Apple has patched a serious authentication vulnerability in the macOS screen sharing component (CVE-2026-65400, CVSS score 9.8) that was exploited by attackers, allowing them to access exposed Macs on the internet without valid credentials and implant Monero mining programs. The vulnerability was fixed on August 6 with the updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, with Apple enhancing credential verification through improved state management. The Dutch National Cyber Security Centre (NCSC) confirmed multiple attacks in which attackers gained root access and deployed mining software. Security researcher @osxreverser disclosed another pre-authentication vulnerability in the same component, where attackers only need the target IP to bypass password authentication, without requiring a username. Calif stated that researchers developed usable attack programs for both vulnerabilities in just 4 hours using AI, demonstrating that AI significantly shortens the time from vulnerability discovery to attack code development. Users are advised to update their systems immediately; if unable to update, they should disable screen sharing.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























