A security update that went out a month ago as a "just in case" precaution has now turned into a real intrusion affecting multiple computers in the Netherlands. According to Ars Technica, a vulnerability in macOS's Screen Sharing tool has been actively exploited in the wild. The Netherlands National Cyber Security Centrum issued a warning stating they've received reports of "multiple systems" being attacked, with attackers gaining root access in every case and uploading cryptocurrency mining software.
The vulnerability, tracked as CVE-2026-65400, effectively gives attackers the equivalent of physical access to a victim's computer: as long as Screen Sharing is enabled, any attacker on the network can exploit the flaw to log in as any user, without ever needing to know the password. Researcher Calif (@calif_io) published a proof-of-concept (PoC) on X, explaining that they pieced together the details of the vulnerability by reverse-engineering an "unusual" patch Apple issued in macOS 26.6.1.






