Internet-exposed macOS Screen Sharing is yielding root accessWhite House creates a federally controlled private cyber operations…Lazarus campaign used a Windows zero-day to suppress endpoint visibilityAkira's Safe Mode tactic blinded controls before encryption failed
Internet-exposed macOS Screen Sharing is yielding root access
NCSC-NL now reports active exploitation of CVE-2026-65400 against Macs exposing Screen Sharing to the internet, with attackers obtaining root access and installing cryptomining software.
Security.io Intelligence Desk · Thursday, 13 August 2026
Executive consequence
Treat CVE-2026-65400 as an exposure-led incident decision, not a fleet-wide patch statistic. Find Macs where Screen Sharing and internet reachability intersect, remove that path, install the fixed release and investigate previously exposed hosts for root-level persistence.
Decision today
Query fleet management for Screen Sharing state, fixed macOS release and internet reachability.
Prioritise CVE-2026-68820 where targeted personnel or suspicious PDF delivery create a plausible foothold. The August Windows update closes the privilege-escalation route, but evidence-based closure requires hunts for the delivery chain, EDR impairment and abused web infrastructure.
Do today
Deploy the August Windows updates to endpoints supporting defence, aerospace and aviation personnel.
Add Safe Mode transitions to ransomware detections and treat failed encryption as an incomplete attack, not a contained one. The observed Akira attempt disabled controls successfully even though memory constraints prevented encryption after credentials and files had already been stolen.
Do today
Alert on Safe Mode boot events and boot-configuration changes on managed Windows systems.
Use NIST's consultation as a trigger to map every enterprise dependency on NVD data and formalise controls for AI-assisted vulnerability decisions. The notice is not a new standard or immediate schema change, but it signals the direction of a foundational security-data service.
Do today
Map scanners, dashboards, compliance controls and ticketing workflows that consume NVD data.