Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exploiting the CVE-2026-65400 Vulnerability: A Critical Authentication Issue in Apple macOS


Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner - A critical authentication issue in Apple macOS has been exploited in the wild, allowing attackers to gain unauthorized access to systems without valid credentials.

  • A critical authentication issue was discovered in Apple macOS, CVE-2026-65400, allowing attackers to authenticate to remote desktop without valid credentials.
  • A post-authentication bug was identified, requiring the target Mac to have Screen Sharing or Remote Management enabled with specific VNC password settings.
  • A pre-authentication vulnerability was discovered in the Screen Sharing daemon, allowing attackers to gain access to Macs with Screen Sharing enabled.
  • Around 40,000 open Screen Sharing hosts were found on the internet, mostly residential IPs and university servers.
  • Users are advised to update their systems to the latest version, turn off Screen Sharing, or enable SSH to secure their systems.
  • The incident highlights the ongoing threat of AI-powered attacks and the importance of responsible disclosure in the cybersecurity community.
  • Staying informed and taking proactive steps to secure systems can significantly reduce the risk of falling victim to these types of attacks.



  • The threat landscape has been marked by a recent vulnerability in Apple macOS that has come under active exploitation in the wild. The vulnerability in question is CVE-2026-65400, a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to authenticate to the built-in remote desktop feature service without valid credentials. This vulnerability was addressed as part of an emergency update in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 earlier this month.

    The vulnerability, according to the Netherlands National Cyber Security Centre (NCSC), was discovered by security researcher Alfredo Pesoli of Bynario. Pesoli described the vulnerability as a post-authentication bug that requires the target Mac to have Screen Sharing or Remote Management enabled with "VNC viewers may control screen with password" configured and the attacker is already in possession of that VNC password. The problem, Pesoli noted, resides in a legacy Screen Sharing authentication path involving VNC password access that turns a file copy operation into protected file disclosure, arbitrary root file creation, and remote root command execution.

    However, a security researcher who goes by the online alias @osxreverser pointed out that the real issue is a pre-authentication vulnerability in the Screen Sharing daemon ("screensharingd") that makes it possible to pwn any Mac that has Screen Sharing enabled without having to know the password or anything else. The researcher noted that they had been sitting on the bug "for a while" and that they did not report the issue to Apple "given my long history with them."

    @osxreverser also mentioned that they had found around 40k open screen sharing hosts on the internet, almost half in the U.S., most are residential IPs but there are many juicy hosts in Murican universities, some companies, a server from BBEdit company. The researcher advised that users should party hard, never expose those services unless behind SSH.

    The vulnerability, CVE-2026-65400, is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws. What's interesting here is that both of them reside in the same source code file, per Calif.

    In a recent update, the NCSC-NL reported that they have received a report indicating active abuse of the vulnerability across multiple systems on which port 5900 was accessible from the internet. In all these cases, root had gained access to the affected system and placed a Monero crypto miner.

    The vulnerabilities, CVE-2026-43779, CVE-2026-43777, and CVE-2026-43760, were all patched by Apple with macOS Tahoe 26.6. The latter of these was described by Pesoli as a post-authentication bug that requires the target Mac to have Screen Sharing or Remote Management enabled with "VNC viewers may control screen with password" configured and the attacker is already in possession of that VNC password.

    In light of this vulnerability, users are advised to update their systems to the latest version for optimal protection. If immediate patching of the flaw is not possible, it's advised to turn off Screen Sharing by navigating to General > Sharing > Toggle Screen Sharing from "Content & Media."

    The recent exploitation of the CVE-2026-65400 vulnerability highlights the ongoing threat of AI-powered attacks in the cybersecurity landscape. AI can find and chain vulnerabilities in minutes, making it a significant challenge for security teams to keep up with the pace of new threats. As the threat landscape continues to evolve, it is essential for organizations to stay vigilant and proactive in their approach to cybersecurity.

    The incident also underscores the importance of responsible disclosure in the cybersecurity community. Researchers and security professionals have a critical role to play in identifying and reporting vulnerabilities to the relevant parties. However, it is equally important to ensure that this process is carried out in a responsible and timely manner, taking into account the potential impact on users and the broader cybersecurity ecosystem.

    In conclusion, the recent exploitation of the CVE-2026-65400 vulnerability serves as a stark reminder of the ongoing threat of AI-powered attacks in the cybersecurity landscape. As AI continues to play an increasingly prominent role in the threat landscape, it is essential for organizations and individuals to stay vigilant and proactive in their approach to cybersecurity. By staying informed and taking proactive steps to secure their systems, users can significantly reduce their risk of falling victim to these types of attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exploiting-the-CVE-2026-65400-Vulnerability-A-Critical-Authentication-Issue-in-Apple-macOS-ehn.shtml

  • https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-65400

  • https://www.cvedetails.com/cve/CVE-2026-65400/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-43779

  • https://www.cvedetails.com/cve/CVE-2026-43779/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-43777

  • https://www.cvedetails.com/cve/CVE-2026-43777/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-43760

  • https://www.cvedetails.com/cve/CVE-2026-43760/


  • Published: Mon Aug 17 07:12:31 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us