Skip to content

Topic

Cryptojacking

Intrusions monetized by installing cryptocurrency miners such as Monero miners on compromised hosts.

Current stories

product5 publishers

Apple's quiet Screen Sharing fix is now a same-day job: CVE-2026-65400 is under active abuse

Dutch officials report root access and Monero miners on Macs with port 5900 open to the internet. Sonoma, Sequoia and Tahoe all need the update Apple shipped as an important security fix.

Perspective Coverage

5 publishers
Builder
Builder 22%
Operator
Operator 70%
Investor
Investor 8%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence68
security6 publishers

macOS Screen Sharing bug exploited in the wild: if port 5900 was open, assume root was taken

The Dutch NCSC says CVE-2026-65400 was abused within two weeks of Apple's fix, with root access and Monero miners in every reported case. Patching closes the door; it does not evict anyone.

Perspective Coverage

6 publishers
Builder
Builder 22%
Operator
Operator 72%
Investor
Investor 6%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence62
security7 publishers

Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers

Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.

Perspective Coverage

7 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption40
Hype gap+20
Incentives
Insufficient
Confidence58