SendTech Times
News
MARKET SIGNAL:

Mac Screen Sharing Flaw Hits Live Exploitation On Exposed Port 5900

Newsroom brief

Ars Technica reported that CVE-2026-65400, a macOS Screen Sharing vulnerability patched by Apple last week, is now being exploited on systems with port 5900 exposed to the Internet. Dutch cyber officials observed root access and Monero miners on affected Macs, making patching and Screen Sharing exposure checks the immediate remediation path.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: Ars Technica
Mac Screen Sharing Flaw Hits Live Exploitation On Exposed Port 5900
Image source: Ars Technica

A patched macOS Screen Sharing flaw has moved from conference disclosure to live exploitation on Internet-exposed Macs, Ars Technica reported, turning a remote-access feature into an immediate patch and firewall issue for operators that leave port 5900 reachable online.

The vulnerability is tracked as CVE-2026-65400 and carries a 7.1 severity score.

Apple released fixes last week for macOS Tahoe, Sequoia and Sonoma after researchers disclosed details at the Black Hat security conference.

Port 5900 Exposure Defines The Attack Surface

The Netherlands National Cyber Security Centrum warned that active abuse had been observed on multiple systems where port 5900 was accessible from the Internet.

In those cases, root access had been obtained and a Monero cryptocurrency miner had been installed.

Screen Sharing lets a remote party view a Mac's screen and control the keyboard and mouse while the machine is running.

The bug sits in the feature's state management, the part of the system that tracks preceding events, user interactions, variables and other operating states.

Apple's advisory described the flaw as one that may allow an unauthenticated attacker to gain access to a Mac.

Routers or dedicated firewalls may still block inbound Screen Sharing traffic unless an administrator has exposed it.

Patch Status Does Not Remove Configuration Risk

Apple's update addresses the software flaw.

Network exposure remains a separate configuration issue when Screen Sharing is left on and rules forward or permit VNC traffic from the public Internet.

Security practitioners generally advise keeping direct VNC access closed and using a VPN or SSH tunneling when remote screen access is needed.

For users without those workflows, the safer operating pattern is to leave Screen Sharing disabled, enable it only for a specific session and turn it off when that session ends.

The current exploitation activity has been tied to Monero miners rather than credential theft or broader malware deployment.

That limits the observed payload, not the access level: root control gives attackers room to install more damaging tools if the same exposure remains open.

Mac operators now have two verifiable remediation steps: install Apple's latest macOS security updates and confirm that Screen Sharing is not exposed directly to the Internet.

Share this article
inXf

Related articles

More
macOS Screen Sharing Flaw Gets Critical Rating After Root Compromises
Cybersecurity

macOS Screen Sharing Flaw Gets Critical Rating After Root Compromises

CVE-2026-65400 in macOS Screen Sharing was raised to a 9.8 critical score after Dutch officials documented exposed Macs being rooted and used for Monero mining.

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure
Cybersecurity

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure

Cisco disclosed fixed-release guidance for a critical Unified Communications Manager flaw that can let attackers gain root privileges when WebDialer is enabled. Cisco PSIRT is aware of public proof-of-concept exploit code for CVE-2026-20230, though it has not found active exploitation or targeting. The immediate test is whether administrators patch Unified CM or disable WebDialer before proof-of-concept code turns into wider exposure.

CISA Adds LoadMaster Flaw After 792 Exploit Attempts
Cybersecurity

CISA Adds LoadMaster Flaw After 792 Exploit Attempts

The Hacker News covered CISA's KEV listing for CVE-2026-8037 after KEVIntel telemetry counted 792 exploitation attempts against Progress Kemp LoadMaster over 41 days.

Rails Fixes Critical Active Storage File-Read Vulnerability
Cybersecurity

Rails Fixes Critical Active Storage File-Read Vulnerability

BleepingComputer reported that Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw tied to libvips image processing and possible file exposure in vulnerable applications.

Minnesota Water Cyberattack Hits More Than 30 Systems
Cybersecurity

Minnesota Water Cyberattack Hits More Than 30 Systems

The Hacker News reported that Minnesota opened a statewide response after more than 30 community water systems were affected, with attribution and the access method still unconfirmed.

Endpoint Blind Spots Put ASEAN Firms at US$1 Million Risk
Cybersecurity

Endpoint Blind Spots Put ASEAN Firms at US$1 Million Risk

A Frontier Enterprise article based on Tanium survey data found ASEAN organisations facing device visibility, patching and audit gaps, with 79% planning new security investment within 12 months.

AI Attack Speed Pushes Check Point Toward Exposure Automation
Cybersecurity

AI Attack Speed Pushes Check Point Toward Exposure Automation

Check Point CEO Nadav Zafrir told Frontier Enterprise that AI is shrinking the window from vulnerability discovery to weaponisation, raising pressure on patching cycles, exposure management and mixed-vendor remediation.

White House Private Cyber Program Tests Hackback Limits Against Foreign Crime Groups
Cybersecurity

White House Private Cyber Program Tests Hackback Limits Against Foreign Crime Groups

Ars Technica reported that a Trump memorandum directs federal officials to build a program allowing vetted private security firms to conduct authorized cyber operations against foreign criminal hacking groups under Justice and Homeland Security oversight.

Keep Reading

More Stories

Latest
Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.