Cybersecurity officials in the Netherlands have confirmed that criminals are actively exploiting a Mac vulnerability that Apple addressed in a security update earlier this month, marking a troubling escalation in the attack timeline. The finding underscores the critical importance of maintaining current software on all computing devices, particularly as the window between a public patch release and widespread exploitation continues to narrow. The Screen Sharing vulnerability represents exactly the type of security gap that cybercriminals have learned to weaponise with alarming speed, turning personal computers and business infrastructure into unwilling participants in illicit financial schemes.

The Netherlands' National Cyber Security Centre reported that attackers have successfully compromised multiple Mac computers that had the Screen Sharing function accessible from the public internet. In each documented instance, the intruders managed to gain root access—the highest administrative privilege on a computer—before deploying Monero cryptocurrency-mining software. This sequence reveals a troubling sophistication in the attack methodology, suggesting that threat actors are systematically scanning for vulnerable systems and then methodically establishing a foothold for sustained exploitation. The speed at which this transition from theoretical vulnerability to active exploitation has occurred demonstrates the urgency surrounding Mac security patching.

Monero represents a deliberate choice by these attackers rather than a random selection. The cryptocurrency is specifically engineered to be mined using ordinary processors rather than specialised hardware, making it ideal for hijacking consumer and business computers. By converting compromised Macs into unwitting mining machines, criminals essentially steal computational power and electricity from device owners while generating revenue for themselves. This form of attack avoids the technical barriers associated with mining Bitcoin or Ethereum, which require dedicated graphics processors or application-specific circuits. The economic calculus favours Monero precisely because the barrier to entry is so low, and the potential profit margins remain substantial when multiplied across thousands of compromised systems.

Tom Hegel, a threat researcher at SentinelOne's SentinelLABS division, characterised the use of Monero miners as an entirely predictable response to the vulnerability's public disclosure. Cybercriminals routinely leverage newly published exploits to deploy automated attack infrastructure that generates quick returns with minimal complexity. The mining payload offers what Hegel describes as "immediate, relatively low-friction monetisation," allowing attackers to begin profiting from compromised systems with simple, reliable malware that requires little ongoing maintenance. The appeal for criminal operators is straightforward: automate the infection process, harvest computing resources, and convert that computational effort directly into cash.

Yet the mining software may represent only the most obvious dimension of the threat. Hegel emphasised that criminals possessing root access to a Mac have opened an extraordinarily broad door to the system's innermost sanctum. Attackers can now access sensitive files, harvest stored credentials, intercept cloud authentication tokens, and potentially pivot to other networked systems and services. The Monero miner serves as a visible symptom of the infection, but it likely masks a far more dangerous capability to exfiltrate data, establish persistent backdoors, or facilitate additional criminal objectives. This distinction between the observable payload and the underlying access privilege represents a critical consideration for anyone managing affected systems.

Apple's initial assessment of the threat appears to have been overly optimistic. When the vulnerability first became publicly known, the company assured the cybersecurity community that it had detected no evidence of exploitation outside controlled testing environments. That assessment has now been definitively contradicted by real-world evidence gathered by Dutch authorities. The rapid transition from theoretical danger to active exploitation in the wild demonstrates how quickly the threat landscape can shift once technical details enter the public domain. Every day that passes without patching represents additional exposure for unpatched systems still reachable across the internet.

The technical details of the vulnerability, tracked as CVE-2026-65400, centre on Apple's built-in Screen Sharing feature, which permits remote access and control of a Mac from another computer. Apple distributed patches through three separate macOS versions: Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, reflecting the breadth of affected systems across different update channels. Users can apply the update through System Settings, navigating to General and then Software Update. For those who have no legitimate need for Screen Sharing functionality, disabling the service entirely represents another layer of protection, accessible through the same settings interface under Sharing options.

Organisations that previously had Screen Sharing enabled on networked Macs face an additional complexity beyond simply patching. Hegel points out that closing the vulnerability itself does nothing to remove malware already installed on compromised systems or reverse actions attackers may have already executed. Administrators must conduct forensic investigations on systems that were exposed and potentially vulnerable, searching for traces of unauthorised access, lateral movement, or data exfiltration. This retrospective threat-hunting imperative has significant implications for IT security teams that may lack visibility into which specific machines were actually targeted or compromised.

The scope of potential exposure varies considerably based on individual network configurations and environmental factors. Researchers noted that the attackers in the Netherlands targeted Macs whose Screen Sharing port was openly accessible from the public internet, a configuration that most home routers and corporate firewalls block by default. This means that many systems, despite running vulnerable software, face substantially lower risk due to network-level protections. However, the exceptions—systems with non-standard configurations, cloud-hosted Macs, or deliberately exposed machines—represent genuine and immediate danger. The technical severity of the flaw is reflected in its official vulnerability rating of 9.8 out of 10, among the highest possible scores, because successful exploitation requires neither special credentials nor any user interaction whatsoever.

Apple's decision to release this patch outside its normal scheduled update cycle already signalled unusual urgency within the company's security hierarchy. Phil Stokes, a SentinelOne research engineer who specialises in macOS security, noted that accelerated patching decisions typically indicate that Apple's threat intelligence teams had elevated confidence in the vulnerability's severity and exploitability risk. Dutch authorities have now vindicated that sense of urgency by confirming that attackers have indeed located and compromised vulnerable systems across the internet. The fundamental challenge remains unchanged: as long as unpatched Macs with Screen Sharing enabled remain exposed to the public internet, criminals will continue to identify and exploit them systematically, each successful compromise representing another node in their distributed mining network.