Update (August 17, 2026): This post follows our earlier Screen Sharing advisory from August 16. Since that post, Help Net Security has confirmed that the Netherlands' National Cyber Security Centre (NCSC) formally escalated its advisory's severity on August 12 — after proof-of-concept exploit code went public and active attacks began rolling in. A security firm also revealed it built a working exploit in just four hours using an AI agent. This post adds practical steps for spotting whether a cryptominer is already running on your machine, and exactly what to do right now.
If you own a Mac and haven't opened your Software Update settings recently, stop what you're doing and go do that right now. A serious security flaw is being actively used by hackers to break into Macs remotely — without needing your password — and silently put your computer to work mining cryptocurrency for them.
Here's everything you need to know in plain language.
What Is Screen Sharing, and Why Does It Matter?
macOS has a built-in feature called Screen Sharing that lets someone else view and control your computer over a network — useful for remote work or getting IT help. When it's turned on, your Mac listens for connections on a network port called port 5900.
The problem: Ars Technica reports that a flaw in how Screen Sharing manages its internal "state" — the record it keeps of what steps have already happened during a login — allowed attackers to skip the credential check entirely. No password required. No special hacking tools. Just knowing your Mac's IP address and sending the right packets in the right order.
The vulnerability is tracked as CVE-2026-65400, and it carries a critical CVSS severity score of 9.8 out of 10.
What Are Hackers Actually Doing With It?
According to the Netherlands National Cyber Security Centre (NCSC), attackers have confirmed access to multiple systems where port 5900 was reachable from the internet. In every reported case, they gained root access — the highest level of control on a Mac — and installed a Monero cryptocurrency miner.
Why Monero? Malwarebytes explains that Monero mining doesn't require specialized hardware chips (called ASICs) the way Bitcoin does. Any CPU or GPU can do the work — including the one inside your Mac. That makes your computer a perfect silent workhorse for someone else's financial gain.
Cryptomining is the relatively mild version of what could happen. With root access, Ars Technica notes that attackers could also steal files, harvest passwords and encryption keys, install persistent backdoors, or spread to other devices on your network.
How Did This Escalate So Quickly?
Apple patched CVE-2026-65400 on August 6. The NCSC published its first advisory the very next day as a heads-up, with no exploitation reported yet. Five days later, on August 12, everything changed: Help Net Security reports that proof-of-concept exploit code became public and active attacks began arriving at the NCSC. The agency immediately raised its advisory's severity level.
Making matters worse, The Hacker News reports that security firm Calif built working exploits for two related Screen Sharing flaws in just four hours — using an AI agent. This underscores how the window between "patch released" and "exploit in the wild" is shrinking fast.
Details of the vulnerability were also presented at the Black Hat security conference last week, putting even more technical eyes on the flaw.
Is Your Mac at Risk?
Your Mac is most exposed if both of the following are true:
- Screen Sharing is enabled in your System Settings
- Port 5900 is reachable from the internet (common if you've ever set up port forwarding on your router, or if your Mac has a direct public IP address)
Malwarebytes notes that Macs only reachable from inside your home or office network are still potentially at risk — an attacker would just need to get onto that local network first, which is a lower bar than it sounds if you're using public Wi-Fi or have a compromised router.
Step 1: Apply the Patch Right Now
Apple released emergency updates on August 6. The fix is available for:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
To update, follow these steps from Malwarebytes:
- Click the Apple menu (top-left corner of your screen)
- Choose System Settings (or System Preferences on older macOS versions)
- Click General in the sidebar, then Software Update
- If an update is available, click Update Now and follow the prompts
- Enter your administrator password if asked, and let the Mac restart if needed
- Keep your Mac plugged in and connected to Wi-Fi until it finishes
Step 2: Turn Off Screen Sharing If You Don't Need It
If you can't update immediately — or just want an extra layer of protection — check whether Screen Sharing is even on. Most home users never turned it on intentionally, but it's worth verifying.
- Click the Apple menu ? System Settings
- Click General ? Sharing
- Find Screen Sharing — if the toggle is colored/on, click it to turn it off
- While you're there, also check Remote Management and turn it off unless you specifically use it for IT support
Per Ars Technica, security professionals generally recommend keeping Screen Sharing off by default and only enabling it for active sessions — then turning it off again when you're done.
Step 3: Watch for These Signs a Cryptominer Is Already Running
If your Mac was exposed before you patched, here's what to look for:
- Unusually slow performance — even on simple tasks like browsing or opening apps
- Your Mac running very hot — the bottom of a laptop noticeably warm to the touch, or the desktop body warm
- Loud or constant fan noise — fans spinning hard when you're not doing anything demanding
- Battery draining much faster than normal on a MacBook
- Activity Monitor showing high CPU usage from a process you don't recognize (open it via Spotlight ? type "Activity Monitor")
If you're seeing several of these symptoms together, it's a sign your Mac's processor is being pushed hard by something running in the background.
Not Sure If You're Protected?
If you're uncertain whether your Mac is fully updated, whether Screen Sharing is properly disabled, or whether something suspicious might already be running on your system, we're happy to take a look. Our virus removal service covers malware and cryptominers, and we can check your Mac's current security posture while we're at it. Stop by our shop on Clark Ave in Yuba City, or give us a call at (530) 645-7007 during business hours.
The bottom line: this one has a patch, and the patch works. The only remaining risk is waiting too long to apply it.