Visualização de leitura

Update your Mac: Screen Sharing vulnerability exploited in the wild

The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers.

The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials.

macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900. Successful exploitation can allow a remote attacker on a reachable network to authenticate to the service without legitimate credentials.

Apple said the bug was fixed through “improved state management,” which suggests an authentication-flow or session-state validation failure rather than a cryptographic break.

The patch was issued for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Practical exposure requires Screen Sharing to be enabled, so the highest-risk systems are those where port 5900 is internet-accessible, typically through a router port-forward, public IP assignment, or hosting-provider setup. Hosts reachable only from an internal network are still potentially exposed, but attackers would have to gain a position on that network.

An attacker could view and control the Mac remotely because that is the function Screen Sharing provides. NCSC says active cases involved attackers gaining root access and installing cryptomining software, specifically for Monero mining.

The criminals likely chose Monero mining because it does not depend on heavily specialized, application-specific integrated circuits (ASICs), but can be done with any CPU or GPU.

Cryptomining isn’t necessarily the worst an attacker could do. With a root-level compromise an attacker could enable persistence, data theft, credential and key harvesting, deployment of additional malware, and lateral movement.

How to stay safe

Install the update

The best way to protect your Mac is to install the update.

To update macOS on any supported Mac, use the Software Update feature, which Apple designed to work consistently across all recent versions. Here are the steps:

  • Click the Apple menu in the upper-left corner of your screen.
  • Choose System Settings (or System Preferences on older versions).
  • Select General in the sidebar, then click Software Update on the right. On older macOS, just look for Software Update directly.
  • Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, please read these instructions.
  • Enter your administrator password if prompted, then let your Mac finish the update (it might need to restart during this process).
  • Make sure your Mac stays plugged in and connected to the internet until the update is done.

Make sure Screen Sharing is disabled

If you can’t update immediately, check whether Screen Sharing is enabled and turn it off if you don’t use it.

  1.  Click the Apple menu in the top-left corner of the screen.
  2. Select System Settings.
  3. In the left sidebar, click General.
  4. Click Sharing on the right; you may need to scroll down.
  5. Find Screen Sharing:
    • If the switch is off/grey, it is disabled.
    • If the switch is on/colored, click it to switch it off.

Also check Remote Management on that same Sharing page. It provides another remote-control route and should be off unless the owner knowingly uses it for work or IT support.


Macs need protection too

Malwarebytes Premium Security for Mac stops threats and protects your Mac and personal files from hackers and cybercriminals.

What’s your data worth on the dark web? (Lock and Code S07E15)

This week on the Lock and Code podcast…

Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.”

Pithy as the phrase sounds, it is undeniably true.

Data steers decisions at businesses of every size. Data created entirely new industries built around its capture. And, for a select number of companies, data has produced billions—if not trillions—of dollars in value.

So how is it that, on the dark web, your stolen identity can be purchased for just 95 cents?

That’s what a Malwarebytes researcher found last month after spending 48 hours inside the dark web to investigate cybercrime. Across a variety of forums and directories, he found subscription plans for malware that steals information once implanted on a device. He found guides for deploying social engineering scams. He found people selling their services to build fake websites that trick people into handing over their usernames and passwords. And he found one of the dark web’s most traded commodities—personal data, packaged together about individual people, to help a cybercriminal commit identity fraud.

These packages are called “fullz.” For victims in the United States, a fullz contains a full name, Social Security Number, date of birth, address, and other personal details. That is enough, on its own, for a cybercriminal to potentially open a bogus line of credit, file a fake tax return, access financial accounts, or obtain medical services under someone else’s name.

As we wrote on Malwarebytes Labs:

“For less than the cost of a cup of coffee, a cybercriminal can buy enough information to devastate someone’s financial life.”

It’s the kind of risk that could scare anyone, especially considering the scale behind it. In just the first six months of 2026, Malwarebytes found more than 7,500 compromised data sets on the dark web containing more than 8.4 billion records.

And yet, even today, cybersecurity professionals still get asked why anyone should bother protecting their data.

The public, understandably, are exhausted. With data breaches happening every week—if not every day—cybersecurity can start to feel pointless. With young people unable to build financial security, they start believing that they have nothing worth stealing. And with Big Tech already collecting our every movement, behavior, click, and concern, people understandably feel powerless to fight any kind of data abuse, be it corporate or criminal.

