A critical vulnerability in Apple's operating system has moved from theoretical risk to active exploitation in the wild, with cybersecurity authorities in the Netherlands documenting multiple attacks targeting Mac computers connected to the internet. The flaw, identified as CVE-2026-65400, resides in macOS's built-in Screen Sharing feature—a remote access tool that permits one computer to view and control another Mac from a distance. Although Apple released patches earlier this month for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, attackers have already begun systematically exploiting unpatched systems to steal computational resources for personal gain.

The Netherlands' National Cyber Security Centre has identified a disturbing pattern in these attacks. Once hackers breach a vulnerable Mac through the Screen Sharing port, they acquire root access—the deepest level of system control available—and immediately deploy Monero cryptocurrency-mining software. This malware then runs silently in the background, hijacking the computer's processor to generate digital currency that flows directly into the attackers' wallets. Mac users whose systems fall victim to this scheme effectively become unwitting donors, subsidising criminal cryptocurrency operations through their hardware's computing power and elevated electricity consumption.

Monero, a privacy-focused cryptocurrency, has become the preferred target for this particular exploitation method due to its fundamental design. Unlike Bitcoin and many other cryptocurrencies that require specialised hardware called ASICs to mine profitably, Monero is deliberately engineered to be mined using standard computer processors found in everyday machines like Macs and PCs. This accessibility makes compromised consumer devices far more economically attractive to criminal operators seeking quick monetisation of their exploits. The choice of Monero underscores how the digital currency landscape itself shapes cybercriminal behaviour and targeting decisions.

Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, explains that the deployment of cryptocurrency miners represents a logical escalation now that the vulnerability has become public knowledge. Criminals seeking to automate attacks and quickly convert compromised systems into profit-generating assets view miners as low-friction monetisation tools requiring minimal additional work once initial access is secured. However, Hegel cautions that the visible mining activity may mask more sinister intentions. With root access firmly established, attackers gain the ability to pilfer sensitive files, harvest stored credentials, intercept cloud authentication tokens, and potentially pivot to other systems on connected networks. The cryptocurrency miner might simply be the most obvious and resource-intensive payload, obscuring simultaneous theft of valuable data that could prove far more damaging than the computational theft alone.

Apple's initial response to the vulnerability suggested the company expected it would remain largely theoretical. When first informed of the flaw, Apple stated it had no evidence of the vulnerability being exploited outside controlled testing environments. That assessment has proven dramatically incorrect. The Netherlands' cybersecurity authorities have now documented genuine real-world attacks, transforming this from a patching recommendation into an urgent security crisis. The disconnect between Apple's initial assurances and the rapid emergence of active exploitation illustrates how quickly security researcher findings can be operationalised by criminal groups once disclosure occurs.

The specific technical details of the vulnerability contribute to its severity rating. Federal cybersecurity assessments have assigned CVE-2026-65400 a critical severity score of 9.8 out of 10—a near-maximum rating indicating that attackers need neither valid user credentials nor any form of user interaction to trigger successful exploitation. The vulnerability is unauthenticated, meaning simply having the Screen Sharing port accessible from the internet provides sufficient opportunity for compromise. This combination of factors explains why Apple expedited its patch release outside the normal monthly update cycle, a departure that should have signalled the urgency of the threat to observant users and system administrators.

For Malaysian Mac owners and businesses operating across Southeast Asia, understanding exposure patterns is critical to assessing personal risk. The documented attacks in the Netherlands specifically targeted Macs whose Screen Sharing port was reachable from the public internet—a scenario that depends heavily on network configuration. Most consumer-grade routers and corporate firewalls block such connections by default, providing implicit protection for machines behind standard security infrastructure. However, organisations that have intentionally opened these ports for legitimate remote management purposes, or individuals running Macs with router port forwarding rules configured, face substantially elevated risk. Even small businesses relying on remote work arrangements may inadvertently expose vulnerable machines while attempting to facilitate productivity.

The technical remediation pathway is straightforward but demands immediate action. Mac users can access patches through System Settings > General > Software Update, where the latest operating system versions containing the fix are available. For those who have never utilised the Screen Sharing feature, an additional protective measure involves disabling the service entirely through System Settings > General > Sharing, eliminating the attack surface altogether. However, security professionals emphasise that patching alone does not constitute a complete response for organisations that operated vulnerable systems before protection was applied.

Phil Stokes, a SentinelOne research engineer specialising in macOS threats, has previously highlighted that Apple's decision to release the patch outside its standard update schedule already telegraphed the severity. Yet many users and organisations operate on less aggressive update schedules, creating windows of vulnerability that determined attackers have already begun exploiting systematically. For businesses whose Macs had Screen Sharing enabled and internet-reachable prior to patching, the situation requires forensic investigation. Hegel warns that applying patches closes the vulnerability but does not automatically remove malware already installed or reverse actions attackers have executed. Compromised systems may require professional security assessments to determine whether cryptocurrency miners were installed during the exposure window, and whether any additional persistent access mechanisms were established for future exploitation.

The broader implication for users throughout Southeast Asia extends beyond individual machines. As regional economies increasingly digitise and businesses expand remote work capabilities, the attack surface for vulnerabilities like this expands correspondingly. Malaysian enterprises operating in finance, technology, and professional services sectors—where remote Mac usage is particularly prevalent—should prioritise immediate patch deployment and conduct security audits of systems that may have been exposed. This incident demonstrates how quickly vulnerabilities transition from academic discoveries to active criminal exploitation, underscoring the critical importance of maintaining current software regardless of the inconvenience patching may entail.