[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner-msvxsxjp":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"f7245884-6c33-4c07-8d36-757e59899006","Hackers exploit macOS Screen Sharing flaw to deploy Monero miner","hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner-msvxsxjp","Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public exploitation.","critical","advisory",[12],"CVE-2026-65400",[14,15,16],"macOS","Apple","Screen Sharing","Immediately identify all macOS systems with port 5900 exposed to the internet. Patch to the August 6 Apple security update or later. For systems that cannot be patched immediately, firewall port 5900 or disable Screen Sharing.",[19],"8b56f1f5-6c51-4f64-8605-5860dd2045f9",null,[22],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner\u002F","archived","2026-08-18T15:05:41.185+00:00","2026-08-16T15:05:44.275426+00:00","2026-08-18T15:05:48.831715+00:00",[28],{"id":19,"title":6,"url":22}]