系统之家提供 Windows 系统、Ghost 系统、驱动与常用软件的安全下载及安装教程。 后台管理
📢 欢迎访问系统之家!所有资源均经过安全检测。

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

发布时间:2026-08-17 | 浏览:3
📥 下载地址(文章开头)
软件神器安装一切软件
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner August 14, 2026 The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900. Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases. The flaw allows network-based attackers to gain access without valid credentials. An attacker could use this access to open applications remotely, access files, change security settings, and perform various other actions. In an update to the initial advisory, the Dutch agency said it received a report indicating that the vulnerability is being exploited in the wild in attacks where port 5900 is exposed to the internet. According to the NCSC, the attacker obtained root access to the system and deployed a Monero cryptocurrency miner. “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” reads the Dutch agency's update . “In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.” macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400: macOS Tahoe 26.6.1 macOS Sequoia 15.7.9 macOS Sonoma 14.8.9 These releases improve state management mechanisms to enforce correct credential validation and prevent rogue authentication attempts. Where system updates are not immediately possible, users can use System Settings to disable Screen Sharing (General → Sharing → Screen Sharing) if not needed. NSCS has not shared any details about the reported attacks, when they started, if they extend beyond cryptocurrency mining, or how many systems have been impacted. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Related Articles: N-able warns of N-central auth bypass flaw exploited in attacks Check Point warns of SmartConsole zero-day exploited in attacks Hackers exploit critical auth bypass in Gitea Docker image
📥 下载地址(文章中间)
软件神器安装一切软件
New AmnesiaStealer macOS malware hijacks browser sessions via remote control Max severity SAP Commerce Cloud flaw now targeted in attacks Actively Exploited Authentication Bypass Previous Article Not a member yet? Register Now You may also like: Microsoft confirms GitHub is down worldwide Microsoft confirms GitHub is down worldwide Hackers arrested over €30M bank fraud exploiting service provider flaw Hackers arrested over €30M bank fraud exploiting service provider flaw RingCentral data breach exposed info of 1.6 million accounts RingCentral data breach exposed info of 1.6 million accounts Certighost CVE is new. The privilege behind it isn't. Discover where yours is hiding. Certighost CVE is new. The privilege behind it isn't. Discover where yours is hiding. Stop AI slopsquatting attacks. Secure open source package ingestion before it hits your build. Stop AI slopsquatting attacks. Secure open source package ingestion before it hits your build. Overdue a password health-check? Audit your Active Directory for free Overdue a password health-check? Audit your Active Directory for free Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how. Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how. 91% of AI Apps Appeared in 16 Months. Get Material's OAuth Risk Report 91% of AI Apps Appeared in 16 Months. Get Material's OAuth Risk Report
📥 下载地址(文章结尾)
软件神器安装一切软件