Hackers Are Exploiting a Mac Screen Sharing Flaw. Apple Says These 3 Updates Fix It

The exploited flaw can enable Screen Sharing without valid credentials. See the patched macOS versions and the simple step every Mac office should take.

A critical alert has been issued for a flaw in Apple’s operating system MacOS that could allow bad actors to gain access to your computers and install potentially dangerous software. Smaller businesses that may lack a dedicated IT department or a local IT expert should take steps to protect themselves, but luckily this isn’t too tricky.
Here’s what happened, and what steps you should take to protect yourself.
The Loophole In Question
The security loophole affects a tiny part of Apple’s Screen Sharing tool. This tool seems simple, but it can be very useful: it lets someone else on your network see and interact with the display of your Mac. This is commonly used for remote support, where an expert may help you get our of a complex technical issue, or to manage “headless” Macs (plugged in but lacking a monitor) that, for example, act as a database or serve shared files to everyone at work.
Tech site Tom’s Hardware notes that the Netherlands’ National Cyber Security Centre, NCSC-NL reported several attacks had happened in recent weeks where hackers gained deep access to victims’ computers, and installed a Monero cryptocurrency miner. This is a legitimate piece of software that you can use to mine cryptocurrency on non-specialized computers, but in this case the hackers were using it to effectively enrich themselves by using their target computers’ power.
Weekly roundup of the latest in tech news
An Inc.com Featured Presentation
That sounds frustrating, and unfair, but it may not seem like much of a security risk, compared to headline-grabbing cyberattacks that take down whole hospital’s networks.
The Threat Is Growing
In recent days the danger level of the hack, which was first reported earlier in August, has been raised from a Common Vulnerability Scoring System score of just over 7 out of 10 (meaning it’s a “high” security risk that needs fast action to a score of 9.8. This means it’s a “critical” issue that could have a severe impact and demands immediate action.
The danger is that hackers may exploit this loophole in more damaging ways or even snoop around inside a target system and access data that should remain protected and private inside your company.
Source: www.inc.com



