TL;DR
Get the latest gadgets delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Ben Thompson of Stratechery reported that attackers compromised his always-on Mac Mini through a macOS screen-sharing vulnerability, CVE-2026-65400, which Apple had patched for three macOS versions. He said an AI coding agent detected suspicious system changes and helped investigate, while Apple separately announced tighter controls for Full Disk Access. The incident illustrates both the potential security value of persistent agents and the risks of granting software broad access.
Ben Thompson, the writer of Stratechery, says attackers gained root access to his always-on Mac Mini by exploiting a macOS screen-sharing vulnerability, and that an AI coding agent helped flag and investigate the compromise. The incident links a patched security flaw, CVE-2026-65400, to a broader question about how AI agents should be given access to personal computers.
Thompson said the computer ran Claude and Codex and contained little else. He reported that Claude sent an urgent alert after noticing changes that included the account being able to run administrator commands without a password. The agent stopped executing commands and suggested steps to address the issue, according to Thompson’s account.
Thompson said he used Claude to investigate the intrusion, identify a four-second period when access was gained, create a monitoring tool and remove the malware before wiping the Mac Mini. He wrote that these steps took place before he found an Ars Technica report about the vulnerability. His account describes his own system; the source material does not independently establish how the attackers entered it.
The Netherlands National Cyber Security Centrum warned that it had received reports of active exploitation on systems with port 5900 exposed to the internet. It said attackers accessed root privileges and installed a Monero cryptocurrency miner on the systems in those reports. Apple had issued a patch the previous week for macOS Tahoe, Sequoia and Sonoma. The flaw was rated 7.1 out of 10 in severity and relates to state management in macOS screen sharing, which can let a remote party view and control a Mac.
Agent Access Becomes a Security Trade-Off
The episode shows a potential benefit and a risk of persistent computer agents. Thompson’s account suggests that an agent monitoring activity on a machine may spot unusual system changes and help a user respond. At the same time, a compromised computer running an agent raises questions about what the agent can access, what actions it can take and whether its own permissions could increase the consequences of an intrusion.
Apple’s announced plan to add controls around Full Disk Access makes the issue relevant beyond one compromised Mac. That permission can expose sensitive material, including files, messages and browsing history. Apple said its controls are intended to make users take explicit action before granting such broad access, with AI agents among the reasons the company cited for addressing the risk.
Mac Mini security monitoring tools
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The Vulnerability and Apple’s Access Policy
CVE-2026-65400 affects macOS screen sharing, a feature that can allow remote viewing and control of a Mac when it is on. The reported exploitation involved systems where port 5900 was reachable from the internet. The Dutch cybersecurity agency’s warning concerned multiple systems, but the provided source does not give a total number or identify their owners.
Apple credited security firm Bynario with reporting the flaw. Apple said the vulnerability “may” allow an attacker without credentials to gain access to a Mac. Details became public at a Black Hat security conference, and Apple’s patch covered Tahoe, Sequoia and Sonoma, according to the source material.
Separately, Apple published a developer-site notice titled “Updates to Full Disk Access in macOS.” The company said some developers use the permission in ways that can expose users’ data and the communications of people they interact with. It said additional controls would require explicit user action. Thompson argues that the Mac’s Unix foundation and long-standing automation and accessibility features make it a capable host for agents, but he also expressed concern about how Apple will implement the new restrictions.
“CVE-2026-65400 “may” allow an attacker without credentials to gain access to a Mac.”
— Apple
As an affiliate, we earn on qualifying purchases.
Open Questions About the Intrusion
The source material does not identify who attacked Thompson’s Mac Mini, how the attackers found or reached it, or whether its exposure matched the conditions described by the Dutch agency. Thompson said he located a four-second period when the attackers gained access, but he did not provide technical evidence independently verifying the intrusion or the exact method used.
It is also not clear how many systems were affected overall, whether all reported infections involved the same activity, or whether attackers used the vulnerability after Apple’s patch became available. Apple’s statement that the flaw “may” allow access is not a confirmation of every reported exploitation scenario. The timing and details of Apple’s planned Full Disk Access controls have not been specified in the supplied material.
macOS screen sharing vulnerability patch
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Patch Systems and Watch Apple’s Controls
Mac users should apply Apple’s available updates for Tahoe, Sequoia and Sonoma, particularly on machines with screen sharing enabled or exposed to the internet. The Dutch agency’s warning specifically points to systems with port 5900 accessible online. Users and administrators may also want to review which apps have Full Disk Access, while recognizing that the source does not provide a full remediation guide.
Further developments will depend on Apple’s rollout of the promised permission controls and on any additional reporting about exploitation. The available account does not establish a timeline for those controls or say whether Apple has published further technical findings. Thompson’s case is a first-person report, while the wider warning comes from Dutch authorities and Apple’s patch information.
full disk access control software for Mac
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What happened to Ben Thompson’s Mac?
Thompson said attackers compromised his always-on Mac Mini, gained root access and placed malware on it. He later used Claude to investigate and then wiped the machine.
What is CVE-2026-65400?
It is a macOS screen-sharing vulnerability rated 7.1 out of 10 in severity. Apple said it may allow an attacker without credentials to gain access, and issued patches for Tahoe, Sequoia and Sonoma.
Did an AI agent prevent the attack?
No. Thompson said Claude alerted him to suspicious changes after the compromise. He reported that the agent helped investigate and respond, but his account does not establish that it prevented the intrusion.
What is Apple changing about Full Disk Access?
Apple said it plans additional controls so users must take very explicit action before granting an app Full Disk Access. The company has not specified the rollout details in the source material.
Source: hn
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
