A CVSS 9.8 in macOS Screen Sharing let anyone on the network in without a password — and the payload was a crypto miner
2026-08-18Gadgets
CVE-2026-65400 bypasses credential validation on Apple's remote desktop service. The Dutch NCSC confirmed exploitation against internet-exposed Macs with port 5900 open, and what turned up was root access and a Monero miner.