So today’s episode approaches the question from a different direction. This isn’t about why you should protect yourself—plenty of company websites will tell you that, and most of them rely on fear. This is about why hackers want your data in the first place.

Today, on the Lock and Code podcast, host David Ruiz explains how cybercriminals turn a single repeated password into account takeover, how a screenshot of your house from Google Maps became a tool in extortion emails, and why the most benign information about you—an address, an age, one public photo—is often the most useful data a stranger can buy.

Tune in today to listen to the full episode.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

Warning: Scammers are using FaceTime to empty bank accounts

Apple is urging users to treat any suspicious FaceTime call or message as untrusted, especially if it involves payments, refunds, password resets, or requests for personal information.

This warning appears in a broader Apple support article about scams that target iPhone and iPad users through social engineering. Apple says attackers may contact people by phone calls, FaceTime, text messages, or emails while pretending to represent a trusted organization.

The advice comes as many users still delay installing security updates, leaving them exposed even after Apple has released security patches.

Over recent months, we’ve seen a familiar pattern: attackers combine convincing Apple‑branded social engineering with known iOS vulnerabilities, then profit from the gap between “patch available” and “patch installed.”

Criminals have been reported making unsolicited FaceTime calls that look like they come from “Apple Support” or a bank, alongside messages disguised as urgent account alerts or refund offers. Once the victim answers or replies, the script is pretty much standard:

  • The caller claims there is fraudulent activity or a technical problem.
  • They pressure the user to “verify” card details, online banking credentials, or Apple ID information.
  • In some cases, they persuade the victim to install remote‑access software or share one‑time passcodes.

Nothing in this process requires malware on the device. The “exploit” is human trust, backed by familiar names, logos, and a real‑time call that feels inherently more legitimate than a text message. That makes FaceTime a useful delivery channel for social engineering, especially since users are used to seeing Apple notifications and support prompts elsewhere in their digital life.

From an attacker’s point of view, combining social engineering with vulnerabilities is attractive. Social engineering can steal your usernames and passwords, while a browser‑side exploit can silently execute malicious code when users visit a booby‑trapped site. Chain those attacks together and the attacker can move from app‑level compromise to full system control. That’s how campaigns like DarkSword operate.

How to stay safe

Apple’s advice is straightforward:

  • Don’t trust unexpected calls or texts.
  • Never share sensitive information over unsolicited contact.
  • Keep your iPhone updated to the latest iOS version.

We’d add:

  • Protect your devices with an up-to-date, real-time security solution.
  • Contact companies directly through trusted channels. Don’t use contact details provided in an email, text message, or call.
  • Use Malwarebytes Scam Guard to determine whether a message is likely to be a scam.
  • Be especially suspicious of unexpected FaceTime calls claiming to be from your bank or Apple. These organizations are unlikely to use FaceTime to contact you about serious account issues.

Apple also asks users to report suspicious FaceTime calls:

“If you receive a suspicious FaceTime call (for example, from what looks like a bank or financial institution), email a screenshot of the call information to reportfacetimefraud@apple.com.”

How to update your iPhone or iPad

To check whether you’re running the latest version of iOS or iPadOS:

  • Go to Settings > General > Software Update. If an update is available, you’ll be able to download and install it from there.
  • Turn on Automatic Updates if you haven’t already. You’ll find it on the same screen. That way, your device can install important security updates as soon as they’re available.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

This pay gap is programmed (Lock and Code S07E13)

This week on the Lock and Code podcast…

Pay is personal for plenty of Americans, but a new distribution model that consumes vast quantities of worker data is turning pay into something else: personalized.

For an increasing number of workers in America, the money they can expect to be paid on any given day, week, or month is unknown to them. They could work the same number of hours as they did the shift before. They could help the same number of customers. They could do everything, as nearly similar as possible, and still be paid less than another worker in the exact same position, or even themselves just last week.

The mechanism behind this pay disparity is called algorithmic wage discrimination and while the term may be new, it’s inner workings could sound quite familiar.

Algorithmic wage discrimination describes the zig-zag pay that is meted out to contract workers by big companies like Uber and Amazon. Whereas many workers in the world rely on salaries, or commissions, or self-determined contract rates, workers at Uber are different.

