macOS screen sharing flaw went public at Black Hat
CVE-2026-65400, an actively exploited macOS screen sharing flaw, dropped Monero miners via port 5900, and an AI agent on one host caught the compromise.
CVE-2026-65400 is rated 7.1, and it is already being used. The Netherlands National Cyber Security Centrum reported active abuse on multiple systems where port 5900 was reachable from the internet, and in every case attackers had gained root and dropped a Monero miner. Apple patched the flaw last week for macOS Tahoe, Sequoia, and Sonoma, crediting the security firm Bynario for the report. Details became public at Black Hat.
The bug lives in macOS screen sharing, the feature that lets a remote party watch the display and drive the keyboard and mouse while the machine is awake. Apple traces it to a flaw in state management, the bookkeeping that tracks preceding events, user interactions, and system state. Apple’s advisory hedges, saying the flaw “may” let an attacker without credentials gain access; softened language is routine in vendor disclosures, and the NCSC’s field reports describe exactly that outcome.
Port 5900 is the exposure. When screen sharing is enabled, the macOS firewall opens the port. Routers and dedicated firewalls usually block it unless someone configures them otherwise, which is why the compromised machines were the ones reachable directly from the internet. The standard advice applies: keep 5900 closed, reach the machine over a VPN or an SSH tunnel, and turn screen sharing off under System Settings > General > Sharing except for the length of an actual session.
One of the compromised machines was a headless, always-on Mac Mini running nothing but Claude and Codex, and by the operator’s account the agent is what caught the intrusion. Claude drives a monitoring tool that stands down every thirty minutes, so the agent restarts it on a schedule; one of those restarts surfaced an URGENT notification. Claude had noticed the account could now run admin commands without a password, inferred that was how the attacker wrote files, stopped executing commands on its own, and listed next steps. The operator ignored one suggestion, that Claude not be used at all, and instead used the agent to locate the exact four-second window in which access was gained, build a watcher against a recurrence, and then wipe the machine. All of it happened before the operator found the public writeup of the CVE.
Two macOS design points made this host harder to run safely than it should have been.
The first is TCC, Transparency, Consent, and Control, the subsystem behind the GUI permission prompts for the camera, the Desktop, the Downloads folder, and a lengthening list of other resources. On a primary Mac it is a nuisance. On a headless box running agents it is a trap. Agents write new programs constantly, and those programs trip TCC prompts (reaching an SMB share is enough); the permission model sits at the level of individual apps when what an agent host needs is a permission layer for the agent itself. TCC also renders its prompt in a protected space no userland program can read, so programs fail silently and the agent cannot tell why. The only remedy is to screen-share in and click OK by hand, which is one reason screen sharing stays enabled, which is the feature that was exploited. The design is deliberate: if userland could answer TCC prompts, so could malware. The tradeoff that protects a laptop works against a purpose-built agent host.
Apple has signaled where this is going. A developer note last week, “Updates to Full Disk Access in macOS,” says the company will add controls so granting an app full disk access requires “very explicit user action,” and it names the reason directly: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Full Disk Access is what lets an app read mail, messages, and browsing history, so tightening it is defensible. For anyone deliberately running an agent that needs broad access to its own machine, it is more friction on a platform that already has plenty.
The automatic-update setting is worth checking before anything else. “Install security updates automatically” does not apply to most security updates. CVE fixes almost always ship in point releases, including this one, so a machine left on that setting can sit unpatched through exactly the updates that matter. Install the point release by hand, and confirm the checkbox you trusted does what its label implies.
Contains a referral link.
#ad Contains an affiliate link.
Keep Reading
ai-agentsMuse hands root to anyone
Meta's Muse AI agent grants root to anyone claiming to be an agent and uploads private messages despite permission settings, after a rushed launch.
ai-agentsStrands built a 2B model that never writes text
Strands Decider 2B is an open-source 2B decision model that scores choices in ~115ms, cheap enough to run guardrail checks before every agent tool call.
dellDell's Thursday patch closes a root-level DSU flaw
Dell patched CVE-2026-86360, a path traversal flaw in the System Update CLI that gives unauthenticated remote attackers root. Upgrade to DSU 2.3.0.0.
Latest on the Wire
Full wire →- 5.3M-year-old whale necropolis discovered in deep seaHacker News
- ADHD Linked to Circadian Rhythm Disruption: Evidence and ChronotherapyHacker News
- AhsayCBS Flaws Exploited for Webshells, Crypto MiningBleepingComputer
- AI Won't Replace Programmers but Will Change the RoleHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.