Cybersecurity officials in the Netherlands have raised alarms about active exploitation of a critical Apple vulnerability that was patched only weeks ago. The Screen Sharing flaw, now confirmed to be under active attack in the wild, represents a shift from theoretical risk to tangible threat affecting Mac users worldwide. Each successful breach grants attackers root access—essentially complete control of the compromised machine—which they have leveraged to install Monero cryptocurrency-mining software that commandeers processing power at the owner's expense.
The vulnerability, formally designated CVE-2026-65400, resides within macOS's built-in Screen Sharing functionality, a feature that permits remote viewing and control of one computer from another. Apple addressed the flaw through out-of-cycle security releases across multiple operating systems: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. The company's decision to expedite these patches outside its standard update schedule signalled the severity of the underlying risk, though initially Apple stated it was unaware of real-world exploitation beyond controlled testing environments. That assessment has now been overtaken by events as Dutch authorities documented multiple compromised systems.
Monero's selection as the preferred payload reflects attacker economics and technical feasibility. Unlike Bitcoin or other cryptocurrencies requiring specialized hardware, Monero is deliberately engineered to be mined using ordinary computer processors found in consumer devices. This design choice makes it particularly attractive to cybercriminals seeking to quietly monetize stolen computational resources. By transforming unwitting Mac owners' machines into mining nodes, attackers generate revenue streams with minimal infrastructure investment while distributing processing loads across thousands of compromised systems to evade detection.
Threats researchers at SentinelOne's analysis division caution, however, that the visible cryptocurrency mining may represent only the tip of a larger attack iceberg. Tom Hegel, a threat researcher at SentinelLABS, explains that criminals frequently use newly disclosed exploits to automate large-scale attacks and rapidly deploy revenue-generating payloads for what he characterises as "immediate, relatively low-friction monetisation." Yet with root-level access firmly established, attackers possess far broader capabilities than simply siphoning processing power. They can systematically extract sensitive files, harvest stored credentials, compromise cloud authentication tokens, and pivot toward connected systems within corporate networks or personal cloud services.
The gap between Apple's initial assessment and the current reality highlights the velocity of modern exploitation campaigns. When Apple disclosed the patch, the company's statement to technology media suggested the flaw remained theoretical. Within weeks, determined threat actors had not only developed reliable exploitation code but deployed it against live targets across the internet. The compressed timeline reflects both the sophistication of organized cybercriminal groups and the speed at which vulnerability information spreads through underground forums once patches become available. Security researchers can reverse-engineer patches to identify vulnerabilities, and state-sponsored groups maintain even greater analytical resources.
Exposed Macs were those with Screen Sharing enabled and accessible from the public internet—a configuration that, while seemingly niche, proves surprisingly common. Many users enable Screen Sharing for legitimate remote work or technical support without fully appreciating the security implications of internet-facing access. Corporate environments, where IT departments may batch patch cycles and leave systems reachable during transition periods, face particular risk. Most home routers and enterprise firewalls block inbound connections to such ports by default, affording some protection to users operating standard network configurations. Machines in data centres, exposed through misconfigured cloud security groups, or behind simplified firewalls present significantly higher targets.
Federal cybersecurity assessments now rate this vulnerability at 9.8 out of 10 on the critical severity scale, denoting that exploitation requires neither prior system access nor user interaction. An attacker merely needs to detect a vulnerable machine reachable across the internet and execute the attack—no phishing, no social engineering, no user deception required. This vulnerability class represents the most dangerous category from a systems administration perspective, as it renders traditional layered defences ineffective once a machine is internet-exposed.
Mac users who have not yet installed available patches face immediate risk and should prioritize updates through System Settings > General > Software Update. For those unfamiliar with their Screen Sharing configuration, the feature can be disabled via System Settings > General > Sharing, though this approach solves only the symptom rather than the underlying vulnerability. More critically, business IT administrators managing fleets of Mac computers must move beyond simply deploying patches. SentinelOne researcher Phil Stokes emphasises that patching closes the vulnerability pathway but does not eliminate malware or reverse attacker actions already taken. Organisations should assume that any Mac with Screen Sharing enabled and internet exposure prior to patching may have been compromised, necessitating forensic investigation and malware removal.
The implications for Malaysian and regional users extend beyond individual inconvenience. Cryptocurrency mining on compromised devices increases electricity consumption, degrades system performance for legitimate users, and generates revenue for criminal enterprises operating with minimal accountability. For businesses operating in Southeast Asia, where cloud infrastructure adoption accelerates and remote work remains prevalent, the attack pattern mirrors tactics successfully deployed against poorly configured cloud instances in the region. The Dutch discovery serves as an early warning that similarly configured Asian infrastructure may already be under surveillance and potential compromise. Organisations should treat this as a urgent call to audit their Apple device inventory, verify patch status across all systems, and implement network segmentation to limit blast radius should compromise occur.
