Hackers weaponize macOS flaw to secretly mine Monero

Hackers have taken a recently disclosed macOS authentication bypass vulnerability and turned it into a stealthy backdoor for installing Monero-mining malware on unpatched machines. Security authorities report active exploitation after public proof-of-concept code surfaced, making it trivial for attackers to gain control without valid credentials.
A flaw that opens the door
The vulnerability resides in macOS Screen Sharing, a built-in feature that allows remote desktop access. By crafting malformed authentication requests, attackers can bypass the login screen entirely and execute arbitrary commands on the target machine, effectively turning Screen Sharing into an open window for intruders. The Netherlands’ National Cyber Security Centre (NCSC) flagged the issue after seeing exploit code published online, which dramatically lowers the barrier to entry for cybercriminals.
From stealth to payday
Once inside, attackers deploy a Monero miner that runs silently in the background, siphoning CPU cycles to generate cryptocurrency for the attackers’ wallets. Because Screen Sharing is a legitimate macOS service, the malicious process can blend in with normal system activity, making detection difficult for users who aren’t actively monitoring resource usage. Security teams warn that the same flaw could also be repurposed for data theft or ransomware, turning a mining campaign into a far more damaging breach.
Why it matters
The rapid weaponization of this flaw underscores how quickly public exploit code can escalate from a theoretical risk to a live threat. macOS users who rely on Screen Sharing—especially in enterprise environments—should treat this as an urgent patching priority. Beyond the immediate risk of stolen compute power, the episode highlights the growing trend of attackers monetizing one-day vulnerabilities before vendors can issue fixes. For organizations, it’s a reminder that even built-in services can become attack vectors when authentication mechanisms are flawed.
Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

