
What happened
A high-severity macOS vulnerability, CVE-2026-65400 (severity 7.1 out of 10), was actively exploited on systems where port 5900 was exposed; attackers gained root access and placed a Monero crypto miner. Apple patched it last week for macOS Tahoe, Sequoia, and Sonoma.
Why it matters
The exploit hit a machine that ran only agents, and those agents helped find the breach and wipe it, showing agent-driven PCs can be both a risk and a defense.
What to watch
The outcome hinges on whether Apple's promised additional controls on full disk access make headless Macs useable by agents. Watch the software release Apple plans on Oct. 13.
WHO IT HITSMac administrators and security teams managing always-on, headless Macs — especially those exposing screen sharing or port 5900 — may need to reconsider their patching and access controls, since the attacker gained root and installed a crypto miner before the patch.
Summaries like this, in your inbox every morning.
The vulnerability lay in macOS's screen-sharing state management, and the Dutch National Cyber Security Centrum reported active abuse on multiple systems where port 5900 was internet-accessible. Apple softened its own disclosure — saying the flaw "may" allow access without credentials — a hedging common among developers.
In this case, the hacked machine ran only Claude and Codex, and the Claude agent flagged the issue, stopped executing commands, and noticed the account could run admin commands without a password. Thompson ignored Claude's advice not to invoke it further; instead he used it to find the exact four-second access window, build a monitoring tool, and wipe the Mac Mini. The episode sits alongside Apple's note on tightening full disk access for agents, and its Oct. 13 smart-home push with the J490 hub and a new Siri. Thompson argues the obstacles are wider than one patch: macOS permission prompts are invisible to software, so agents fail silently unless a human clicks OK, which pushed him to keep screen sharing on and, indirectly, to be hacked.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
OpenAI released its Jev-style Decisions API, previously announced at last week's DevDay, and Simon Willison us…

The engineer wired Claude Code headless into a pipeline that turns backlog items into merged code, logging 243…

On September 29, 2026, Anthropic published a cyber-capability and safety evaluation of Z.ai's GLM-5.3, reporti…

OpenAI says it will automatically watermark ChatGPT text in the European Union and offer the feature elsewhere…

Lucas Baker, Head of LLM R&D at Jump Trading, said GPT-6 Astra lets agents run multi-day quant research workfl…

Fujitsu announced four AI agents for retail store operations and management decisions, covering sales structur…
