ডutch অফিসিয়ালস warned of active exploitation of a high-severity macOS vulnerability (CVE-2026-65400) allowing attackers to execute code via screen sharing. The flaw, rated 7.1/10, stems from a bug in macOS screen sharing's state management, enabling remote access when port 5900 is exposed. Apple patched the vulnerability last week for macOS Tahoe, Sequoia, and Sonoma, crediting security firm Bynario for its discovery.
The vulnerability allowed root access and deployment of a Monero crypto miner on affected systems. The author recounts how their always-on Mac Mini, running only Claude and Codex, was compromised but protected by a custom agent that detected unauthorized admin access and helped eradicate the malware before the public disclosure. The agent's monitoring tool triggered an urgent alert upon detecting privilege escalation, enabling rapid response.
Despite Apple's cautious wording that the flaw 'may' allow credential-less access, the NCSC confirmed active abuse. The incident highlights both risks and benefits of persistent AI agents in threat detection and response.
উৎস: Hacker News · সারাংশ: HeadlinesBriefing