Dutch cybersecurity officials have raised fresh alarms about a critical weakness in Apple's Mac operating system, revealing that hackers are systematically exploiting the flaw to convert stolen computing power into cryptocurrency profits. The National Cyber Security Centre in the Netherlands documented multiple incidents where attackers gained complete administrative control over vulnerable machines and deployed Monero-mining software, transforming consumer and business computers into unwilling profit-generating engines for criminal operators. The revelation underscores a troubling pattern in which security vulnerabilities transition from theoretical threats to active criminal exploitation within weeks of public disclosure.

The vulnerability, officially catalogued as CVE-2026-65400, resides within Apple's Screen Sharing feature—a convenience tool that permits remote access and control of Mac computers across networks. Apple addressed this flaw through emergency updates distributed to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 earlier this month. The timing of the emergency patch release itself telegraphed the severity, as Apple typically reserves such out-of-cycle updates for threats demonstrating imminent danger to its user base. Yet despite the urgency, substantial numbers of Mac owners have apparently not yet installed the necessary updates, leaving their systems exposed to precisely the attacks now being observed in the wild.

The choice of Monero as the cryptocurrency target reflects sophisticated criminal economics. Unlike Bitcoin and Ethereum, which require specialized hardware to mine profitably, Monero has been engineered specifically to function effectively using standard computer processors. This design characteristic transforms any compromised Mac—whether a budget-friendly MacBook Air or a high-performance iMac—into a viable income stream for attackers. From the hackers' perspective, the calculus is straightforward: once they establish root-level access, they can quietly redirect a machine's processing capacity toward mining operations while the owner continues working, oblivious to the computational theft occurring silently in the background.

Tom Hegel, a threat researcher at SentinelOne's SentinelLABS division, emphasizes that the Monero mining activity, while conspicuous, likely represents only the surface-level manifestation of the attackers' capabilities. With root access firmly established, malicious actors gain far more expansive possibilities than simply harvesting cryptocurrency. They can access confidential files, extract stored passwords and authentication credentials, compromise cloud storage tokens, and potentially pivot into connected corporate networks or cloud infrastructure. The presence of mining software may primarily serve as a distraction from deeper reconnaissance and data theft occurring simultaneously on the same system. Security experts now worry that organisations may assume their security problems are limited to unwanted mining activity when in reality far more sensitive breaches may have occurred.

The shift from theoretical vulnerability to active exploitation represents a critical inflection point. When Apple initially patched the flaw, company representatives told industry observers that they possessed no evidence of attackers leveraging the weakness outside controlled testing scenarios. That assessment has proven dangerously optimistic. The confirmed exploitation documented by Dutch authorities demonstrates that once security flaws achieve public visibility, cybercriminal networks mobilize rapidly to weaponize them at scale. For Mac users accustomed to perceiving their systems as more secure than Windows machines, the incident delivers an uncomfortable reminder that no platform enjoys immunity from determined attackers.

Geographical exposure dynamics influence the practical risk calcurred by individual Mac owners and businesses. The documented attacks in the Netherlands specifically targeted machines whose Screen Sharing service remained accessible from the public internet—a configuration that creates an open door for remote attackers. Fortunately for most users, default configurations of residential routers and corporate firewalls typically block such inbound connections, providing natural protection layers. However, organisations that have deliberately enabled remote access for legitimate business purposes, or individuals who have configured port forwarding for convenience, occupy a fundamentally different risk position. These systems became vulnerable the moment the flaw was discovered and remain compromised until both patching and forensic investigation occur.

The severity assessment assigned to CVE-2026-65400 underscores the technical danger involved. A 9.8 rating on the standard vulnerability severity scale places it in the topmost danger category, indicating that successful exploitation requires neither valid user credentials nor any interaction from the targeted computer's operator. An attacker with network access to the Screen Sharing port can unilaterally establish complete system control, rendering traditional human-as-firewall protections irrelevant. This combination of accessibility and power explains why the vulnerability merited emergency patching outside Apple's normal update rhythm and why cybersecurity officials across multiple nations have begun issuing urgent advisory notices.

For Mac users seeking immediate protection, the remediation path remains straightforward but demands prompt action. Those relying on Mac operating systems can navigate to System Settings, select General, and proceed to Software Update to install the latest security patches. Users who have never employed Screen Sharing functionality can further reduce their attack surface by disabling the feature entirely through System Settings, providing defence-in-depth protection against this particular vulnerability class. Yet patching itself addresses only half the security equation. Organisations and businesses whose Macs operated with Screen Sharing exposed to the internet prior to receiving patches must undertake thorough forensic investigation to determine whether systems were already compromised. As SentinelOne researchers note, installing patches closes the current doorway but cannot extract malware already planted or reverse actions attackers have already executed against the system.

The broader implications for Southeast Asian technology users and businesses warrant careful attention. The region's rapidly growing Mac adoption, driven by creative professionals, technology companies, and increasingly by corporate environments, expands the pool of vulnerable systems that criminals can target. Regional internet connectivity patterns, organisational security practices, and patch deployment discipline vary considerably across ASEAN nations, suggesting that some areas may experience higher exploitation rates than others. Additionally, the nascent but growing cryptocurrency markets across Southeast Asia create local demand for the mining capacity that compromised Macs can generate, potentially attracting regionally-based criminal operators alongside international hacking networks.

Phil Stokes, a SentinelOne security researcher specialising in macOS threats, previously observed that Apple's decision to issue patches outside its standard cycle effectively communicated the seriousness of the underlying threat. Dutch authorities have now validated that assessment through real-world evidence of active exploitation. The incident crystallises a fundamental cybersecurity principle: the window between vulnerability disclosure and widespread patching represents the most dangerous period, and organisations and individuals who delay updates during this interval face maximum risk. For the Mac community, the immediate imperative involves completing updates without further postponement, conducting threat assessments on previously exposed systems, and disabling unnecessary remote access features. The broader lesson extends across all computing platforms: rapid patch deployment is not merely best practice but essential survival strategy in an environment where attackers now weaponise vulnerabilities within days rather than months.