The cybersecurity landscape has shifted into more urgent territory for Apple users, as threat actors have begun actively exploiting a critical flaw in the company's Screen Sharing feature. According to the Netherlands' National Cyber Security Centre, attackers have successfully breached multiple Mac computers connected to the Internet, leveraging a vulnerability that Apple only addressed earlier this month. In each instance documented by Dutch authorities, the intruders secured the highest level of system control and proceeded to install Monero mining software—turning unsuspecting owners' machines into illicit computing resources for generating cryptocurrency profits.

The vulnerability, designated CVE-2026-65400, represents a significant security oversight in one of Apple's foundational remote access tools. Screen Sharing, a built-in macOS feature that enables users to view and control a Mac from another computer, became the entry point for these attacks. What distinguishes this exploit from many others is how swiftly it has moved from theoretical threat to active real-world deployment. When Apple initially disclosed the flaw, the company stated it had no evidence of exploitation beyond controlled testing environments—a reassurance that has now evaporated in light of the Netherlands' findings.

Apple has distributed patches across multiple macOS versions to address the vulnerability: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. The decision to release the patch outside Apple's normal update schedule underscored the severity of the threat, a signal that was apparently well-warranted. The vulnerability carries a federal severity rating of 9.8 out of 10—the second-highest possible score—because attackers can exploit it without requiring user credentials or interaction. This means a vulnerable Mac need only be reachable from the internet to become a target.

The choice of Monero cryptocurrency as the attackers' payload provides insight into the economics of modern cybercrime. Unlike Bitcoin or Ethereum, which rely on specialised graphics processing units and dedicated mining hardware, Monero is specifically designed to be mined using standard computer processors. This computational flexibility makes it ideal for criminals who compromise consumer devices, as they can extract value from ordinary machines without the technical limitations that plague other cryptocurrencies. The attackers are essentially monetising the processing power of compromised Macs with minimal friction and risk.

However, security researchers caution that mining may represent only the visible surface of these attacks. Tom Hegel, a threat researcher at SentinelOne's research division, emphasises that root access—the level of control these attackers obtained—opens far broader possibilities for malicious activity. With such elevated privileges, intruders can access sensitive files, harvest saved login credentials, compromise cloud authentication tokens, and pivot laterally to connected systems. The Monero miner serves as an obvious indicator of compromise, but criminal actors with root access might simultaneously be conducting espionage, data theft, or establishing persistent backdoors for future exploitation. From the attacker's perspective, mining is merely the most straightforward and passive way to extract immediate value while covering their tracks with a plausible technical explanation for unusual system activity.

The geographic concentration of reported attacks in the Netherlands is particularly instructive. The targeted Macs all had Screen Sharing ports exposed directly to the public internet—a configuration that suggests either deliberate exposure by security-conscious users or the result of misconfigured firewalls and routers. Most home network setups and corporate firewalls block inbound connections to such ports by default, which provides a layer of protection for the majority of Mac users. Nevertheless, the mere existence of any exposed devices means the attack surface remains active and exploitable. Network administrators and individual users operating outside standard security configurations face elevated risk.

For Malaysian users and regional business managers, the implications warrant immediate attention. Many organisations across Southeast Asia maintain mixed-platform environments with Apple devices, particularly among executive and technical staff. The critical severity rating and active exploitation status elevate this beyond typical security advisories into the realm of urgent threat response. Users should access System Settings, navigate to General, and proceed to Software Update to download and install the latest available patches. Those running older macOS versions should prioritise this task, as older systems may lack concurrent security hardening measures that would mitigate the exploitation attempt.

Beyond immediate patching, users should evaluate their Screen Sharing configuration. Anyone not actively utilising the Screen Sharing feature can disable it entirely by accessing System Settings, selecting General, then Sharing, and toggling off the Screen Sharing option. This eliminates the attack vector entirely for those who do not require remote access capabilities. Organisations managing fleet deployments should consider whether Screen Sharing aligns with their security posture and access policies, potentially disabling it enterprise-wide if remote access can be accomplished through more secure mechanisms.

A particularly troubling aspect of this situation concerns systems that may already be compromised. Phil Stokes, a macOS security researcher at SentinelOne, notes that patching addresses the vulnerability itself but does nothing to remove malware or reverse actions already undertaken by attackers. Organisations whose Macs had Screen Sharing enabled and internet-facing before receiving patches should conduct forensic investigations to determine whether their systems were compromised during the window of vulnerability. This might involve reviewing system logs for unusual access, checking for signs of cryptocurrency-mining activity through elevated processor usage or heat generation, and auditing file system changes for evidence of persistence mechanisms.

The timing of this vulnerability and its active exploitation arrives during a period of increasing cybercriminal interest in compromising consumer and business devices for cryptomining purposes. The technique represents a mature monetisation strategy in the criminal economy, requiring minimal technical sophistication once an initial compromise is achieved. As long as cryptocurrency maintains market value and energy costs remain reasonable for attackers, mining malware will continue to represent an attractive target for threat actors seeking quick financial returns.

Looking forward, this incident reinforces several enduring cybersecurity principles that remain relevant across the region. First, network architecture matters enormously—services should not be exposed to the public internet unless absolutely necessary and properly secured. Second, patch management requires urgency, not convenience; delaying security updates transforms vulnerabilities from theoretical risks into practical liabilities. Third, security awareness among users and administrators drives operational resilience. For Malaysian businesses, regional organisations, and individual users, the immediate imperative is straightforward: update macOS systems now, review configuration settings to disable unnecessary services, and monitor systems for signs of compromise. The threat is real, actively being exploited, and within reach of any Mac connected to the internet without current patches.