The Netherlands' National Cyber Security Centre is warning of active exploitation of a macOS authentication bypass vulnerability. Hackers are using the flaw to deploy Monero miners on compromised systems.
The NCSC issued an alert after public exploit code surfaced online, making the vulnerability accessible to a broader range of attackers. The macOS Screen Sharing feature contains an authentication bypass that allows threat actors to gain unauthorized access to affected systems without proper credentials.
Once attackers gain access through the vulnerability, they deploy Monero cryptocurrency miners that consume system resources to generate digital currency for the attackers. This type of exploitation represents a growing threat, as cryptominers run silently in the background, degrading system performance while remaining relatively undetected.
Screen Sharing, a legitimate macOS feature that enables remote desktop access, becomes a vector for attack when the authentication mechanism fails to properly validate user permissions. The release of functional exploit code accelerates the threat timeline, moving the vulnerability from theoretical risk to active, in-the-wild exploitation.
Affected users may experience symptoms including slower system performance, increased CPU usage, and elevated fan activity from their machines working harder than normal. The Monero cryptocurrency was specifically chosen by attackers because it prioritizes privacy and is difficult to trace compared to other digital currencies.
Apple has not yet released a patch for the vulnerability. Users should review their Screen Sharing settings and consider disabling the feature if remote access is not required. Network administrators should monitor for suspicious Screen Sharing connections and implement access controls to limit exposure.
The NCSC recommends immediate patching once a fix becomes available and suggests organizations review logs for unauthorized access attempts. This incident underscores the importance of securing remote access features, which remain attractive targets for attackers seeking to monetize compromised hardware.
Flock Safety announced new safeguards for its license plate recognition cameras following reports that law enforcement used the system to target immigrants and track people seeking out-of-state abortions. The company operates a network processing 20 billion monthly scans across the US.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud is being exploited in the wild just three days after the company released a patch. Threat intelligence firm Defused confirmed active targeting of the flaw.
The Administrative Office of the U.S. Courts will begin disclosing how frequently judges authorize government use of spyware for wiretapping suspects, marking a shift toward greater transparency in surveillance practices.
Shell has launched an investigation into a potential security incident following claims by the Clop ransomware gang that it stole 89GB of company data. The oil giant confirmed the probe but has not yet disclosed details about the breach's scope or impact.