Mac flaw let hackers mine Monero, 9.8/10
A macOS Screen Sharing flaw scored 9.8/10 on the CVSS scale, and hackers used it to quietly install Monero miners.

Dutch cybersecurity officials say hackers exploited a flaw in macOS Screen Sharing to quietly install Monero mining software on affected devices. The vulnerability let attackers gain remote access without the usual authentication checks, then run mining scripts in the background while the machine's owner noticed nothing beyond a slower fan and a warmer laptop.
The numbers behind the flaw
U.S. officials rated the vulnerability 9.8 out of 10 on the Common Vulnerability Scoring System, a scale that tops out near total system compromise with minimal attacker effort. That score puts it in the same bracket as some of the worst remote-code-execution bugs disclosed in the past decade. The Block reports that the Dutch national cyber agency flagged the exploit after tracking Monero-mining activity traced back to compromised Macs running Screen Sharing with the flawed configuration. Experts cited in the report are urging an immediate update to the latest macOS patch, the standard fix for CVSS-rated bugs once a vendor ships a correction.
Monero was the coin of choice here for a reason that has nothing to do with price. Its default privacy features hide wallet addresses and transaction amounts, which makes tracing where mined coins end up close to impossible for investigators. That is also why Monero shows up disproportionately in cryptojacking cases compared with its actual market size: attackers pick it because it is hard to follow, not because it is popular.
Why cryptojacking still works
The read here is simple: cryptojacking survives because it is boring and invisible, and boring, invisible attacks are the ones that persist the longest. A ransomware attack announces itself the moment files get locked. A stolen-wallet drain shows up in a balance the second it happens. A background miner just sits there, clipping a slice of CPU cycles and a slice of a monthly electricity bill, for months or years, until someone finally notices the machine running hot for no obvious reason.
That asymmetry is what makes a 9.8-rated flaw in something as widely used as macOS Screen Sharing genuinely dangerous rather than a headline number. Screen Sharing sits on by default for a meaningful share of Mac users who rely on it for remote support or file access between their own devices. A flaw that critical, in a feature that common, gives an attacker a wide net with very low visibility once they are in. Mining malware doesn't need privilege escalation drama or a ransom note. It needs time, and until this disclosure, time was exactly what it had.
The bigger point is about incentives on the attacker's side. Monero's price has been a fraction of bitcoin's for years, yet it remains the preferred payout for this category of attack, which tells you the calculation isn't about the size of the reward. It's about the odds of getting caught. As long as untraceable mining income beats traceable theft on a risk-adjusted basis, this category of attack keeps showing up in unpatched machines, regardless of what any single coin is worth that week.
What to watch next
The next signal worth tracking is whether the CVSS 9.8 rating triggers a mandatory patch push from Apple with forced update prompts, versus a routine advisory that many users skip. Cryptojacking campaigns tend to have a long tail after disclosure, since patch adoption on personal devices is slower and less complete than on managed corporate fleets. If Monero-linked mining traffic tied to this exploit keeps showing up in network telemetry three or six months from now, that's the clearest evidence the fix isn't reaching the machines that need it.
