View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Hackers exploit macOS Screen Sharing bypass to deploy Monero miners

๐Ÿšจ ACTIVE EXPLOITATION

  • Hackers exploit macOS Screen Sharing bypass to deploy Monero miners CVE-2026-65400 Hackers are exploiting a macOS Screen Sharing authentication bypass to deploy Monero miners.
    • macOS Tahoe, Sequoia, and Sonoma systems with Screen Sharing enabled are affected.
    • CVE-2026-65400 allows network attackers to access Screen Sharing without valid credentials.
    • Attacks target internet-exposed TCP port 5900 after public exploit code emerged.
    • Attackers obtained root access and installed Monero cryptocurrency miners. ๐Ÿ“„ Source: support.apple.com ยท ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Week 33 roundup covers sextortion, Gunra ransomware and Defender bypass SentinelOne highlighted a sextortion conviction, Gunra ransomware, and a Microsoft Defender bypass.
    • The case involved a convicted member who sextorted 117 minors.
    • A joint advisory warned about Gunra ransomware.
    • ShieldBreak bypasses Microsoft Defender to obtain SYSTEM access.
    • The bypass affects environments relying on Microsoft Defender. ๐Ÿ“Ž Coverage: sentinelone.com ยท ๐Ÿ‘ via SentinelOne Blog

๐Ÿ“‹ ADVISORIES

๐Ÿ”“ CVEs & KEV

  • CVE-2026-73673 โ€” CVSS 8.7 โ€” Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptogra...
  • CVE-2026-19870 โ€” CVSS 8.6 โ€” IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check