Attackers are now actively weaponising a recently patched vulnerability affecting Apple's Mac computers to harvest cryptocurrency, marking a dramatic escalation from the time the flaw first came to light. The Netherlands' National Cyber Security Centre has documented multiple incidents in which hackers exploited a weakness in macOS Screen Sharing to compromise machines connected to the internet. Upon gaining access, they immediately installed Monero cryptocurrency-mining software, effectively hijacking the computational power of affected devices for profit while imposing significant costs on the victims through degraded performance and elevated electricity consumption.
The particular focus on Monero as the payload of choice reflects a strategic calculation by the criminal operators. Unlike many other digital currencies that require specialised graphics processing units or application-specific integrated circuits, Monero is deliberately designed to be mined efficiently using standard computer processors. This makes any Mac, regardless of its age or specifications, a viable target for transformation into an unwilling cryptocurrency farm. The economics are attractive for attackers: they face minimal overhead in deploying the malware and begin generating revenue almost immediately once installation succeeds.
Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, underscores that cryptocurrency mining may represent only the tip of a far more sinister iceberg. Armed with root access—the highest level of system control—intruders can traverse the entire digital footprint of a compromised machine. They gain the ability to exfiltrate sensitive files, steal stored credentials, pilfer cloud authentication tokens, and potentially pivot into other networked systems. The presence of a mining operation might simply indicate the most conspicuous activity, with additional espionage or data theft occurring silently in the background.
Apple's initial assessment of the threat proved premature. When the technology giant first acknowledged the flaw, it stated categorically that it had "not aware of this issue being exploited outside of test environments." That assertion has now been thoroughly invalidated by real-world attacks documented by Dutch cybersecurity officials. This development underscores how the timeline between vulnerability disclosure and active exploitation has compressed dramatically in recent years. Within weeks of a patch becoming available, determined threat actors had already begun scanning the internet for vulnerable machines and launching attacks against accessible targets.
The vulnerability, designated CVE-2026-65400, resides within macOS Screen Sharing, a built-in feature that permits remote users to view and control a Mac from another device. Apple released fixes across three major operating system versions: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. The breadth of this patching effort reflects the severity of the flaw. Users can apply the update through System Settings, navigating to General and then Software Update. For those who have never used Screen Sharing, the safest approach involves disabling the feature entirely through System Settings, accessible under General and Sharing.
Yet patching represents merely half the battle for organisations and individuals concerned about their security posture. Hegel emphasises a critical distinction that many overlook: installing the update closes the door against future intrusions but does nothing to eradicate malware that may already be present or to reverse actions previously taken by attackers. Businesses whose Macs had Screen Sharing accessible from the public internet and remained unpatched should undertake comprehensive forensic examinations. The existence of a mining process on a patched machine indicates past compromise, and thorough investigation is warranted to determine what else may have occurred.
The geographic pattern of exploitation reveals something instructive about how internet exposure translates into real risk. The incidents documented in the Netherlands involved machines whose Screen Sharing port was reachable directly from the global internet. In most home and business environments, routers and firewalls are configured by default to block such connections, providing a substantial protective buffer. However, organisations that have deliberately opened these ports for legitimate remote administration, or users who have configured port forwarding without understanding the implications, face heightened vulnerability. The exposure represents a failure not necessarily of Apple but of network configuration.
The severity with which authorities and security researchers are treating this flaw reflects its inherent danger. Federal assessments have assigned it a critical severity score of 9.8 out of 10, a rating reserved for vulnerabilities that enable attackers to strike without requiring valid credentials or user interaction. An attacker needs only to locate a vulnerable machine reachable online and launch an exploit. No social engineering, no phishing emails, no user mistakes need occur. This combination of ease of exploitation and severity of impact explains why Apple broke with its normal update cycle to release the patch as an out-of-schedule security release.
For Malaysian readers and Southeast Asian businesses, the implications warrant careful consideration. The region's growing digital economy and increasing adoption of Mac computers among creative professionals, tech workers, and enterprises make this threat locally relevant. Remote work practices that have become entrenched since the pandemic may have left many Mac users with Screen Sharing unnecessarily exposed. Organisations managing fleets of Mac computers should prioritise a comprehensive audit of their update status and network configurations. Those who have not yet deployed the patch face an urgent deadline, as attackers have already demonstrated their willingness and capability to exploit this vulnerability at scale. The window of vulnerability remains open, but it closes with each completed software update.
