Cybercriminals have begun actively exploiting a critical vulnerability in Apple's Mac computers just weeks after the company released a patch, marking a significant escalation in the threat landscape for users in the region. The Netherlands' National Cyber Security Centre has documented multiple incidents where attackers breached Macs through a flaw in the built-in Screen Sharing feature, gaining complete administrative control over affected systems. In each reported case, the intruders immediately installed Monero cryptocurrency-mining software, transforming the compromised machines into unwilling participants in a profit-generating operation at the expense of their owners' resources and hardware.
The vulnerability, designated CVE-2026-65400, exploits Apple's native Screen Sharing capability, which permits remote access and control of a Mac from another computer or device. This fundamental feature, while essential for legitimate technical support and collaborative work, became a vector for attackers once the flaw was discovered. Apple addressed the issue through expedited updates released outside its normal patch cycle, indicating the company's assessment of the threat's severity. The fixes were distributed across three macOS versions: Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, reflecting the breadth of potentially affected installations across different user bases and device generations.
The choice of Monero as the cryptocurrency of interest reveals the strategic thinking behind these attacks. Unlike Bitcoin and many other cryptocurrencies that require specialised hardware known as application-specific integrated circuits to be mined profitably, Monero is specifically engineered for mining on conventional computer processors found in everyday machines. This characteristic makes Monero ideally suited to large-scale, distributed attacks where the goal is to capture processing power from thousands of ordinary devices rather than operate a concentrated mining operation. The attackers are essentially harvesting computational resources from Mac owners worldwide, converting legitimate computing capacity into illicit profit with minimal additional investment.
SentinelOne researchers provide crucial insight into the broader implications of these attacks. Tom Hegel, a threat analyst at the company's SentinelLABS division, characterises the use of cryptocurrency miners as a standard approach to monetising newly discovered exploits. He explains that criminals favour this technique because it provides what he terms "immediate, relatively low-friction monetisation"—rapid income generation without the complexity or risk of selling stolen data or ransoming systems. However, Hegel and his colleagues stress that the visible mining activity may represent only the most obvious payload installed by attackers who have gained root access, the highest privilege level on any computer system.
With root-level access secured, attackers possess the ability to pursue objectives far more damaging than passive resource theft. They can access confidential files stored on the compromised Mac, extract stored passwords and authentication credentials, capture tokens used for cloud services, and potentially pivot to other connected systems and networks. This capability transforms affected machines into beachheads for deeper intrusions, particularly concerning for business users whose Macs may serve as gateways to corporate infrastructure. The mining operation thus serves as both a revenue stream and a mask for more sophisticated espionage or infrastructure compromise that users may never detect.
Apple's initial assessment of the situation proved premature. When the vulnerability was first publicly disclosed, Apple stated it had "not aware of this issue being exploited outside of test environments," suggesting the company believed the flaw remained largely theoretical. Within weeks, however, the Netherlands' cybersecurity authorities documented real-world exploitation on multiple systems, demonstrating that threat actors had quickly weaponised the vulnerability and deployed automated attack infrastructure to scan for and compromise exposed Macs. This gap between Apple's initial appraisal and the emergence of active exploitation underscores how rapidly security incidents can escalate in the modern threat environment.
The federal cybersecurity assessment framework now assigns the vulnerability a severity score of 9.8 out of 10—a critical rating indicating that exploitation requires no authentication credentials and demands no user interaction. This maximum-severity classification reflects the combination of factors that make the flaw exceptionally dangerous: the ease with which attackers can trigger it remotely, the complete control it grants over affected systems, and the widespread deployment of the vulnerable feature across Apple's installed base. From a risk perspective, any Mac with Screen Sharing enabled and exposed to the public Internet became an attractive target once the attack method became known to criminal groups.
The victims identified in the Netherlands shared a common characteristic that determined their vulnerability: their Macs had the Screen Sharing port accessible from the public Internet. Most residential routers and corporate firewalls block such inbound connections by default, creating a protective barrier that shields the majority of Mac users from direct attack. However, users who have deliberately opened port forwarding rules, organisations that expose remote access services, or systems inadvertently made Internet-accessible through misconfiguration face heightened risk. Identifying which users fall into this exposed category requires understanding both network architecture and device configurations—knowledge that may not be apparent to non-technical users.
Security researchers at SentinelOne emphasise that patching the vulnerability, while essential, does not automatically remediate machines that were already compromised before updates were applied. Phil Stokes, a macOS security specialist, points out that installing the patch closes the initial entry point but leaves any malware already installed on affected systems untouched. Organisations and individuals whose Macs had Screen Sharing enabled and reachable before the patch was deployed must assume potential compromise and conduct forensic analysis to detect and remove any installed miners or other malicious payloads. This remediation challenge extends the operational impact of the vulnerability well beyond the simple act of software updating.
For Malaysian and Southeast Asian users, the practical implications warrant immediate attention. Mac ownership and usage are growing across the region, particularly among professionals, businesses, and creative industries that favour the platform. The presence of active exploitation efforts means the threat is not theoretical but concrete and ongoing. Users should navigate to System Settings, access the General section, and check Software Update to ensure they are running the latest patched versions of their macOS. Those who do not utilise Screen Sharing should additionally disable the feature under System Settings > General > Sharing to eliminate the attack surface entirely. For business users, system administrators should conduct audits to determine which Macs have Screen Sharing exposed to networks and take steps to restrict access or implement additional security controls.
The incident also reinforces a broader security principle that extends beyond Apple products: the critical importance of deploying security patches promptly and systematically. The delay between when a vulnerability becomes publicly known and when attackers weaponise it has narrowed considerably in recent years, leaving organisations and individuals limited time to act. In this case, Apple's decision to release the patch outside its normal update schedule signalled the urgency, yet many users still operate unpatched systems weeks later. Regional cybersecurity authorities are likely to issue additional guidance as the exploitation campaign evolves, making it prudent for users to monitor official statements and implement recommendations as they emerge.
The targeting of Mac users for cryptocurrency mining highlights an underappreciated vulnerability in the security posture of the Apple ecosystem. While Macs have long benefited from a reputation as inherently more secure than Windows systems, this assumption increasingly requires qualification. Active exploitation campaigns demonstrate that sophisticated threat actors view Apple's platform not as harder to compromise but as a legitimate profit opportunity when vulnerabilities exist. The regional security community should expect similar exploitation waves whenever high-severity macOS flaws are discovered, underscoring the necessity for rapid patch deployment and continuous monitoring across all systems, regardless of their operating system or vendor.
