Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Cyberattacks

Clop Claims Shell Breach as macOS Cryptomining Attacks Surface

1 reports · First detected 2026-08-17 · Last active 2026-08-17

The Clop ransomware group has built a record of targeting large organizations and weaknesses in widely used software or supply chains, stealing data to pressure victims into paying. Its claim involving Shell and other companies highlights how one compromised service or vulnerability can expose multiple businesses, intensifying scrutiny of corporate defenses, disclosure practices and incident-response readiness.

An Aug. 17 cybersecurity roundup said Clop claimed to have breached Shell and several other companies and stolen large volumes of data. Separate incidents included attackers exploiting a macOS screen-sharing flaw to deploy Monero mining software and the active exploitation of a GeoServer zero-day vulnerability. Anthropic’s Claude service also suffered an outage. No ransom amount or complete victim count was disclosed.

All Coverage

1 original reports

The Backstory

The history behind this event
Hackers Exploit macOS Screen Sharing Flaw to Mine Monero2026-08-17 · 4 reports · similarity 0.83

Apple’s built-in macOS Screen Sharing service, which uses TCP port 5900, contains an authentication-bypass flaw tracked as CVE-2026-65400. The bug can allow an attacker without valid credentials to gain root-level control of a vulnerable Mac. Systems exposing Screen Sharing to the internet face the greatest risk, as attackers can remotely commandeer computing resources and run Monero cryptocurrency-mining software without the owner’s consent.

The Netherlands’ National Cyber Security Centre, NCSC-NL, said on Aug. 12 that attackers had compromised multiple internet-facing Macs after proof-of-concept exploit code became public, installing Monero miners in every reported case. Apple issued out-of-band fixes on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. The U.S. Cybersecurity and Infrastructure Security Agency raised the flaw’s CVSS score from 7.1 to a critical 9.8 on Aug. 14, reinforcing calls for immediate updates.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)