CybersecurityAugust 14, 2026· via BleepingComputer

Hackers weaponize macOS flaw to secretly mine Monero

Hackers weaponize macOS flaw to secretly mine Monero

Image : BleepingComputer

Hackers have taken a recently disclosed macOS authentication bypass vulnerability and turned it into a stealthy backdoor for installing Monero-mining malware on unpatched machines. Security authorities report active exploitation after public proof-of-concept code surfaced, making it trivial for attackers to gain control without valid credentials.

A flaw that opens the door

The vulnerability resides in macOS Screen Sharing, a built-in feature that allows remote desktop access. By crafting malformed authentication requests, attackers can bypass the login screen entirely and execute arbitrary commands on the target machine, effectively turning Screen Sharing into an open window for intruders. The Netherlands’ National Cyber Security Centre (NCSC) flagged the issue after seeing exploit code published online, which dramatically lowers the barrier to entry for cybercriminals.

From stealth to payday

Once inside, attackers deploy a Monero miner that runs silently in the background, siphoning CPU cycles to generate cryptocurrency for the attackers’ wallets. Because Screen Sharing is a legitimate macOS service, the malicious process can blend in with normal system activity, making detection difficult for users who aren’t actively monitoring resource usage. Security teams warn that the same flaw could also be repurposed for data theft or ransomware, turning a mining campaign into a far more damaging breach.

Why it matters

The rapid weaponization of this flaw underscores how quickly public exploit code can escalate from a theoretical risk to a live threat. macOS users who rely on Screen Sharing—especially in enterprise environments—should treat this as an urgent patching priority. Beyond the immediate risk of stolen compute power, the episode highlights the growing trend of attackers monetizing one-day vulnerabilities before vendors can issue fixes. For organizations, it’s a reminder that even built-in services can become attack vectors when authentication mechanisms are flawed.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home