Dutch officials report root access and Monero miners on Macs with port 5900 open to the internet. Sonoma, Sequoia and Tahoe all need the update Apple shipped as an important security fix.
Perspective Coverage
5 publishers
- Builder
- Builder 22%
- Operator
- Operator 70%
- Investor
- Investor 8%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence68
The Dutch NCSC says CVE-2026-65400 was abused within two weeks of Apple's fix, with root access and Monero miners in every reported case. Patching closes the door; it does not evict anyone.
Perspective Coverage
6 publishers
- Builder
- Builder 22%
- Operator
- Operator 72%
- Investor
- Investor 6%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence62
CVE-2026-60004 turns Gitea's diffpatch API into remote code execution for anyone who can register an account. The fix is three steps, and CISA's federal deadline is August 28, 2026.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
Perspective Coverage
7 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption40
- Hype gap+20
- Incentives
- Insufficient
- Confidence58
Huntress traced a September 2026 intrusion in which the actor compiled a Monero miner on the endpoint, using a MagicINFO flaw Samsung fixed 16 months earlier. The build step is loud in telemetry, but it ran only after Defender had been disabled.
Reality
- Evidence66
- Adoption28
- Hype gap+10
- Incentives62
- Confidence58
Unit 42 committed a fresh, overly permissive AWS key to a random GitHub repository with the usual quarantine policy switched off, then timed how long a cryptojacking crew took to find it and start mining.
Reality
- Evidence52
- Adoption45
- Hype gap+30
- Incentives78
- Confidence60
Elastic documented four programs that stay in the user profile after the stealer wipes itself. The credential rotation that closes the ticket does not restore the update services or clear the Defender exclusions.
Reality
- Evidence60
- Adoption45
- Hype gap−10
- Incentives70
- Confidence58
Huntress says the modified client waits for a new host connection, then uses ScreenConnect's own file transfer and Run functions to place scripts on the operator's machine, which is why the interim guidance is a config toggle.
Reality
- Evidence55
- Adoption25
- Hype gap−5
- Incentives60
- Confidence45
MayaBot only shows up in 2022, seven years into the operation, and one branch of the funnel ends in a phone call to a scam call centre. That leaves the search referral and the redirector domains as the constants worth detecting.
Reality
- Evidence46
- Adoption54
- Hype gap+20
- Incentives45
- Confidence63
Microsoft Security Research says intruders who reached exposed LiteLLM, RAGFlow and Kestra deployments went for provider keys and database URLs first. It can name a confident initial vector in only one of the three cases.
Reality
- Evidence45
- Adoption30
- Hype gap+10
- Incentives55
- Confidence42
Ninety days of Wiz honeypot telemetry shows tooling written for LiteLLM's internals, including a config test endpoint that spawns whatever command it is handed and a miner whose output comes home inside the MCP protocol.
Reality
- Evidence62
- Adoption66
- Hype gap+12
- Incentives72
- Confidence55
Wiz says attackers are using the WebDriver API's documented remote-command features to plant a modified XMRig on internet-facing Selenium Grid nodes. Authentication is off by default.
Publishers:selenium.dev · wiz.io Reality
- Evidence74
- Adoption71
- Hype gap+14
- Incentives62
- Confidence70
Wiz says a TeamCity honeypot exposing JDWP was mining Monero within hours, and GreyNoise counted more than 6,000 unique IPs scanning for the protocol in 90 days.
Reality
- Evidence63
- Adoption52
- Hype gap+12
- Incentives70
- Confidence58
An authentication state flaw lets anyone who reaches TCP/5900 skip credentials entirely. Multiple cases reported to NCSC-NL ended in root and a Monero miner.
Reality
- Evidence34
- Adoption31
- Hype gap+18
- Incentives24
- Confidence41