Cybersecurity authorities in the Netherlands have documented a troubling shift in the digital threat landscape: criminals are now actively leveraging a critical vulnerability in Apple's macOS to commandeer personal computers for illicit cryptocurrency mining operations. The flaw, which Apple addressed in an emergency patch earlier this month, has moved from theoretical concern to practical exploitation in the wild, with attackers systematically targeting Mac systems exposed to the internet and installing Monero-mining software that converts compromised devices into profit-generating machines at their owners' expense.

The vulnerability, designated CVE-2026-65400, resides in Apple's built-in Screen Sharing feature, a widely-used utility that permits remote access and control of Mac computers across networks. According to the Netherlands' National Cyber Security Centre, attackers have successfully exploited this flaw on multiple occasions, achieving root access—the highest administrative privilege level on a computer system. Once they gain this unrestricted access, intruders have installed mining software designed to harvest the processing power of ordinary computer hardware to generate Monero cryptocurrency tokens, a process that runs continuously and invisibly to the user whilst consuming computational resources and electricity.

Monero, a privacy-focused cryptocurrency, has become the miner of choice for this category of cybercriminal activity because, unlike Bitcoin or Ethereum, it can be efficiently mined using standard computer processors rather than specialised hardware. This characteristic makes Monero particularly attractive for attackers seeking to monetise compromised systems quickly and with minimal technical sophistication. The attackers are essentially converting thousands of innocent Mac owners' computers into part of a distributed mining network, generating revenue whilst degrading device performance and accumulating electricity costs borne entirely by the victims.

Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, has cautioned that the cryptocurrency mining installation may represent only the most visible dimension of these intrusions. With root-level access fully established, malicious actors possess the capability to access sensitive files, extract stored credentials, compromise cloud authentication tokens, and potentially pivot to compromise connected systems on corporate or home networks. The Monero miner, Hegel emphasises, may be merely the most obvious sign of compromise, obscuring more sophisticated and potentially damaging activities taking place simultaneously on affected systems.

The situation represents a stark deterioration from Apple's initial assessment. When the vulnerability first entered the public domain, the technology giant told media outlets that it was unaware of any active exploitation occurring outside controlled testing environments. That reassurance has proven premature. The Dutch authorities' discovery of systematic, real-world exploitation marks a significant escalation that should prompt immediate action among Mac users globally, including those in Southeast Asia and Malaysia where Apple device adoption continues to grow.

The compromised systems identified by Dutch authorities all shared a specific characteristic: their Screen Sharing ports were accessible directly from the public internet, an unusual configuration for most consumers whose home routers typically block such connections by default. However, the presence of this exposure in some cases—particularly among businesses, organisations, and users running non-standard network configurations—creates sufficient attack surface for criminals to identify and target vulnerable machines systematically using automated scanning tools. The federal assessment of this vulnerability assigns it a critical severity rating of 9.8 out of 10, indicating that attackers can achieve exploitation without possessing valid credentials or requiring any interaction from the user, making it exceptionally dangerous.

Apple has released patches across multiple macOS versions: Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 all contain the necessary security fix. Users can apply these updates by navigating to System Settings, selecting General, and then Software Update. For those who do not utilise Screen Sharing functionality, an additional layer of protection exists through disabling the feature entirely via System Settings > General > Sharing, eliminating the attack vector at its source. The emergency release of this patch outside Apple's normal update schedule, noted by security researcher Phil Stokes of SentinelOne, already suggested to knowledgeable observers that the vulnerability represented an unusually grave threat requiring accelerated remediation.

Yet patching alone does not constitute a complete response for organisations and businesses whose Mac systems may have already been compromised before security updates were applied. Hegel stresses that whilst the patch closes the vulnerability, it does not automatically remove malware or undo actions that attackers have already executed on infected machines. Systems that had Screen Sharing exposed to the internet prior to patching should be subjected to forensic analysis and malware scanning to identify whether unauthorised access has already occurred, what data may have been accessed or stolen, and whether additional malicious software persists on the system.

For Malaysian users and Southeast Asian businesses operating significant numbers of Apple devices, this incident carries particular relevance as companies increasingly adopt Mac computers for their workforces and as individual device ownership grows. The attack demonstrates that no platform—regardless of reputation or perceived security advantages—remains immune to exploitation when users delay applying critical security updates. The incident also underscores the importance of network security practices, particularly for organisations, ensuring that management and administrative services do not become unnecessarily exposed to the public internet where automated attack tools can discover and target them.

The broader lesson extends beyond this specific vulnerability. Organisations managing macOS environments should establish policies ensuring timely application of security patches, particularly when vendors issue updates outside their normal release schedules. Users operating devices with sensitive information should verify that Screen Sharing and other remote access services are disabled unless specifically required, and should monitor system performance for unexpected slowdowns that might indicate mining operations or other malicious processes running in the background.

The discovery of active exploitation also highlights the value of defensive monitoring by government cybersecurity agencies. The Netherlands' rapid identification and public disclosure of this attack pattern potentially prevented thousands of additional compromises by alerting the global security community and prompting urgent action from affected users. For those who have not yet updated their systems, the window for safe, proactive patching remains open—but every delay increases the probability that their devices have already been infiltrated and are currently being utilised for cryptocurrency generation without their knowledge or consent.