web3: Dutch cybersecurity agency warns: macOS vulnerability is being used to mine Monero coins
Coinpaper
1h ago
Ai Focus
Dutch cybersecurity agency claims that a screen-sharing vulnerability in macOS is being exploited to implant Monero mining programs; Apple has already fixed the related issue.
Helpful
No.Help

荷兰国家网络安全中心本周警告称,攻击者正在利用苹果 macOS 屏幕共享功能的一处漏洞,入侵部分对互联网开放的 Mac 设备,并在设备上秘密部署门罗币挖矿程序。

该机构表示,已收到多起活跃攻击报告。这些受影响系统都将 5900 端口暴露在公网,攻击者借此进入屏幕共享服务,随后取得 root 权限,也就是设备的最高控制权限。

漏洞已出现公开利用代码

这处漏洞编号为 CVE-2026-65400,严重性评分为 7.1 分。问题出在登录认证过程中的状态管理,导致系统在某些情况下会错误接受本应被拒绝的登录请求,使网络攻击者无需有效凭证也能通过认证。

荷兰国家网络安全中心还提到,这一漏洞的公开 PoC 代码已经流传,意味着更多攻击者可以更低门槛地复制相关攻击手法。

攻击者植入门罗币挖矿程序

在已知案例中,攻击者拿到设备控制权后,会植入门罗币挖矿程序,利用受害者的硬件资源持续挖矿。门罗币因匿名性较强,长期被用于这类“加密劫持”攻击。相比比特币或以太坊等公开链资产,这类收益更难追踪。

这类攻击通常不会立刻锁死设备,而是长期占用算力。受害者往往承担电力消耗、设备性能下降等成本,而挖矿收益则流向攻击者。

苹果已发布修复更新

苹果已经在多个 macOS 版本中修复这一问题,包括 macOS Sequoia 15.7.9、Sonoma 14.8.9 和 Tahoe 26.6.1。修复方式是加强认证校验,避免异常登录状态被错误放行。

荷兰国家网络安全中心建议用户尽快安装更新,并避免让屏幕共享服务直接暴露在互联网环境中,尤其是仍开放 5900 端口的设备,风险更高。

近期,围绕加密资产的钱包窃取和恶意挖矿攻击仍在增加。除门罗币挖矿程序外,安全机构也持续发现通过盗版软件、伪造验证码页面、移动应用和恶意代码库传播的加密窃取程序。

Tip
$0
Like
0
Save
0
Views 20
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Amazon reportedly disassembles rare books for AI training
404 Media claims that Amazon purchases rare books and scans their content for use in the training of the AI model.
TechCrunch
·2026-08-18 00:48:30
8
web3: Foreign media: Stripe's acquisition of OpenRouter aims to control the billing entry point of AI
Foreign media reports that Stripe acquired OpenRouter for over $7 billion, with the aim of establishing a unified route, billing, and payment chain for AI and gaining control over the enterprise's AI expenditure and revenue flows.
Coinpaper
·2026-08-18 00:37:16
10
web3: The US Treasury Department initiates the formulation of rules for payment-style stablecoins
The U.S. Treasury Department has initiated the development of federal regulations for payment-style stablecoins, opening a 60-day comment period. The White House and industry executives will also hold a closed-door meeting this week.
U.Today
·2026-08-18 00:26:49
11
Foreign media: The rising threat of AI draws attention to cybersecurity stocks
CNBC states that the security threats brought by AI have intensified, and the cybersecurity sector has once again drawn attention.
CNBC
·2026-08-18 00:16:17
11
View More