In the same way that Uber decides what you pay for a ride to the airport, Uber also decides what a driver makes. And the calculus behind that decision is opaque. Location, traffic, the time of day, and the number of drivers on the road all play some role, but not a complete one. And in the same way that Uber incentivizes you with a flash sale or a price so high that you maybe walk a couple blocks in a different direction to get a lower price, Uber incentivizes drivers with bonuses and challenges, keeping them on the road perhaps longer than they intended.

The end result, then, isn’t just unpredictable pay—it’s potentially an attempt to predict and control behavior.

For her 2023 paper, titled “On Algorithmic Wage Discrimination,” professor of law Veena Dubal spoke with many Uber drives who compared this system to “casino culture,” in that the pay is unpredictable but the potential for a jackpot—or, just a good payment on one ride—is enough to convince drivers to stick around, night after night, hour after hour.

As one driver told Dubal:

“It’s like gambling! The house always wins.”

Today, on the Lock and Code podcast with host David Ruiz, we speak with Dubal—professor of law at the UC Irvine School of Law—about how algorithmic wage discrimination works, what data it consumes to function, and the threat it poses as it creeps from gig work into many more industries.

Tune in today to listen to the full conversation.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)


Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium Security for Lock and Code listeners.

Cardiac patients’ medical data stolen and held to ransom

Cardiac monitoring provider iRhythm has been hit by a data theft followed by an extortion attempt.

In a filing with the Securities and Exchange Commission (SEC), iRhythm revealed it was contacted by someone on June 9 who claimed to have stolen sensitive information, including proprietary data, patient PHI, and other personal information. That person demanded payment in exchange for not publishing the data.

iRhythm provides ambulatory cardiac monitoring and analysis (for example using the Zio patch) and has reportedly processed over two billion hours of heartbeat data from more than twelve million patients.

In the filing, the company said the data was obtained through social engineering and is from “certain third-party-hosted business applications”, without revealing any further details about the amount of data.

On its own website, iRhythm also doesn’t disclose much about the nature of the stolen data, but does seem to imply no financial data was affected:

“We have not identified any impact to our products, our clinical or medical device systems, our connections to customers, our manufacturing and distribution operations, patient safety, or our ability to meet patient needs. In addition, we do not store or retain individual financial account information or payment card information. 

 As we actively investigate, we will notify individuals affected by this incident in accordance with applicable law and take steps as needed to protect and remediate the impact to them.“

However, the SEC filing adds that iRhythm determined that the incident is significant, “in light of the volume of the potentially affected data.” Together with the extortionist’s claims that they have patients’ medical data, that makes the breach one worth noting if you have used iRhythm’s services.

Even without payment data, healthcare breaches have serious downstream effects:

  • Attackers can craft highly convincing emails, texts, or calls that reference specific procedures or monitoring episodes (for example, “about your recent Zio patch recording”) to trick patients into sharing more data or paying fake bills.
  • The breached data can be used to create a fake identity, insurance fraud, or medical identity theft.
  • Exposure of cardiac and other health‑related information can be deeply sensitive and may have employment/insurance ramifications, especially if data is posted publicly or sold to data brokers.

Healthcare breach data tends to circulate for years, and victims may face sporadic fraud and phishing attempts long after the headlines fade.

How to stay safe

If you’ve used iRhythm’s services, keep an eye on your post, email, and patient portals for official breach notifications from iRhythm or your healthcare provider.

In the US, breaches of protected health information that meet certain criteria must be reported to patients and regulators. iRhythm has promised to “notify individuals affected by this incident in accordance with applicable law and take steps as needed to protect and remediate the impact to them.”

To stay out of the hands of phishers and scammers:

  • When you receive a communication about the data breach, verify through other channels that it really came from iRhythm. Go directly to iRhythm’s official website or patient portal, or call a known phone number to confirm the communication is genuine.
  • Be extra suspicious of emails or texts that claim to offer compensation, refunds, or other financial consequences related to this incident.
  • Change passwords for your iRhythm‑linked portals and your cardiology or hospital patient portals, especially if you reused those passwords elsewhere.
  • Log into your health insurer’s portal and check claims on a regular basis.
  • If you see anything suspicious, report it immediately to your insurer and provider and ask them to flag your account for possible identity theft.
  • Do not provide personal or financial information over the phone just because the caller knows details about you which they may have obtained from the stolen data.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

❌