Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

A recently identified vulnerability within macOS Screen Sharing has reportedly been exploited in the wild, allowing threat actors to achieve root access on compromised systems. Following successful exploitation, the attackers were observed deploying a Monero cryptocurrency miner. The specifics of the vulnerability itself, such as its technical classification or CVE identifier, were not detailed in the report.
The mechanism of exploitation appears to leverage a flaw within the macOS Screen Sharing functionality, a service designed to allow remote control and observation of a Mac’s desktop. While the precise method by which root access was obtained remains undisclosed, vulnerabilities in such services often stem from improper authentication checks, privilege escalation flaws, or memory corruption issues that can be triggered remotely. Achieving root access grants an attacker the highest level of control over a Unix-like operating system, enabling them to execute arbitrary commands, modify system configurations, and install persistent malware.
Upon gaining root privileges, the threat actors proceeded to deploy a Monero miner. Cryptocurrency miners, when installed without authorization, consume significant system resources, including CPU cycles and electrical power, to generate cryptocurrency for the attacker. This can lead to performance degradation, increased energy consumption, and potentially shorten the lifespan of hardware components for the victim. Monero is a privacy-focused cryptocurrency often favored by illicit actors due to its enhanced anonymity features.
The affected product is macOS, specifically its Screen Sharing component. Products in this category, which facilitate remote access and administration, are frequently targeted by attackers due to their inherent ability to bridge network boundaries and provide direct control over endpoints. The scope of affected systems would include any macOS installations running the vulnerable version of the Screen Sharing service and exposed to potential attack vectors, which could range from direct internet exposure to internal network access.
Typical mitigation guidance for vulnerabilities in remote access services includes ensuring all operating systems are kept up-to-date with the latest security patches, as these often address known flaws. Users should also restrict network access to such services, ideally placing them behind firewalls and only allowing connections from trusted IP addresses or via Virtual Private Networks (VPNs). Disabling unnecessary services, including Screen Sharing if not actively used, is another common recommendation to reduce the attack surface. Implementing strong, unique passwords and multi-factor authentication for any remote access accounts is also crucial.
This incident underscores the ongoing importance of promptly patching operating systems and exercising caution with remote access services. Even seemingly benign system functionalities can harbor critical vulnerabilities that, once discovered and exploited, can lead to significant compromise, ranging from resource theft through cryptocurrency mining to more severe data breaches or system disruption. The rapid exploitation of newly identified flaws highlights the persistent cat-and-mouse game between security researchers, vendors, and malicious actors.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.