• Sources: primary, discussion
  • Summary: The Netherlands National Cyber Security Centre warns that attackers began exploiting CVE-2026-65400 after public exploit code emerged, with abuse observed on multiple systems that had port 5900 reachable from the internet, root obtained on each host and a Monero miner placed. Fixed releases are macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, and disabling Screen Sharing removes the exposure where patching is not immediate. The report reaches this archive through one outlet quoting the agency update, the NCSC-NL advisory URL tried here did not resolve, and the agency published no attack timeline, scope or host count.
  • Why it matters: This archive covered the same CVE on 2026-08-11 as an Apple advisory with no known exploitation, so unpatched internet-facing hosts now face observed attacks driven by public exploit code rather than a theoretical risk.
  • Follow-up: Check whether the NCSC-NL advisory resolves and publishes an attack timeline, scope or host count.

send feedback on this story