← Blog · · df00tech

NCSC Warns of Active Exploitation of macOS Screen Sharing Auth Bypass to Deploy Monero Miner

security-news advisory

What happened

The Netherlands' National Cyber Security Centre (NCSC) has issued a warning that attackers are actively exploiting a macOS authentication bypass vulnerability affecting Screen Sharing, according to BleepingComputer. The advisory follows the public release of exploit code for the flaw. Per the report, attackers are using the bypass to gain unauthorized access and deploy a Monero (XMR) cryptocurrency miner on compromised systems.

Specific details such as the affected macOS versions, a CVE identifier, and Apple's patch status were not included in the source summary available to us at publication time.

Why it matters for defenders

Screen Sharing is a remote-access service enabled on many macOS systems, particularly in enterprise and creative/media environments where remote administration is common. An authentication bypass in this service is significant because it can grant an attacker interactive, GUI-level access to a host without valid credentials — a much more capable foothold than typical opportunistic malware delivery. The fact that public exploit code exists means the barrier to exploitation is now low, and the observed use case (cryptomining) suggests broad, opportunistic targeting rather than a narrow, high-value campaign, though that could evolve.

What defenders should watch for or do now

  • Inventory macOS endpoints and servers with Screen Sharing (Apple Remote Desktop / VNC-based) enabled, especially any exposed to the internet or reachable without VPN.
  • Where Screen Sharing is not required, disable it; where required, restrict access via firewall rules, VPN-only exposure, and strong network segmentation.
  • Monitor for anomalous Screen Sharing authentication events, especially successful sessions without corresponding valid credential use, and unexpected sessions originating from unfamiliar external IPs.
  • Watch for indicators of cryptomining activity on macOS hosts: sustained high CPU/GPU utilization, unfamiliar background processes, launch agents/daemons persisting at logon, and outbound connections to mining pool infrastructure.
  • Review persistence mechanisms commonly abused on macOS (LaunchAgents, LaunchDaemons, cron) for unfamiliar entries following any suspected Screen Sharing compromise.
  • Apply Apple security updates promptly once a patch addressing this bypass is available, and monitor Apple's security advisories for the relevant fix.

Developing story

This is a developing situation and the source summary available to us does not include a CVE identifier, affected version range, or patch status — details we will update as they become available. For the original report, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.