FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Apple macOS Screen Sharing Authentication Bypass CVE-2026-65400

CVE-2026-65400 is a high-severity state management vulnerability within the macOS screen sharing capability affecting macOS Tahoe, Sequoia, and Sonoma. Attackers targeting exposed Port 5900 can bypass authentication to gain immediate root-level access, enabling full remote takeover of the user interface, including screen visibility and input manipulation. The Netherlands National Cyber Security Centrum (NCSC) has confirmed active exploitation in the wild, primarily utilizing the flaw to deploy Monero cryptominers for resource theft. Immediate remediation requires updating to the latest macOS versions and implementing network restrictions to prevent direct internet exposure of VNC services.

Multi-Stage Cryptojacking Campaign Exploiting ScreenConnect and Microsoft .NET Utilities

A sophisticated, financially motivated cryptojacking campaign is successfully bypassing EDR and AV protections by blending AI-driven social engineering with Living-off-the-Land (LotL) techniques. By abusing ScreenConnect for persistence and Microsoft .NET utilities for execution, threat actors are hijacking high-performance GPU resources to maximize cryptocurrency mining profits.


LINK COPIED TO CLIPBOARD