Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

3036

Exposed macOS Screen Sharing Becomes an Entry Point for Active Attacks

Verified Context

Apple released fixes for CVE-2026-65400, a vulnerability in the macOS Screen Sharing feature that could allow authentication without valid credentials.

The issue was fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9 and macOS Tahoe 26.6.1. Apple describes it as an authentication issue addressed through improved state management.

NCSC-NL first published an informational advisory on 7 August. On 12 August, the agency updated the advisory after receiving information about active exploitation against systems where port 5900 was reachable from the internet.

What Is Confirmed About the Attacks

According to NCSC-NL, active exploitation was observed on multiple systems with internet-exposed port 5900. In the reported cases, attackers obtained root access on affected macOS systems and installed a Monero cryptominer.

At this stage, the full scope of the attacks has not been publicly specified. NCSC-NL has not reported how many systems were affected, when the attacks began or whether the attackers performed actions beyond installing the cryptominer.

That distinction matters: active exploitation is confirmed, but the full public picture of scale and impact is still limited.

Why the Case Matters

This news does not mean that macOS environments are inherently easy targets. The more important point is different: any remote access service exposed to the internet can become an entry point when a vulnerability appears.

Screen Sharing is useful for remote work and support. But when it is directly reachable from the internet, the risk changes. An authentication issue is no longer only a local concern; it becomes a path to remote system access.

The cryptominer is the visible result in the reported cases. But with root access, investigation needs to check what else was possible: system changes, new accounts, file access, attempts to maintain access or movement toward other resources.

What Organizations Should Check

Organizations using macOS devices should verify not only whether the update has been applied, but also whether Screen Sharing was internet-exposed before patching.

Practical checks:

  • whether macOS Sequoia 15.7.9, Sonoma 14.8.9 or Tahoe 26.6.1 has been applied;
  • whether any macOS devices expose port 5900 to the internet;
  • whether Screen Sharing is enabled and on which devices;
  • whether there are unusual processes, high CPU usage or signs of cryptomining;
  • whether new accounts, permission changes or suspicious commands exist;
  • whether logs are sufficient for retrospective review;
  • if patching cannot be done immediately, whether Screen Sharing has been disabled.

The key question is not only whether the system is now updated. It is whether it was exposed before the update and whether there are signs of access.

DIAMATIX Comment

From the DIAMATIX perspective, this case shows why remote access services need to be part of day-to-day visibility.

Devices with internet-facing services are often overlooked until active exploitation appears. At that point, the task is not only to apply a patch, but to prove whether the system was used before remediation.

SOC (Security Operations Center) and MDR (Managed Detection and Response) processes should connect exposure, logs, process behavior and network activity. This helps teams distinguish “vulnerable but not exploited” from “vulnerable and likely used.”

Questions for CISO and IT Teams

  • Which macOS devices have remote access services enabled?
  • Which of them were reachable from the internet?
  • Is there control over who can enable Screen Sharing?
  • How are devices with open port 5900 detected?
  • Are signs of cryptomining and unexpected root access being checked?
  • Is there a process to temporarily disable a service when a patch cannot be applied immediately?

The practical takeaway: for remote access, security does not depend only on the platform. It depends on exposure, timely updating and the ability to verify whether abuse already occurred.

Check which remote access services are exposed to the internet

DIAMATIX can help review exposure, logs, remote access services and response readiness for actively exploited vulnerabilities.

Request a visibility and response readiness review with DIAMATIX.
Trusted · Innovative · Vigilant


Sources

  • Apple. About the security content of macOS Tahoe 26.6.1.
  • Apple. About the security content of macOS Sequoia 15.7.9.
  • Apple. About the security content of macOS Sonoma 14.8.9.
  • NCSC-NL. Security Advisory NCSC-2026-0280.
  • NVD. CVE-2026-65400.
  • Help Net Security. Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer.

This article summarizes publicly available information as of August 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.