← Back to Feed
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
August 14, 2026 · BleepingComputer · Severity: HIGH
The Netherlands National Cyber Security Centre (NCSC) has issued a warning about active exploitation of a macOS authentication bypass vulnerability. Hackers are targeting the Screen Sharing feature, using a publicly available exploit code to gain unauthorized access to systems. Once inside, they deploy a Monero cryptocurrency miner, which consumes significant system resources to generate digital currency for the attackers. This campaign highlights the dangers of unpatched vulnerabilities and the rapid weaponization of exploit code after public release. Users are advised to apply security updates promptly and disable unnecessary services like Screen Sharing if not required.
Key Takeaways
- Hackers are exploiting a macOS Screen Sharing authentication bypass flaw for remote access.
- The attack deploys a Monero cryptocurrency miner to hijack system resources for mining.
- The Netherlands NCSC warned after public exploit code enabled widespread active exploitation.