AIToday
Large Language ModelsAI Safety & AlignmentStratechery (Ben Thompson)Published: Oct 5, 2026, 19:01 JST

CVE-2026-65400 Hack: Mac Mini Cleaned by Agent

CVE-2026-65400 Hack: Mac Mini Cleaned by Agent

3 Key Points

  1. What happened

    A high-severity macOS vulnerability, CVE-2026-65400 (severity 7.1 out of 10), was actively exploited on systems where port 5900 was exposed; attackers gained root access and placed a Monero crypto miner. Apple patched it last week for macOS Tahoe, Sequoia, and Sonoma.

  2. Why it matters

    The exploit hit a machine that ran only agents, and those agents helped find the breach and wipe it, showing agent-driven PCs can be both a risk and a defense.

  3. What to watch

    The outcome hinges on whether Apple's promised additional controls on full disk access make headless Macs useable by agents. Watch the software release Apple plans on Oct. 13.

WHO IT HITSMac administrators and security teams managing always-on, headless Macs — especially those exposing screen sharing or port 5900 — may need to reconsider their patching and access controls, since the attacker gained root and installed a crypto miner before the patch.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The vulnerability lay in macOS's screen-sharing state management, and the Dutch National Cyber Security Centrum reported active abuse on multiple systems where port 5900 was internet-accessible. Apple softened its own disclosure — saying the flaw "may" allow access without credentials — a hedging common among developers.

In this case, the hacked machine ran only Claude and Codex, and the Claude agent flagged the issue, stopped executing commands, and noticed the account could run admin commands without a password. Thompson ignored Claude's advice not to invoke it further; instead he used it to find the exact four-second access window, build a monitoring tool, and wipe the Mac Mini. The episode sits alongside Apple's note on tightening full disk access for agents, and its Oct. 13 smart-home push with the J490 hub and a new Siri. Thompson argues the obstacles are wider than one patch: macOS permission prompts are invisible to software, so agents fail silently unless a human clicks OK, which pushed him to keep screen sharing on and, indirectly, to be hacked.

FAQ
How did the attackers get in?
Attackers exploited a flaw in macOS screen sharing when port 5900 was exposed to the internet. Once inside, they gained root access and placed a Monero crypto miner.
Did Apple fix the vulnerability?
Yes. Apple patched CVE-2026-65400 last week for macOS Tahoe, Sequoia, and Sonoma. The patch came after details went public at the Black Hat security conference.
What is Apple planning for full disk access?
Apple's developer site said it will introduce additional controls so users who grant an app full disk access must do so with explicit action. The note cited growing risks from AI agents.
Stratechery (Ben Thompson)Read Original Article

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleNvidia 2030: $625 bull case, $135 bear case