Loading IndicatorLoading Indicator

Hackers Exploit Apple Screen-Sharing Flaw to Install Monero Miner on Macs

Source
Suehyeon Lee

Summary

  • The Netherlands’ National Cyber Security Centre said hackers exploited a screen-sharing vulnerability in Apple Mac computers to install Monero (XMR) mining software.
  • Cybersecurity firm Huntress said the macOS screen-sharing flaw is exploited before authentication and urged all users to apply the latest security updates immediately.
  • The U.S. CISA raised the severity rating of the flaw to 9.8 out of 10, while the Monero network’s daily mining output stands at about 432 XMR, worth roughly $179,000.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Shutterstock
Photo: Shutterstock

Hackers have exploited a vulnerability in Apple’s Mac screen-sharing feature to covertly install Monero mining software.

The Block reported on August 16 that the Netherlands’ National Cyber Security Centre said in a recent advisory that multiple internet-exposed Macs had been attacked through the flaw. Attackers took full control of the compromised devices and installed Monero mining software, the agency said. It did not identify the number of affected machines or the group behind the campaign.

The vulnerability affects the Mac screen-sharing feature. It allows attackers to access a device over a network without a valid password. Because the flaw occurs before authentication, changing or removing a password does not stop the attack. Screen sharing is disabled by default, but it is commonly used to connect to Apple devices installed on remote servers.

Huntress wrote in an analysis that the flaw tricks Macs into treating an external connection as an already authenticated session. Ryan Dowd, a researcher at the cybersecurity firm, urged anyone using macOS screen sharing to apply the latest security updates immediately. He said he identified tens of thousands of potentially vulnerable devices through internet asset search platform Censys.

Apple patched the vulnerability on August 6 in updates to macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. The U.S. Cybersecurity and Infrastructure Security Agency initially rated the flaw 7.1 out of 10 on the day the patch was released, then later raised the score to 9.8.

Monero has long been a major target for so-called cryptojacking attacks because it can be mined on ordinary computers and its transaction history is difficult to trace. The Monero network is currently producing about 432 XMR a day, worth roughly $179,000 at recent prices.

#Cryptojacking
#Cybersecurity
#Incidents
Suehyeon Lee

Suehyeon Lee

shlee@bloomingbit.ioI'm reporter Suehyeon Lee, your Web3 Moderator.

What do you think about this news?








PiCK News






Hashtag News