A macOS Zero-Day Is Being Exploited to Mine Monero

A macOS flaw that attackers found before Apple did is being exploited to mine Monero on other people's computers. The bug, tracked as CVE-2026-65400, sits in the operating system's built-in Screen Sharing service and hands an attacker root access, the deepest level of control a machine can give, on Macs whose Screen Sharing is reachable from the open internet. Apple has shipped emergency patches. CISA, the US cybersecurity agency, raised the flaw's severity score to 9.8 out of 10 as the attacks ran. The goal is cryptojacking: mining cryptocurrency on hardware the attacker does not own, at the owner's expense.
The way in
Screen Sharing is the remote-desktop feature built into every Mac, off by default but commonly enabled on machines that get administered from afar. The reported attack path targets Macs where the service is switched on and exposed to the internet. Exploiting the flaw against such a machine yields remote root, and from there the intruders install their payload. TechTimes reported the active exploitation on Saturday, urging users in its headline to patch now. The Hacker News and Tom's Hardware carry the technical detail.
The payload is an XMRig-class miner, a variant of the open-source program behind most illicit Monero mining. Nothing about a miner announces itself. There is no ransom note and no contact with the victim, just a machine that runs hot, drains its battery and pushes up the power bill while its processor earns coins for someone else. Infections of this kind can run for months unnoticed, and the economics reward scale over stealth against any single target.
Why the coin is always Monero
Bitcoin cannot be mined meaningfully on a laptop; that work moved to specialized hardware years ago. Monero was designed to resist such hardware, keeping its mining practical on the ordinary CPUs found in every hijacked machine. It is also a privacy coin, built so that transactions hide the sender, the receiver and the amount, which makes proceeds hard to trace once they leave the infected fleet. That combination has kept Monero the default currency of cryptojacking for years, and this campaign fits the pattern exactly.
What 9.8 means
Severity scores top out at 10, and 9.8 is the bracket for bugs that can be attacked over the network and end in total compromise of the machine. CISA moving CVE-2026-65400 to that mark while exploitation is live is about as loud as the agency's signaling gets. The defensive list is short. Install Apple's emergency update, and ask whether Screen Sharing needs to be on at all. A Mac with the service disabled, or one not exposed to the internet, sits outside the attack path the coverage describes.
A quiet crime in a loud week
How many Macs are already mining for someone else is not public. None of the Saturday coverage carries an infection count, so the campaign's scale stands unverified. The shape of the week around it is clearer. Attackers drained about $8 million from Coinsbuy days earlier, and Galaxy spent early August still counting victims of the Coldcard exploit. Cryptojacking is the gentler cousin of those thefts. It takes electricity instead of coins. The patch, at least, is already out, which is more than most of this month's security stories can offer.