Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Hackers Exploit Apple Screen Sharing Flaw to Mine Monero on Macs

US cyber authorities raised the flaw's severity score to 9.8 out of 10 on August 14, after Dutch officials confirmed attacks were already under way.

Written By Dhara Chavda
Edited by Divya Mistry
Published 2026-08-17
Make The Crypto Times preferred on GoogleGoogle
Hackers Exploit Apple Screen Sharing Flaw to Mine Monero on Macs

Key Highlights

  • Attackers are using a macOS flaw to install Monero mining software on Macs.
  • Every case reported to Dutch authorities ended in full administrator access.
  • US authorities raised the flaw’s severity score from 7.1 to 9.8 on August 14.

Attackers are exploiting a flaw in Apple’s Screen Sharing feature to seize root access—full administrator control—of Macs reachable over the internet and using it to install software that mines Monero.

US cyber authorities raised the flaw’s severity score to 9.8 out of 10 on August 14, after Dutch officials confirmed attacks were already under way.

Attackers are breaking into Macs over the internet and installing software that mines Monero, using a flaw in Apple’s Screen Sharing feature that the company patched on August 6.

Every Reported Case Ended the Same Way

The Netherlands’ National Cyber Security Centre said that it had received a report of the flaw being actively abused on multiple systems. In every case, attackers obtained root access and installed a Monero mining program.

All the affected systems had port 5900 reachable from the internet. That is the network port Apple’s screen sharing uses, and leaving it open to the public internet is what allowed attackers to reach the vulnerable feature from outside.

The agency did not say how many machines were affected, when the attacks began, or who was behind them.

Why Attackers Choose Monero

Mining is the process of running calculations that verify transactions on a blockchain in exchange for newly created coins. Installing mining software on someone else’s computer without permission is known as cryptojacking. The victim pays the electricity bill and loses processing power; the attacker keeps the coins.

Monero is designed to obscure the sender, receiver, and amount of every transaction, which makes proceeds harder to trace than Bitcoin. It can also be mined efficiently on ordinary computer processors rather than specialist hardware, which makes hijacked laptops and desktops worth using.

Severity Score Raised After Attacks Began

CISA first scored it 7.1 out of 10 on August 6, assessing that an attacker would need some level of access to the machine. On August 14 the agency replaced that assessment with one requiring no access at all and granting complete compromise of the system, raising the score to 9.8. A separate record the following day changed its assessment of whether the attack can be automated from no to yes.

The agency’s record still lists exploitation as “none,” despite the Dutch advisory published two days earlier. NIST’s own National Vulnerability Database has not issued a score for the flaw. Both entries are visible in the change history on the NVD listing.

Apple described the problem as an authentication issue that it addressed with improved state management. In plain terms, the feature could be tricked into treating a stranger as a logged-in user. Apple credited security researcher Alfredo Pesoli of Bynario Atlas with reporting it.

The Dutch advisory also noted on August 12 that the working attack code had been published publicly, which typically widens the pool of people able to carry out an attack.

Changing Your Password Will Not Help

Because the flaw defeats the login check itself, the usual protective steps do not work. Security firm Huntress found that removing allowed user accounts, disabling legacy VNC password authentication, and rotating the VNC password all have no effect, because the bypass happens before any of those controls are consulted.

Huntress also reported the result as pre-authenticated remote code execution on all supported macOS versions, meaning an attacker can run their own software on the machine without ever logging in.

There are two fixes. Update to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9, all released on August 6. Or turn Screen Sharing off entirely, under System Settings, then General, then Sharing.

Anyone running a Mac that is reachable from the internet should also check whether port 5900 is open to the public.

Six Days From Patch to Attacks

Apple released the updates on August 6 outside its normal schedule. The Dutch agency published its first advisory on August 7, then updated it on August 12 to record that working attack code had been published publicly and that active abuse had been observed.

The gap matters because attackers often study a patch to work out what it fixed, then target machines whose owners have not installed it yet. Macs that were updated promptly were never at risk from these attacks; those still running older versions remain exposed.

Apple devices have drawn steady attention from attackers targeting crypto users. The Crypto Times reported in April on a macOS campaign attributed to the Lazarus Group aimed at crypto and fintech employees and in 2024 on macOS malware that replaced wallet applications with tampered versions to steal recovery phrases.

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto HackUnited States
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

NEAR Governance Proposal Targets Lower Token Issuance and Dilution
NEAR Governance Proposal Targets Lower Token Issuance and Dilution
Official U.S. Securities and Exchange Commission (SEC) seal mounted on a exterior stone wall.
SEC Proposes Tailored Crypto Custody Rules for Advisers and Funds
Galaxy and Polymarket corporate logos displayed side by side on dark and blue metallic plaques.
Galaxy Finds 69% of Polymarket Retail Accounts Lost Money
Ripple corporate sign displayed with the flag of Uganda in the background.
Ripple Launches RLUSD Insurance Pilot for Ugandan Farmers
Conceptual representation of an Ethereum crypto transfer between two digital wallets with a hooded hacker and Aave v3 screen in the background.
FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes

Find Us on Socials

You may also like

Physical Bitcoin and Ethereum coins standing next to wooden blocks spelling ETF with a September calendar in the background.

Bitcoin Leads Crypto ETF Inflows as September Ends With Outflows

Congressional Research Service wall signage featuring a Capitol dome logo on a beige background.

CRS Examines What Crypto Activities U.S. Banks Can Conduct 

Libra and visual crypto coins positioned next to a wooden gavel with the U.S. flag in the background.

US Judge Dismisses $LIBRA, $M3M3 Case Against Davis, Kelsier

Official New York State Department of Financial Services seal mounted on a dark wall.

New York and Wyoming Regulators Sign MOU to Coordinate Digital Asset Oversight

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information