About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used a simple global password for authentication. Apple adapted the protocol for its own use, but overall, left the VNC prot

A recent report has highlighted long-standing security characteristics of Apple's Screen Sharing feature, noting its reliance on the Virtual Network Computing (VNC) protocol. The report indicates that Apple's implementation, introduced with macOS 10.5 (Leopard) approximately two decades ago, largely retained the fundamental nature of VNC, which is described as a simple, unencrypted protocol operating over TCP port 5900.
The core of the concern stems from VNC's historical design, which typically employs a straightforward global password for authentication. While Apple adapted the protocol for its macOS environment, the underlying VNC framework, as described, remains. This means that, fundamentally, the communication itself is unencrypted, making it susceptible to eavesdropping if not protected by other means, such as a VPN tunnel or secure network infrastructure.
Products that implement VNC, including Apple's Screen Sharing, commonly face challenges related to the protocol's inherent lack of encryption. This characteristic means that any data transmitted during a screen sharing session, including screen contents, mouse movements, and keyboard inputs, could be intercepted and read by an attacker with access to the network path between the two endpoints.
Mitigation strategies for this class of issue typically involve ensuring that VNC traffic is encapsulated within a secure, encrypted tunnel. Common approaches include using a Virtual Private Network (VPN) to encrypt all network traffic, or employing SSH tunneling to specifically secure the VNC connection. Additionally, strong, unique passwords are always recommended for VNC authentication, and network access controls should be implemented to restrict who can even attempt to connect to the VNC port.
The likely scope of impact for such a characteristic would primarily affect users who utilize Apple Screen Sharing over untrusted networks without additional security layers. For instance, connecting to a macOS device via Screen Sharing over public Wi-Fi without a VPN would expose the session to potential interception.
This report serves as a reminder of the importance of understanding the underlying protocols and security implications of common network services. While convenience features like screen sharing are valuable, users and administrators must be aware of their security posture, especially when these services are based on older or inherently unencrypted protocols, and take proactive steps to secure them against modern threats.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]