to apply the most recent security updates immediately," Huntress researcher Ryan Dowd wrote.