Cybersecurity authorities in the Netherlands have raised fresh alarm over a critical vulnerability in Apple's Mac computers, confirming that malicious actors are actively exploiting a flaw that the tech giant patched just weeks ago. The National Cyber Security Centre reported that attackers have compromised multiple Mac systems exposed to the Internet, gaining the highest level of administrative control and installing Monero cryptocurrency-mining malware. The discovery underscores a persistent challenge in the technology ecosystem: the window between disclosure and widespread patching remains a dangerous period for users who delay updates.

The vulnerability, catalogued as CVE-2026-65400, resides in Apple's built-in Screen Sharing feature—a utility that permits remote access and control of a Mac from another device. This functionality, while convenient for IT support and remote work scenarios, becomes a security liability when exposed to the Internet without proper network protections. Attackers systematically scanned for Macs with the Screen Sharing port accessible to the public Internet, then exploited the flaw to gain root access, the highest privilege level on a computer system. Once inside, they deployed Monero-mining software that silently harnesses the machine's processing power to generate cryptocurrency for the attackers' benefit, effectively transforming each compromised device into a revenue stream at the owner's expense.

The choice of Monero as the payload is deliberate and revealing of attacker methodology. Unlike Bitcoin, which requires specialised mining hardware for profitability, Monero is explicitly designed to be mined efficiently using standard computer processors found in laptops and desktops. This accessibility makes Monero particularly attractive to cybercriminals seeking to monetise exploited systems with minimal additional investment. Attackers can compromise numerous machines and aggregate their combined processing power into a distributed mining operation, generating income with relatively low technical overhead. Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, notes that this pattern reflects criminal preference for swift monetisation when new exploits become public; the automation and scale available through malware deployment offers immediate financial returns without the complications of more elaborate attacks.

However, security experts caution that cryptocurrency mining may represent only the most visible activity on compromised systems. With root access secured, attackers gain a comprehensive window into a Mac's data stores and operational systems. They can extract sensitive files, capture stored login credentials, intercept cloud service tokens that provide access to backup systems and cloud storage, and potentially pivot to connected networks and devices. The Monero miner may function as a deliberate distraction—a visible but relatively benign activity that could mask deeper exploitation of a victim's files, communications, and personal information. This stratified approach to compromise, where obvious malicious activity conceals more sophisticated espionage, represents a significant concern for businesses and individuals storing sensitive data on their Macs.

Apple's initial response to the vulnerability's discovery suggested the risk was contained. The company told media outlets it had no evidence of the flaw being exploited beyond controlled test environments, a statement that proved premature. The transition from theoretical vulnerability to active exploitation in the wild marks a critical juncture in the flaw's lifecycle. The company issued patches outside its normal monthly update schedule, a deviation that typically signals exceptional urgency among Apple's security leadership. Subsequent confirmation from Dutch authorities that exploitation had begun in earnest validates that escalated response and reinforces the danger of assuming undiscovered vulnerabilities remain unexploited simply because evidence has not yet emerged.

The patched versions span multiple macOS generations, reflecting the flaw's broad reach across Apple's product ecosystem. Users operating macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9 have received the fix and need only apply it through their Systems Settings interface. The update path is straightforward: navigating to System Settings, accessing General, and selecting Software Update to download and install available patches. Yet this simplicity masks a persistent problem—many users defer updates due to inconvenience, fear of compatibility issues, or simple inattention, leaving their systems vulnerable long after patches become available. The Netherlands' disclosure suggests that window of vulnerability has closed for some organisations, while others remain exposed.

For individuals and organisations whose Macs possessed Screen Sharing enabled and Internet accessibility before patching, proactive investigation is now essential. Hegel emphasises that applying patches halts future compromise through this particular flaw but does not eliminate Monero miners already installed or undo actions attackers may have performed. Organisations must audit their systems for signs of compromise, including unusual processor usage (miners consume significant CPU resources), unexpected network traffic, and system logs indicating unauthorised access attempts or suspicious processes running with root privileges. Forensic examination becomes necessary for any machine that was vulnerable and reachable from the Internet during the exploitation window.

Network architecture plays a crucial role in determining exposure levels. The majority of home networks feature routers and firewalls configured by default to block inbound connections to computer systems, providing an effective barrier against direct attacks targeting Screen Sharing. Consequently, not every Mac faces equal risk; exposure correlates with specific configurations—machines with port forwarding enabled to permit remote access, servers deliberately exposed to the Internet, or systems protected by insufficiently restrictive firewalls. However, the federal assessment assigning the vulnerability a severity score of 9.8 out of 10 reflects the catastrophic potential when vulnerable machines do become accessible. This scoring reflects that successful exploitation requires neither valid credentials nor user interaction, meaning an automated attack can compromise a system instantly upon finding an exposed vulnerable Mac.

Disabling Screen Sharing altogether represents an alternative for users who do not require the feature. Users can navigate to System Settings > General > Sharing and deactivate Screen Sharing to eliminate the attack surface entirely. This approach suits home users and organisations whose operational requirements do not depend on remote Mac access. For those requiring Screen Sharing functionality, patching remains the only viable mitigation, alongside network controls that restrict Screen Sharing port access to authorised users and known IP addresses. The disclosure highlights a broader lesson for Mac users across the region: the luxury of perceived stability and lower malware incidence must not breed complacency about patch management. The Mac ecosystem's growth has attracted increasing attacker attention, and the appetite for exploits targeting macOS continues expanding alongside the platform's market share.