Cybersecurity authorities in the Netherlands have confirmed that attackers are actively exploiting a Mac vulnerability that Apple patched earlier this month, underscoring once again the critical importance of keeping devices updated with the latest security fixes. The discovery represents a tangible threat to Mac users worldwide, including those in Malaysia and across Southeast Asia who may not yet realize their systems are at risk.
The vulnerability in question affects Apple's built-in Screen Sharing feature, a tool designed to allow remote access and control of Mac computers. According to the Netherlands' National Cyber Security Centre, threat actors have successfully targeted multiple Macs that were exposed to the Internet through this service. In each confirmed case, the attackers achieved root access—the highest level of system control—before deploying Monero cryptocurrency-mining software to exploit the compromised machines' processing power.
Monero, a privacy-focused digital currency, has become the preferred target of cybercriminals engaged in illicit mining operations precisely because it can be mined efficiently using standard computer processors rather than specialized hardware. By compromising Mac systems, attackers effectively commandeer the machines' computational resources to generate cryptocurrency revenue at the expense of legitimate owners who bear the costs of increased electricity consumption and hardware wear. This represents a form of stolen computational labor that many users may not immediately notice on their systems.
Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, explained that the use of Monero miners aligns with typical attacker behavior following the public disclosure of new vulnerabilities. Criminals exploit newly revealed security flaws to automate attacks and install mining software for what Hegel describes as "immediate, relatively low-friction monetisation." However, Hegel issued an important caution: the visible cryptocurrency mining activity may represent only the most obvious malicious payload. Armed with root access, attackers could potentially access sensitive files, steal stored credentials, compromise cloud authentication tokens, or establish footholds for lateral movement into connected systems and networks.
The shift from theoretical exploitation to real-world attacks marks a significant escalation in the threat timeline. When Apple initially disclosed the vulnerability, the company stated it was "not aware of this issue being exploited outside of test environments." This represented a relatively narrow window during which organizations and individuals could deploy protective measures before criminal exploitation began in earnest. That window has now closed, making immediate action essential for all Mac users.
The flaw, catalogued as CVE-2026-65400, specifically undermines the security of Apple's Screen Sharing functionality, a feature that provides remote desktop capabilities similar to tools used by legitimate IT support teams. Apple addressed the vulnerability across multiple operating system versions: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. The breadth of affected versions indicates that this was a widespread security issue affecting Mac users across different hardware generations and user segments.
Mac users seeking to protect themselves should navigate to System Settings, select General, then choose Software Update to install the latest patches. Those who do not utilize Screen Sharing functionality can provide an additional layer of protection by disabling the feature entirely through System Settings > General > Sharing. This straightforward approach eliminates the attack vector entirely for users who have no legitimate need for remote access capabilities.
Beyond installing patches, Hegel emphasized that organizations and businesses whose Mac systems had Screen Sharing enabled and Internet-accessible before applying security updates must investigate whether their machines were already compromised. Applying a patch closes the vulnerability but does not reverse any actions an attacker may have already completed or eliminate malware that may already reside on the system. A thorough forensic examination becomes necessary to determine the full scope of any potential breach.
The attacks documented by Dutch authorities specifically targeted Macs whose Screen Sharing ports were reachable directly from the public Internet. Most home routers and corporate firewalls implement default configurations that block such external connections, meaning that not all Mac systems face equivalent exposure. However, organizations running servers, development machines, or remote work infrastructure may have intentionally configured Screen Sharing for legitimate remote administration purposes, placing those systems at substantially higher risk.
Despite the apparent rarity of Screen Sharing being accessible from the Internet, the vulnerability carries exceptional severity once a machine becomes reachable. Federal cybersecurity assessments have assigned the flaw a critical severity score of 9.8 out of 10, reflecting the ease of exploitation and the lack of required credentials or user interaction necessary to trigger the attack. This means that once an attacker locates a vulnerable and exposed Mac, they can compromise it almost effortlessly.
Phil Stokes, a SentinelOne security researcher specializing in macOS threats, noted that Apple's decision to issue an out-of-cycle patch ahead of its normal release schedule already signaled the urgency surrounding this vulnerability. "What matters is whether they can reach the Screen Sharing service," Stokes previously stated. Dutch authorities have now confirmed that attackers have indeed successfully located and reached the Screen Sharing service on multiple occasions, validating the concern that drove Apple's accelerated patch release schedule.
For Malaysian and Southeast Asian Mac users, this incident serves as a powerful reminder that security vulnerabilities do not respect geographical boundaries. The attacks documented in Europe represent a proof-of-concept that the same tactics can be deployed against systems anywhere in the world. Users should treat the availability of security patches not as optional maintenance but as critical infrastructure for protecting their digital assets and preserving system integrity. The window for safe exploitation of this vulnerability by attackers remains open for every Mac system not yet updated.
