Vulnerability giving attackers full control of Macs is under active exploitation
ID: c00c0544-7c48-53fc-a61a-1d5ee28f6196
STIX ID: report--c00c0544-7c48-53fc-a61a-1d5ee28f6196
Feed Name: Ars Technica Security (category)
Threat Score
Dutch authorities report active exploitation of CVE-2026-65400, a macOS screen-sharing vulnerability (severity 7.1) that can allow remote attackers to gain root on machines with port 5900 exposed; observed intrusions installed a Monero crypto miner and Apple has issued patches for Tahoe, Sequoia, and Sonoma.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
