CuraSec

Act active

macOS Screen Sharing auth bypass exploited to drop Monero miner

2026-08-15 11:32 UTC · BleepingComputer · read the source ↗ #macos#cryptomining#cve
  • Engineer — Act: Active exploitation with public PoC — audit your macOS fleet for Screen Sharing (VNC) exposure and apply Apple’s patch immediately; disable Screen Sharing on hosts where it isn’t required.
  • SOC/IR — Act: Hunt for unexpected xmrig or Monero miner processes on macOS endpoints and check for anomalous outbound connections to mining pools since the PoC went public.
  • Leader — Learn: Active cryptomining campaign on macOS is unlikely to require board-level action, but confirms macOS is not a safe-harbor — useful context for endpoint policy discussions.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.