B
今週中
macOSの画面共有機能における認証回避の脆弱性(CVE-2026-65400)が悪用され、Moneroマイナーが展開されていること
📌 一言でいうと
macOSの画面共有機能における認証回避の脆弱性(CVE-2026-65400)が悪用され、Moneroマイナーが展開されていることが判明しました。攻撃者はポート5900が公開されているMacを標的にし、有効な資格情報なしでルート権限を取得することが可能です。Appleは既にmacOS Tahoe 26.6.1、Sequoia 15.7.9、Sonoma 14.8.9で修正済みのパッチをリリースしています。
🔍該当判定
- 社内でMac(macOS)を利用している
- Macの標準機能である「画面共有」を有効にしている
- 外部(インターネット)からMacにリモート接続できるよう、ポート5900を開放している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
速やかにmacOSを最新バージョン(Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9以降)にアップデートすること。また、不要な場合は画面共有機能を無効化し、ポート5900を外部に公開しない設定を確認すること。
📧 メール案を見る (社員向け + 管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【注意喚起】Macをご利用の方は至急OSのアップデートをお願いします
お疲れさまです。情報システム担当です。
Macの「画面共有」機能に深刻な欠陥が見つかり、これを悪用して不正なソフト(仮想通貨マイナー)をインストールさせる攻撃が確認されています。
ご協力をお願いしたいこと:
1. Macの「システム設定」からソフトウェアアップデートを確認し、最新の状態に更新してください。
2. 不審な動作や、PCの動作が極端に重くなった場合は、すぐにシステム担当までご連絡ください。
対応期限: 本日中
お疲れさまです。情報システム担当です。
Macの「画面共有」機能に深刻な欠陥が見つかり、これを悪用して不正なソフト(仮想通貨マイナー)をインストールさせる攻撃が確認されています。
ご協力をお願いしたいこと:
1. Macの「システム設定」からソフトウェアアップデートを確認し、最新の状態に更新してください。
2. 不審な動作や、PCの動作が極端に重くなった場合は、すぐにシステム担当までご連絡ください。
対応期限: 本日中
Subject: [Urgent] Please update your macOS immediately
Hi everyone,
A critical security flaw has been discovered in the macOS "Screen Sharing" feature, which attackers are using to install unauthorized software (cryptocurrency miners) on affected devices.
Action required:
1. Please check for software updates in "System Settings" and update your macOS to the latest version immediately.
2. If you notice any unusual system behavior or extreme slowdowns, please report it to the IT department right away.
Deadline: End of today
Hi everyone,
A critical security flaw has been discovered in the macOS "Screen Sharing" feature, which attackers are using to install unauthorized software (cryptocurrency miners) on affected devices.
Action required:
1. Please check for software updates in "System Settings" and update your macOS to the latest version immediately.
2. If you notice any unusual system behavior or extreme slowdowns, please report it to the IT department right away.
Deadline: End of today
件名: 【共有】macOS Screen Sharing 脆弱性 (CVE-2026-65400) 対応について
お疲れさまです。macOSの画面共有機能における認証回避の脆弱性に関する情報共有です。
■ 概要
macOSの画面共有機能において、有効な資格情報なしで認証を回避し、ルート権限を取得できる脆弱性が確認されました(CVE-2026-65400, CVSS 9.8)。現在、ポート5900を公開している環境を標的にMoneroマイナーを配備する攻撃が観測されています。
■ 影響範囲
- macOS Tahoe, Sequoia, Sonoma の未修正バージョン
- 特にポート5900 (VNC/Screen Sharing) を外部に公開している端末
■ 対応手順
1. 以下の修正済みバージョンへのアップデートを強制適用してください:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
2. ネットワーク境界において、不要なポート5900の外部公開を遮断してください。
■ 参考情報
- Apple Security Updates
対応優先度: 高
対応期限: 至急
お疲れさまです。macOSの画面共有機能における認証回避の脆弱性に関する情報共有です。
■ 概要
macOSの画面共有機能において、有効な資格情報なしで認証を回避し、ルート権限を取得できる脆弱性が確認されました(CVE-2026-65400, CVSS 9.8)。現在、ポート5900を公開している環境を標的にMoneroマイナーを配備する攻撃が観測されています。
■ 影響範囲
- macOS Tahoe, Sequoia, Sonoma の未修正バージョン
- 特にポート5900 (VNC/Screen Sharing) を外部に公開している端末
■ 対応手順
1. 以下の修正済みバージョンへのアップデートを強制適用してください:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
2. ネットワーク境界において、不要なポート5900の外部公開を遮断してください。
■ 参考情報
- Apple Security Updates
対応優先度: 高
対応期限: 至急
Subject: [Technical Alert] macOS Screen Sharing Vulnerability (CVE-2026-65400)
Hi team,
This is a technical alert regarding a critical authentication bypass vulnerability in macOS Screen Sharing.
■ Overview
CVE-2026-65400 (CVSS 9.8) allows an attacker on the network to authenticate to Screen Sharing without valid credentials, potentially gaining root access. Active exploitation has been observed, specifically targeting systems with port 5900 exposed to deploy Monero miners.
■ Scope
- Unpatched versions of macOS Tahoe, Sequoia, and Sonoma.
- Systems with port 5900 (VNC/Screen Sharing) exposed to the internet/network.
■ Mitigation Steps
1. Ensure all macOS endpoints are updated to the following versions:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
2. Audit firewall rules to block unauthorized access to port 5900.
■ Reference
- Apple Security Updates
Priority: High
Deadline: Immediate
Hi team,
This is a technical alert regarding a critical authentication bypass vulnerability in macOS Screen Sharing.
■ Overview
CVE-2026-65400 (CVSS 9.8) allows an attacker on the network to authenticate to Screen Sharing without valid credentials, potentially gaining root access. Active exploitation has been observed, specifically targeting systems with port 5900 exposed to deploy Monero miners.
■ Scope
- Unpatched versions of macOS Tahoe, Sequoia, and Sonoma.
- Systems with port 5900 (VNC/Screen Sharing) exposed to the internet/network.
■ Mitigation Steps
1. Ensure all macOS endpoints are updated to the following versions:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
2. Audit firewall rules to block unauthorized access to port 5900.
■ Reference
- Apple Security Updates
Priority: High
Deadline: Immediate