Dutch cybersecurity authorities have sounded the alarm over active exploitation of a critical Mac vulnerability that allows attackers to gain complete control of compromised computers and install cryptocurrency-mining malware. The disclosure marks a significant escalation in real-world attacks targeting the flaw, which Apple rushed to patch earlier this month through an emergency software update. The warning serves as an urgent reminder to Mac users worldwide, particularly those in Southeast Asia where the region's rapid digital adoption has made devices like these increasingly common in both corporate and home environments.

The Netherlands' National Cyber Security Centre revealed that multiple Mac systems exposed to the internet have already fallen victim to the vulnerability in Apple's built-in Screen Sharing feature. In each confirmed case, attackers successfully obtained root access—the highest level of system control—allowing them to fundamentally compromise affected machines. Once inside, the threat actors deployed Monero cryptocurrency-mining software that hijacks the computer's processing power to generate digital currency for the criminals' benefit, essentially turning stolen hardware into a remote mining operation.

Monero has become the cryptocurrency of choice for these types of attacks due to its design philosophy. Unlike Bitcoin, which typically requires specialized hardware to mine profitably, Monero is engineered to be mined using standard computer processors found in ordinary laptops and desktops. This accessibility makes Monero particularly attractive to attackers seeking to monetize compromised systems quickly. The criminals effectively transform innocent Mac owners into unwitting participants in a cryptocurrency-mining operation, draining battery life, generating excess heat, slowing performance, and incurring electricity costs without the user's knowledge or consent.

Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, emphasized that cryptocurrency mining likely represents only the most obvious aspect of the threat. With root access firmly established, attackers gain far broader capabilities that extend well beyond mining. They can access confidential files, steal stored login credentials, compromise cloud authentication tokens, and pivot to attack connected systems and networks. The cryptocurrency miner essentially serves as the visible symptom of a much deeper infection, masking potentially far more damaging activities occurring simultaneously on compromised systems.

The shift to active exploitation marks a dramatic change in the threat landscape. When Apple initially disclosed the vulnerability, the company stated it had observed the flaw only in controlled testing environments and had no evidence of real-world abuse. That assessment has now proven dangerously optimistic. The passage from theoretical vulnerability to widespread active exploitation has occurred with troubling speed, demonstrating the aggressive posture modern threat actors adopt once security flaws enter the public domain. The Dutch security centre's confirmation of multiple victim machines indicates this is no longer a theoretical risk but a tangible, immediate danger.

The vulnerability, formally designated CVE-2026-65400, resides in Apple's Screen Sharing functionality—a legitimate remote access tool that permits one computer to view and control another Mac from a distance. While useful for technical support and remote work, this feature becomes dangerously exploitable when exposed to the public internet and running unpatched software. Apple distributed fixes across three major macOS versions: Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The company's decision to issue security updates outside its normal release schedule underscored the severity of the threat.

Mac users seeking protection should navigate to System Settings, select General, then access Software Update to install the latest patches. Those who do not require remote access functionality can further reduce risk by disabling Screen Sharing entirely through System Settings, General, and the Sharing section. This layered approach—patching where possible and disabling unnecessary services—reflects fundamental cybersecurity principles increasingly critical in an era of sophisticated, rapidly-deployed threats. For users in Malaysia and across Southeast Asia, where internet infrastructure is increasingly robust and many businesses maintain global operations, these steps carry particular importance.

Organizations running Mac fleets face additional complications. Phil Stokes, a macOS threat specialist at SentinelOne, previously warned that patching addresses only the vulnerability itself. It does not eradicate malware already installed on compromised systems, nor does it undo damage attackers may have inflicted before the patch was applied. Businesses whose Macs had Screen Sharing enabled and reachable from the public internet should conduct thorough security audits to identify whether their systems were compromised before patching. This forensic investigation becomes particularly crucial for organizations handling sensitive data, financial information, or intellectual property.

The severity assessment assigned by federal authorities—a 9.8 out of 10 critical rating—reflects the concerning characteristics of this vulnerability. The flaw requires neither valid user credentials nor any user interaction to exploit. An attacker need only locate a vulnerable Mac with its Screen Sharing port exposed to the internet, then execute the attack remotely. This accessibility, combined with the high-value payoff of gaining root access, explains why threat actors have moved so rapidly from initial awareness to active exploitation.

Most consumer-grade home routers and corporate firewalls block inbound connections to the Screen Sharing port by default, which provides some degree of natural protection. However, systems explicitly configured to allow remote access, those behind misconfigured network security devices, or machines in environments with intentionally permissive firewall rules remain dangerously exposed. The Dutch authorities' confirmation that attackers have successfully compromised systems indicates that a meaningful number of Macs worldwide fall into these higher-risk categories.

For users across Southeast Asia, where Mac adoption continues growing in creative industries, startups, and multinational corporations, this vulnerability carries particular resonance. The region's integration into global business networks means many systems legitimately require remote access capabilities, increasing the likelihood they fall into vulnerable configurations. The rapid evolution from theoretical threat to active exploitation serves as a stark reminder that security patching is not an optional or deferrable activity but an urgent operational necessity in modern computing.

The broader lesson extends beyond this specific vulnerability. As threat actors become increasingly sophisticated and automated in their exploitation techniques, the window between public disclosure and widespread attacks has compressed dramatically. Waiting weeks or months to patch known vulnerabilities has become untenable. Organizations and individuals must adopt rapid patching regimes, prioritizing critical updates immediately upon release. For Mac users globally, the message from Dutch cybersecurity officials is unambiguous: update your systems now, and consider disabling unnecessary remote access services. The cost of delay has already proven substantial.