Build1 distinct publisher3 min readUpdated
An authentication state flaw lets anyone who reaches TCP/5900 skip credentials entirely. Multiple cases reported to NCSC-NL ended in root and a Monero miner.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
A dev.to writeup dated 2026-08-14, summarising a BleepingComputer report, describes CVE-2026-65400 as an authentication state management flaw in macOS Screen Sharing that lets an attacker reaching the service over the internet establish a session without valid credentials [1][2][3]. In multiple cases reported to the Dutch NCSC, that session ended in root access and the installation of a Monero cryptocurrency miner [5][6].
The chain is short enough to fit in a sentence: connect to TCP/5900 from the internet, exploit the state flaw, get a remote desktop session with the ability to launch applications, read files, and change security settings [3][4]. No user interaction is required, so there is no phishing step to detect and no click to blame [8]. The preconditions are unglamorous and common: Screen Sharing enabled, TCP/5900 reachable by the attacker, patches not applied, and nothing in place to constrain execution or settings changes once a remote session exists [10]. That is a description of a lot of Mac minis and desk machines that someone port-forwarded for convenient out-of-office access.
Two operational details matter more than the CVE number. First, because valid accounts are never used, a password reset alone cannot contain the intrusion, and sessions persisting after a password change are themselves a signal worth hunting [9][19]. Second, the fix spans three separate release trains: macOS Tahoe before 26.6.1, Sequoia before 15.7.9, and Sonoma before 14.8.9 are affected, so a patch audit has to cover three version baselines rather than one [7][21]. MDM device version and compliance data is the practical way to check that state at fleet scale [18].
Containment does not depend on the details being published. Update to the fixed builds, disable Screen Sharing where it is not needed, and block TCP/5900 from the internet, restricting it to VPN or management networks [7][11]. For hunting, the listed signals are TCP/5900 connections from external IPs, Screen Sharing sessions not tied to regular accounts, unknown binaries running as root, elevated CPU or GPU usage, and outbound traffic or DNS queries to mining pools and Stratum endpoints [14][15]. Connections from a single source IP to multiple Macs, and miner pool traffic that follows a session, are the higher-confidence patterns; bare TCP/5900 scanning or SYN traffic is not [16]. If you find a hit, the triage list is standard: confirm macOS version, Screen Sharing settings, exposure path, initial source IP and timestamp, cross-reference session logs against valid login activity, and preserve process trees, launchd entries, file creations, quarantine and xattr attributes, unified logs, and network sockets [17].
Be honest about the gaps. The specific steps used to reach root, whether other vulnerabilities are involved, and how the miner persists are not publicly disclosed, and the miner's name and hash are unknown [12][6]. Data theft and lateral movement are not confirmed in public reporting either, which is not the same as ruling them out [13].
Watch for Apple and NCSC-NL, whose advisory is tracked as NCSC-2026-0280, to publish concrete IOCs and a persistence description [20][15]. Watch also for reports of one source IP hitting many Macs, which would distinguish opportunistic scanning from a campaign working a target list [16]. A miner is the cheapest possible use of root on a build machine; the access level on offer supports considerably more [4][6].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
In multiple cases reported to NCSC-NL, the attacker obtained root access.
A Monero cryptocurrency miner is installed in the reported incidents; the miner's name and hash are unknown.
A dev.to article dated 2026-08-14 summarises a BleepingComputer report headlined "Hackers exploit macOS Screen Sharing flaw to deploy Monero miner" and rates the issue Critical.
CVE-2026-65400 is an authentication state management flaw in macOS Screen Sharing exposed to the internet that allows attackers to authenticate without valid credentials.
The attacker connects to macOS Screen Sharing from the internet via TCP/5900 and exploits the authentication state flaw to establish a session without valid credentials; initial execution occurs within the Screen Sharing service and the remote GUI session.
The attacker gains the ability to launch applications, access files, and change security settings via remote desktop.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single secondhand source, no primary advisory or IOCs
Everything in the cluster traces to one dev.to post that summarises a BleepingComputer report. Apple Security and NCSC-2026-0280 are named as related sources but neither is reproduced or quoted, there is no CVE record text, no miner name or hash, and no published IOCs. The technical narrative is internally coherent and specific about versions, ports and detection signals, which lifts it above rumour, but the source itself states that root-acquisition path, persistence, exfiltration and lateral movement are unconfirmed in public data, so the strongest claims cannot be independently corroborated within this cluster.
Confirmed exploitation and shipped fix, scope unquantified
There are two concrete real-world markers: a vendor fix released across three macOS trains on 6 August 2026, and multiple NCSC-NL-reported cases in which attackers reached root and installed a Monero miner. That is more than a theoretical proof-of-concept. But nothing quantifies the footprint — no case counts, no number of internet-exposed TCP/5900 Macs, no scanning telemetry, no patch-uptake data and no victim sectors or geographies beyond the NCSC-NL reporting channel — so the observed scale stays low and unbounded.
Framing runs slightly ahead of the disclosed evidence
The direction of the story is defensible: an unauthenticated network path to a remote GUI session, root in reported cases, and a miner payload genuinely warrants urgency, and the source is unusually candid about what is unknown. The mild overstatement comes from packaging: a Critical rating and an 'already dropping miners' framing rest on one secondhand summary with no case count, no IOCs, no named miner and an explicitly undisclosed root-escalation path. Operators are handed detection and triage detail that is more precise than the underlying evidentiary chain supports.
Aggregator restating a news report, no disclosed stake
The supplied material shows a community-platform post reformatting a third-party security report into defender guidance. It sells no product, names no vendor tooling, offers no service and makes no funding or market argument, so commercial pull is low. The residual incentive is attention-driven: aggregation of a Critical-rated Apple exploitation story on a developer publishing platform benefits from urgency, and the header severity rating is asserted rather than sourced to a scoring body.
Specific and internally consistent, but unduplicated
Confidence is moderate-low. In its favour: the account is detailed, self-consistent and unusually explicit about the limits of public knowledge, and it names checkable artefacts (CVE-2026-65400, three fixed builds, an August patch date, NCSC-2026-0280). Against it: one secondhand publisher, no primary advisory text in the cluster, no IOCs, no case counts, and an escalation-to-root mechanism that is acknowledged as undisclosed. The versioning and mitigation guidance can be acted on with reasonable safety; the impact narrative should be treated as provisional pending the Apple and NCSC-NL originals.
security
Pre-auth flaw in macOS Screen Sharing turns any exposed Mac into an arbitrary file read1 distinct publisher
security
Apple patches a network-reachable Screen Sharing auth bypass in macOS Tahoe 26.6.11 distinct publisher
build
AmnesiaStealer drives your own browser, so session theft is the real macOS loss1 distinct publisher
build
Judge transactional email on retries and DKIM alignment, not open rates1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 14, 2026