flash on Nostr: ⚡️⚠️ NEW - Hackers are actively exploiting a macOS vulnerability to take ...
⚡️⚠️ NEW - Hackers are actively exploiting a macOS vulnerability to take control of Macs… and then turn them into Monero mining machines.
The CVE-2026-65400 vulnerability affected the macOS screen-sharing feature. Macs exposing VNC port 5900 to the Internet could be compromised without authentication, allowing attackers to gain root access and install a Monero cryptocurrency miner without the owner’s knowledge.
Apple patched the vulnerability on August 6 with macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, but the Dutch NCSC warns that attacks are already underway.
If your Mac isn’t up to date, you should install the patch as soon as possible or temporarily disable screen sharing.
Published at
2026-08-16 13:25:31 UTCEvent JSON
{
"id": "6444d470a924b678337e0ecc997d139597c2cb9ea542632ff41600028ae1fd31",
"pubkey": "4d7842051782e0d3feb034d150adc2b6bae4ee3b49786793bffa468b6f5b96b3",
"created_at": 1786886731,
"kind": 1,
"tags": [
[
"client",
"Primal iOS"
]
],
"content": "⚡️⚠️ NEW - Hackers are actively exploiting a macOS vulnerability to take control of Macs… and then turn them into Monero mining machines.\n\nThe CVE-2026-65400 vulnerability affected the macOS screen-sharing feature. Macs exposing VNC port 5900 to the Internet could be compromised without authentication, allowing attackers to gain root access and install a Monero cryptocurrency miner without the owner’s knowledge.\n\nApple patched the vulnerability on August 6 with macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, but the Dutch NCSC warns that attacks are already underway.\n\nIf your Mac isn’t up to date, you should install the patch as soon as possible or temporarily disable screen sharing. \nhttps://blossom.primal.net/278144cb81ff08f04ef0257033191d0a805d04f91a3e522bafa5e5fe62cbbceb.jpg",
"sig": "2e18a01046df990a568661411c7292a52a76357bf11f0e755f9804726a0d55caec9b85d0e33ee8b597daa7231a7c14986e4d1dc462fbdab350b92a84a2b7f8d7"
}