Cybersecurity officials in the Netherlands have confirmed that attackers are actively leveraging a recently patched vulnerability affecting Apple computers, turning compromised machines into cryptocurrency-mining operations. The National Cyber Security Centre disclosed that the Screen Sharing flaw, which Apple addressed earlier this month, has moved from theoretical risk to real-world attacks. In every documented case, intruders gained root-level access to affected Macs and deployed Monero-mining software that silently drains processing power and resources at the expense of legitimate owners.

The vulnerability tracked as CVE-2026-65400 exploits Apple's built-in Screen Sharing feature, a convenience tool designed to allow remote users to view and control a Mac from another computer. The flaw's severity lies in its fundamental nature: attackers can trigger the vulnerability without requiring credentials or user interaction, meaning even casual exposure of the Screen Sharing port to the internet creates substantial risk. Apple patched the issue across three major operating systems simultaneously—macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9—a move that itself signalled the seriousness of the threat.

Monero represents an especially attractive target for this category of cybercriminal activity. Unlike Bitcoin and many other cryptocurrencies that require specialized graphics processing units or dedicated mining rigs to be economically viable, Monero can be profitably mined using standard computer processors. This characteristic transforms ordinary Macs scattered across homes and offices into unwitting components of a distributed mining operation, allowing attackers to harvest cryptocurrency while victims bear the costs of electricity and hardware wear. The attacks observed in the Netherlands demonstrate how quickly criminal networks operationalize newly disclosed vulnerabilities once patches become available.

Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, contextualized the mining installations within a broader threat landscape. He explained that cryptocurrency miners have become criminals' preferred initial payload when exploiting newly public vulnerabilities because they provide straightforward monetization with minimal technical friction. However, the presence of mining software should not be interpreted as the limit of potential damage. With root-level access—the highest permission tier on any computer system—attackers gain unfettered ability to retrieve sensitive files, extract authentication credentials, compromise cloud service tokens, or establish persistent backdoors for future access. The visible mining activity may represent only the most obvious malicious action, masking deeper system compromise that remains undetected.

The timeline of this exploitation reveals how rapidly threat actors move to weaponize disclosed flaws. When the vulnerability initially became public, Apple maintained to technology publications that the issue had not been exploited outside controlled laboratory environments. That assessment has now been superseded by evidence of active attacks, demonstrating the window between patch release and genuine criminal exploitation has narrowed considerably. This acceleration underscores a persistent challenge in cybersecurity: the balance between responsible disclosure and the time legitimate users have to protect themselves against opportunistic attackers.

The attacks observed targeted Macs whose Screen Sharing ports were exposed to the public internet, a configuration that creates direct vulnerability but remains relatively uncommon among average users. Most residential routers and corporate firewalls block such external connections by default, providing an accidental layer of protection. However, organizations operating Mac systems in cloud environments, remote access configurations, or with non-standard network setups may discover their machines exposed. Additionally, businesses that enabled Screen Sharing for legitimate administrative purposes without restricting access to trusted networks now face heightened risk.

For Mac users, the immediate response is straightforward: installation of available security updates. Users can initiate the process by navigating to System Settings, selecting General, then Software Update. The update process typically requires a device restart but takes only minutes to complete. Those who do not rely on Screen Sharing functionality should consider disabling the feature entirely through System Settings > General > Sharing, an additional protective measure that eliminates the attack vector altogether regardless of whether patches have been applied.

However, the presence of a patch creates a critical false sense of security for organizations and individuals. Applying the update closes the vulnerability pathway, preventing future exploitation through this particular flaw, but it does nothing to identify or remove malware that attackers may have already installed on previously unpatched systems. Hegel emphasized that administrators of business environments face the urgent task of investigating any Macs that had Screen Sharing enabled and internet-accessible before patches were applied. Systems with suspicious processor usage, unexpected network activity, or unusual battery drain warrant immediate forensic examination.

The federal assessment of the flaw's severity assigns it a critical score of 9.8 out of 10, reflecting that exploitation requires neither special credentials nor active victim participation. An attacker need only probe for internet-exposed Screen Sharing services, identify vulnerable systems running older macOS versions, and launch attack code—a process that can be largely automated. Phil Stokes, a SentinelOne research engineer specializing in macOS security threats, previously noted that Apple's decision to issue the patch outside its standard monthly release cycle already signalled the organization's internal assessment of urgency.

For Southeast Asian users and organizations, the implications extend beyond individual convenience. Regional businesses increasingly rely on Mac systems for creative and technical work, from design studios to software development firms. The cryptocurrency mining attacks not only compromise system performance but potentially expose proprietary intellectual property, client credentials, and business-sensitive data to criminal actors operating across international borders. The incident reinforces the necessity of maintaining disciplined patch management practices and viewing security updates not as optional improvements but as critical infrastructure maintenance equivalent to changing locks when security risks emerge.