Cybersecurity officials in the Netherlands have confirmed that attackers are now actively exploiting a critical vulnerability in Apple's macOS systems, marking a significant escalation in threat activity. The flaw, which Apple addressed earlier this month across multiple operating system versions, has already been weaponised by threat actors seeking to commandeer Mac computers for illicit cryptocurrency mining operations. The Dutch National Cyber Security Centre's disclosure underscores the persistent danger posed by unpatched systems and the speed at which adversaries move to exploit publicly known security gaps.

The vulnerability, catalogued as CVE-2026-65400, affects Apple's native Screen Sharing feature—a built-in tool that allows remote access and control of Mac computers across networks. Attackers have successfully targeted multiple machines with exposed Screen Sharing capabilities connected to the public Internet, gaining root-level access in every documented case. Root access represents the highest tier of system control, granting threat actors virtually unlimited authority to install software, modify system configurations, and access sensitive data. This level of compromise transforms each affected Mac into a fully compromised asset under attacker control.

Instead of deploying traditional malware or stealing data immediately, attackers in the observed incidents installed Monero, a privacy-focused cryptocurrency designed specifically for mining on consumer-grade processors. This choice reflects a deliberate monetisation strategy: rather than attempting complex data theft or ransom schemes, the criminals are converting stolen computing resources into direct financial gain. Mac owners unknowingly subsidise this operation through elevated electricity consumption and hardware degradation as their machines run processor-intensive mining operations around the clock. The approach represents an efficient, low-risk means for cybercriminals to generate revenue from compromised systems.

Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, contextualises this exploitation pattern within broader cybercriminal behaviour. Newly disclosed vulnerabilities frequently trigger automated, widespread attacks designed to quickly establish cryptocurrency miners, he explains to Inc, because such deployments offer immediate financial returns with minimal operational friction. The simplicity and speed of mining operations make them attractive initial payloads for mass exploitation campaigns. However, Hegel emphasises a critical point that should concern Mac users: the presence of a cryptocurrency miner may obscure far more dangerous activity occurring simultaneously on compromised systems.

With unfettered root access, attackers can traverse an entire system to harvest valuable credentials, authentication tokens, cloud service credentials, and personal files. They may establish persistent backdoors ensuring continued access even after the original vulnerability closes. The cryptocurrency miner essentially serves as a visible distraction—the activity most readily noticed by security tools or observant users—while attackers simultaneously conduct espionage, data exfiltration, or lateral movement into corporate networks. In business environments, a single compromised Mac could serve as a foothold for breaching entire organisational infrastructure, making the initial cryptocurrency theft almost secondary in severity.

Apple's response timeline itself signals the severity of this flaw. The company issued patches for CVE-2026-65400 across three macOS versions: Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9—a broad deployment uncommon outside critical security scenarios. When the vulnerability initially became public, Apple claimed no evidence of exploitation beyond controlled testing environments. The Dutch authorities' confirmation of active, real-world exploitation represents a dramatic reversal, proving attackers wasted no time transitioning from vulnerability disclosure to operational deployment.

The severity scoring reflects the exploitation ease: a federal assessment assigns the vulnerability a 9.8 out of 10 critical severity rating, indicating that attackers require neither valid user credentials nor any interaction from Mac owners. The flaw can be triggered remotely by simply connecting to the exposed Screen Sharing service—a trivial precondition for attackers scanning the public Internet for vulnerable systems. This combination of remote exploitability, ease of access, and severe impact explains the rapid weaponisation and active attack campaigns documented in the Netherlands.

Mac users remain exposed if they have not applied the relevant patches. Updating requires navigating to System Settings, selecting General, then accessing Software Update to download and install the latest macOS version. For those unfamiliar with their exposure status, disabling Screen Sharing—found under System Settings > General > Sharing—eliminates the attack vector entirely, particularly beneficial for users who never utilise remote access capabilities. However, this retroactive protection does nothing for machines already compromised before patching occurred.

The geographic focus on attacks in the Netherlands reflects where security monitoring successfully detected and reported the exploitation; similar campaigns likely target vulnerable systems worldwide. The attacks specifically affected Macs whose Screen Sharing ports remained accessible from the Internet—a configuration existing primarily on systems behind misconfigured firewalls or routers. While standard home network configurations typically block such exposure by default, many business environments, remote workers, and organisations providing employee remote access may have created the necessary conditions for exploitation without realising the associated risks.

Organisations whose Mac systems had Screen Sharing enabled and exposed face a critical decision: beyond applying patches immediately, they must investigate whether their machines were already compromised during the vulnerability window. Patching closes the entry point but cannot remove cryptocurrency miners already installed or reverse unauthorised modifications attackers may have executed. Comprehensive incident response—including forensic analysis of affected systems and scrutiny of network logs—becomes necessary to detect and remediate existing compromises. For businesses operating significant Mac fleets, this could demand substantial remediation effort across many systems.

The implications for Southeast Asian users extend beyond individual Macs to regional security posture. As cryptocurrency mining remains financially attractive in markets where electricity costs remain comparatively low, the incentive for conducting such attacks remains high across the region. Malaysian businesses, increasingly adopting Mac computers in creative and technology sectors, should recognise their exposure and prioritise patch deployment across all systems. The incident demonstrates that Apple's ecosystem, while generally considered more secure than alternatives, remains subject to serious exploitation when users neglect timely security updates.

The most immediate action Mac users and administrators can take is straightforward: update to the latest macOS version immediately. For users managing multiple Macs within organisations, enforcing mandatory patching policies transforms a potential catastrophe into manageable risk. The disclosure from Dutch cybersecurity authorities serves as a crucial wake-up call that security patches require urgent attention, not leisurely implementation.