Tens of Thousands of Macs Exposed via Port 5900
The Netherlands’ National Cyber Security Centre (NCSC) issued an updated warning on August 12, confirming active exploitation of CVE-2026-65400. Attackers targeted multiple systems connected to the internet via port 5900, and in every observed instance, they achieved root access before installing Monero mining software. Apple released updates for macOS Tahoe, Sequoia, and Sonoma on August 6 to close the hole.
A Flaw in SCRAM Let Attackers Skip Authentication Entirely
The Screen Sharing flaw is a state management error that allowed network based attackers to bypass authentication entirely. Security company Huntress traced the root cause to the SCRAM (Secure Remote Password) authentication mechanism, which allowed an unauthenticated connection to be treated as authenticated, leading directly to privilege escalation.
What makes this particularly dangerous is timing. The vulnerability exists before normal authentication even runs, which means changing your password does nothing to stop it. CISA assigned the flaw a CVSS severity score of 9.8, and it requires no privileges or user interaction to exploit.
Why Monero, Not Wallet Theft
Attackers compromised these Macs to leverage their processing power for Monero mining, not to steal cryptocurrency wallets. According to the Dutch NCSC, mining was the primary objective throughout the campaign. Monero’s mineability on general purpose hardware makes it a frequent target for cryptojacking operations, since attackers don’t need specialized mining rigs to profit.
Researcher Ryan Dowd ran a Censys search that turned up tens of thousands of exposed hosts. That number reflects potential exposure, not confirmed infection. Hosted bare metal Macs are particularly vulnerable here, since they’re often provisioned with Screen Sharing enabled by default.
Patch Now, Disable Screen Sharing If You Can’t
Huntress emphasized that patching vulnerable systems remains the best mitigation, especially for machines exposing Screen Sharing ports directly to the internet. Disabling Screen Sharing until updates can be applied works as a temporary stopgap.
This incident fits a broader pattern of cryptocurrency attacks on macOS, spanning both cryptojacking campaigns like this one and malware specifically built to target crypto companies.
What We Still Don’t Know
- The total number of affected devices
- The identity of the attacking group
- Miner and mining pool addresses
- Attacker wallet addresses
- The total amount of XMR mined
Monero traded around $417 at the time of writing, up roughly 2% over 24 hours and nearly 6.7% over the past week, though that price movement doesn’t reflect the size or returns of this specific mining campaign.
Hashlytics Take
The real story here isn’t the exploit itself, it’s how long root level access from an authentication bypass sat undetected on hosted infrastructure before anyone noticed the CPU spikes. A 9.8 CVSS score with zero user interaction required should have triggered faster disclosure timelines than we’re seeing. If Screen Sharing ships enabled by default on bare metal Mac hosting, that’s not just an Apple patch problem, it’s a hosting provider configuration problem that nobody in this story is being held accountable for yet.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



