๐จ ACTIVE EXPLOITATION
- Hackers exploit macOS Screen Sharing bypass to deploy Monero miners
CVE-2026-65400Hackers are exploiting a macOS Screen Sharing authentication bypass to deploy Monero miners.- macOS Tahoe, Sequoia, and Sonoma systems with Screen Sharing enabled are affected.
- CVE-2026-65400 allows network attackers to access Screen Sharing without valid credentials.
- Attacks target internet-exposed TCP port 5900 after public exploit code emerged.
- Attackers obtained root access and installed Monero cryptocurrency miners. ๐ Source: support.apple.com ยท ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ต๏ธ RESEARCH & DEEP DIVES
- Week 33 roundup covers sextortion, Gunra ransomware and Defender bypass
SentinelOne highlighted a sextortion conviction, Gunra ransomware, and a Microsoft Defender bypass.
- The case involved a convicted member who sextorted 117 minors.
- A joint advisory warned about Gunra ransomware.
- ShieldBreak bypasses Microsoft Defender to obtain SYSTEM access.
- The bypass affects environments relying on Microsoft Defender. ๐ Coverage: sentinelone.com ยท ๐ via SentinelOne Blog
๐ ADVISORIES
-
Cloudflare Gateway detects and controls MCP traffic Cloudflare Gateway identifies MCP traffic with protocol-level heuristics.
- Cloudflare Gateway customers and security teams are affected.
- MCP requests are identified as shadow traffic on managed networks.
- Protocol-level heuristics distinguish MCP requests from other traffic.
- Gateway controls include Portal-only access and blocking direct MCP connections. ๐ Coverage: blog.cloudflare.com ยท ๐ via Cloudflare Blog
-
TP-Link Aginet Flaws Enable Authentication Bypass and Device Takeover ๐ Source: tp-link.com
๐ CVEs & KEV
- CVE-2026-73673 โ CVSS 8.7 โ Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptogra...
- CVE-2026-19870 โ CVSS 8.6 โ IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation...