The Dutch National Cyber Security Centre this week warned that the attackers were using a loophole in the Apple MacOS screen sharing function to invade parts of Mac equipment that was open to the Internet and to secretly deploy Menroco-mining procedures on the equipment.

The Agency indicated that it had received numerous reports of active attacks. These affected systems expose 5900 ports to the public web, where the attackers enter screen sharing services and then get root privileges, the maximum control of the equipment.

There's a gap in the open code.

This loophole is CVE-2026-65400 with a severe rating of 7.1. The problem arises from the management of the status of the login certification process, which leads the system to wrongly accept, in certain circumstances, a request for login that should have been rejected, making it possible for cyberattackors to pass the certification without a valid certificate.

The Netherlands National Cybersecurity Centre also mentioned that the open PoC code of this loophole has been circulated, which means that more attackers can replicate the methods of attack at a lower threshold.

The attackers implanted the Monroe miner.

In known cases, after the attackers have taken control of the equipment, they are implanted in a Menroco mining programme, using the hardware resources of the victims to sustain the mine. Menrococo is used for a long time to carry out such “encrypted hijacking” attacks because of its anonymity. Such gains are more difficult to trace than in the case of open-chain assets such as TTcos or Taifu.

Such attacks usually do not lock the equipment immediately, but are long-term occupancy calculations. Victims often bear the costs of electricity consumption, reduced equipment performance and mining proceeds to the attackers.

Apple released fixer update

Apples have repaired the problem in several MacOS versions, including MacOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1. This was done by enhancing the authentication verification and avoiding an abnormal login status being incorrectly released.

The NNSC recommends that users install updates as soon as possible and avoid the risk of direct exposure of screen-sharing services to the Internet environment, in particular equipment that remains open at 5900 ports.

In the recent past, the theft of wallets around encrypted assets and malicious mining attacks have continued to increase. In addition to the Menroco mining programme, security agencies continue to detect encryption thefts that are disseminated through pirated software, forged authentication code pages, mobile applications and malicious codes.