Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Leaked Stripe Merchant API Keys Expose Payment and Payout Capabilities
August 19, 2026
AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
August 19, 2026
China Hackers Use Malicious VHD Disguised as JPEG to Deploy QUICAgent Backdoor
August 19, 2026
Home/Threats/Critical macOS Screen Sharing Vulnerability Actively Exploited
Threats

Critical macOS Screen Sharing Vulnerability Actively Exploited

Key Takeaways A critical vulnerability, CVE-2026-65400, in macOS Screen Sharing is being actively exploited in the wild. Attackers are gaining root-level control over affected macOS devices. The...

Sarah simpson
Sarah simpson
August 19, 2026 3 Min Read
3 0

Key Takeaways

  • A critical vulnerability, CVE-2026-65400, in macOS Screen Sharing is being actively exploited in the wild.
  • Attackers are gaining root-level control over affected macOS devices.
  • The exploit allows for file manipulation, system setting changes, and the deployment of cryptocurrency miners.
  • The vulnerability stems from an improper authentication weakness in the Screen Sharing service.
  • Immediate application of security updates and proactive monitoring are crucial for mitigation.

Hackers Actively Exploiting macOS’s Built-in Screen Sharing Service

Cybersecurity researchers have uncovered active exploitation of a severe vulnerability within Apple’s macOS Screen Sharing feature, designated as CVE-2026-65400. This flaw, characterized as an improper authentication weakness, allows attackers to escalate privileges and gain root-level control over a limited number of compromised macOS systems. The attacks leverage the operating system’s native remote access capabilities to establish persistent footholds, deploy malicious payloads, and conduct covert operations.

Table Of Content

  • Key Takeaways
  • Hackers Actively Exploiting macOS’s Built-in Screen Sharing Service
  • Microsoft Threat Intelligence Uncovers Campaign
  • Post-Exploitation Tactics and Persistence
  • Miner Persistence and Response

The exploitation chain begins with an intruder accessing the Screen Sharing service, which is frequently enabled for legitimate remote support and administrative functions. Once an authenticated connection is established, the vulnerability permits the attacker to transition from user-level access to full root privileges. This elevated access enables the silent placement of files, alteration of system configurations, and the installation of cryptocurrency mining software, which then siphons off the victim’s computational resources.

Microsoft Threat Intelligence Uncovers Campaign

The active exploitation was initially identified by Microsoft Threat Intelligence. Their analysis, based on telemetry data from Microsoft Defender, revealed successful network sign-ins to root accounts via Screen Sharing. Microsoft Threat Intelligence said in a report shared with Cyber Security News (CSN) that organizations should prioritize security updates and scrutinize related alerts. This advisory follows previous warnings regarding an earlier Apple Screen Sharing vulnerability that allowed for privileged file access and writes through file-copy utilities.

Post-Exploitation Tactics and Persistence

Following successful exploitation, attackers use the Screen Sharing connection to transfer their tools. This includes copying malicious scripts and an SSH public key to the compromised device. The SSH key serves as an alternative access method, ensuring persistent remote access even after the initial Screen Sharing session concludes. The attackers then meticulously erase command histories and logs, hindering forensic investigations. Furthermore, they modify Packet Filter settings, potentially altering network traffic handling on the compromised host. These actions suggest a deliberate and sophisticated intrusion, far beyond a simple opportunistic attack.

The core issue lies in the elevated permissions associated with the Screen Sharing service. Previous research has indicated that legacy VNC authentication mechanisms can allow Screen Sharing’s file-copy components to operate with root authority. This enables attackers to read sensitive protected files or write arbitrary files to critical system locations.

For organizations, the risks extend beyond merely slowed performance due to a cryptocurrency miner. Root access grants an attacker the ability to inspect critical configuration files, establish additional remote access, weaken existing security controls, and utilize the compromised device as a pivot point for further network infiltration. Any unexplained root SSH sessions observed after Screen Sharing activity should be treated as a potential security incident, not a routine support event.

Miner Persistence and Response

The ultimate payload delivered in these attacks is XMRig 6.26.0, a popular Monero cryptocurrency mining software. Attackers cunningly copy and rename the miner to “sysmond” and apply an ad-hoc signature before concealing it within a system-like path: /private/var/root/.config/sysmond. <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/762de495-6d23-495f-a863-9416dd1c335b/Hackers-Actively-Exploiting-macOSs-built-in-Screen-Sharing-Service-Vulnerability-in-the-Wild.pdf?AWSAccessKeyId=ASIA2F3EMEYEZH4LQP3F&Signature=meR9T2vCZyDOFuynVyE0bi2XAss%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEKz%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQDYRm6WpmQ%2BgdhXqiVuAMcJTSxUYC7wyHVxhxgU29XEXQIhAJhLgBQTrpbtI3G6IemvWWof3u3939P9MXFL%2BjqlXfQhEKvMECHQQARoMNjk5NzUzMzA5NzA1IgxrgJwH253A9Q

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitHackerMalwarePatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

MacSync Stealer Uses 30+ Domains to Steal Passwords and Sensitive Mac Data

Next Post

Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000
August 19, 2026
Critical macOS Screen Sharing Vulnerability Actively Exploited
August 19, 2026
MacSync Stealer Uses 30+ Domains to Steal Passwords and Sensitive Mac Data
August 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us