Cybercriminals have begun actively exploiting a critical vulnerability in Apple's Mac operating system that the company patched only weeks ago, prompting fresh warnings from cybersecurity authorities across Europe. The Netherlands' National Cyber Security Centre has documented multiple cases where attackers leveraged a flaw in the built-in Screen Sharing feature to infiltrate Mac computers connected to the internet, gaining the highest level of system access and covertly installing cryptocurrency-mining software designed to generate illicit revenue at the machines' owners' expense.
The vulnerability, designated CVE-2026-65400, represents a significant escalation from Apple's initial assessment when the flaw first became public knowledge. At that time, the technology giant indicated to media outlets that it had detected no evidence of the weakness being exploited beyond controlled laboratory environments. That assurance has now proven premature. The attacks documented by Dutch cybersecurity officials demonstrate that threat actors have moved with remarkable speed from theoretical proof-of-concept demonstrations to real-world campaigns targeting unpatched systems in production environments across multiple organizations and potentially individual users.
The attackers' choice of Monero as their cryptocurrency of preference reveals a deliberate strategic calculation. Unlike Bitcoin and many other cryptocurrencies that require specialized hardware for efficient mining, Monero is specifically designed to be mined using standard computer processors found in consumer-grade devices. This characteristic transforms compromised Macs into unwitting profit-generating machines, with the processing power and electricity costs absorbed entirely by victims unaware their systems have been compromised. Researchers at cybersecurity firm SentinelOne describe this approach as an attractive vector for criminal operations seeking rapid monetization with minimal technical barriers to implementation.
Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, emphasizes that the cryptocurrency-mining payload visible on infected systems likely represents only the surface layer of a more comprehensive security breach. With the administrative-level access that the vulnerability provides, attackers gain the ability to extract sensitive data including stored passwords, authentication credentials, and cloud service tokens. They can also pivot laterally to connected systems and networks. The Monero miner may serve primarily as a distraction or smokescreen while attackers simultaneously conduct more valuable espionage or data theft operations invisible to system owners and security teams unfamiliar with forensic analysis.
The technical nature of the Screen Sharing flaw amplifies its danger significantly. The feature, which enables remote viewing and control of a Mac from another computer, becomes a critical entry point when exposed to public internet access without authentication or user interaction required for exploitation. A federal cybersecurity assessment has assigned the vulnerability a severity rating of 9.8 out of 10, the near-maximum possible score, reflecting the minimal requirements for successful attack. Most environments are partially protected by default configurations—standard home routers and enterprise firewalls typically block the relevant network ports—but any organization or individual who has intentionally opened these ports for remote administration, or who has failed to properly configure network defenses, faces acute risk.
Apple has issued patches across multiple macOS versions to address this critical weakness. The updates include macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, distributed through the standard Software Update mechanism accessible via System Settings. The company's decision to release these patches outside its normal update schedule signaled the urgency of the threat, a signal that has been validated by the Dutch authorities' discovery of active exploitation. Mac users who have not yet installed these updates face mounting risk as the window of vulnerability remains open, particularly if their devices expose the Screen Sharing port to network accessibility.
For organizations and individual users, the immediate imperative is straightforward: install the available patches without further delay. Users can access updates by navigating to System Settings, selecting General, and then Software Update. Those who do not utilize Screen Sharing can further reduce their exposure surface by disabling the feature entirely through System Settings, General, and Sharing. However, remediation extends beyond simple patching. SentinelOne researchers caution that applying security updates closes the entry vector but does not automatically remove malware or cryptocurrency miners that may already be installed on compromised systems, nor does it undo unauthorized actions attackers may have already completed.
This reality creates a forensic imperative for businesses and technically sophisticated users whose Mac systems had the Screen Sharing feature enabled and internet-accessible prior to applying patches. These systems require immediate investigation to determine whether they were already targeted during the window of vulnerability. Malware persistence mechanisms, including scheduled tasks for cryptocurrency mining, credential harvesting tools, or backdoors enabling future unauthorized access, may continue operating even after patches are installed. Professional incident response services may be necessary to comprehensively identify and eliminate active threats on previously compromised equipment.
The incident reflects a recurring pattern in cybersecurity where publicly disclosed vulnerabilities transition from theoretical demonstrations to active criminal exploitation with striking rapidity. The speed at which threat actors weaponize newly available exploits, automate attacks, and conduct campaigns suggests sophisticated criminal operations with dedicated development resources and financial incentives to monetize access quickly. For Mac users accustomed to perceiving their operating system as inherently more secure than Windows alternatives, the discovery of active exploitation targeting macOS systems challenges long-held assumptions and underscores the reality that no platform enjoys universal immunity from targeted attacks.
Regional implications for Southeast Asian technology users and organizations warrant consideration. While the documented attacks thus far have centered on European targets identified by Dutch authorities, the internet-facing vulnerability exists globally wherever unpatched Macs maintain exposed Screen Sharing ports. Malaysian and regional businesses operating Mac infrastructure, particularly those in technology sectors, financial services, or international operations, should prioritize immediate patch deployment and network security audits. The sophistication evident in this campaign—from targeting a specific vulnerability to deploying cryptocurrency miners—suggests adversaries capable of adapting tactics and potentially expanding targets geographically as awareness of the vulnerability spreads and initial targets become saturated.
