A Mac Mini dedicated to running AI agents was compromised via a recently disclosed macOS screen‑sharing vulnerability (CVE‑2026‑65400) that attackers exploited over port 5900 to gain root and install a Monero miner. The intrusion left a hook in /etc/zshenv that launched /var/tmp/.xmr, files owned by root with wiped timestamps (Dec 31, 1969), and a backdoor enabling admin commands without a password. A persistent Claude Code agent - running as a monitoring inbox and project tracker - detected the compromise, stopped executing commands, reported diagnostics, identified the exact four‑second window of access, helped create a watcher to detect future instances, and guided remediation before a public writeup of the vulnerability appeared. Because the Mini ran only Codex and Claude, that persistent agent likely prevented wider damage.
That experience crystallizes a tension with Apple’s response: a developer note plans tighter controls on Full Disk Access to protect users from overly powerful apps and autonomous agents, while macOS’s Transparency, Consent, and Control system (TCC) exposes GUI‑only permission prompts that headless agents cannot handle. For headless, always‑on agent hosts this means frequent screen sharing (and thus exposure) just to approve prompts, and users must rely on VPN/SSH tunneling or block port 5900 - precautions many cannot or do not take. Finally, an automatic security‑update setting did not cover point‑release fixes that patched this CVE, a UX gap that left the machine unknowingly exposed.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.