
macOS Screen Sharing Flaw Exploited for Root Access and Monero Mining
Dutch authorities report active attacks on internet-exposed Macs via CVE-2026-65400. CISA has raised the bug's severity to a critical 9.8.
AfroEuropa Newsroom
AfroEuropa desk
The Netherlands' National Cyber Security Centre (NCSC-NL) has warned that attackers are actively exploiting an authentication bypass in macOS Screen Sharing, tracked as CVE-2026-65400.
In an update issued on August 12, the agency said the flaw is being used to compromise Macs that have port 5900 exposed to the internet. According to the NCSC-NL, every incident reported to it involved attackers gaining root access and installing a Monero cryptocurrency miner, as reported by Tom's Hardware. BleepingComputer noted that the warning followed the emergence of public exploit code.
Apple addressed the vulnerability on August 6 in an out-of-band update covering macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The NCSC-NL first published an advisory on August 7, a day after the patch, urging organizations to update without delay. Its August 12 revision added that public proof-of-concept code was now available and that abuse had been seen on multiple internet-exposed systems.
Keep reading
Italy's Exein Raises $270 Million for Physical AI Security, Hits $1.7B Valuation
Rome-based Exein has closed a $270 million round at a $1.7 billion valuation, described by its backers as making it Europe's most valuable cybersecurity startup.
Other highlights
Crypto Stocks Fall After Senate Declines to Advance Clarity Act
Shares of Coinbase, Circle and Galaxy dropped after the U.S. Senate failed to move forward a crypto market structure bill.
Follow the storyOne newsletter, two continents
The Bridge brings you the tech, startups, and leaders moving between Africa and Europe in one sharp email each morning. No spam, unsubscribe anytime.










