Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: Claude Ships Text Watermarking as macOS Screen Sharing Flaw (CVE-2026-65400) Is Exploited for Monero Mining (20260818)

Anthropic begins watermarking Claude-generated text to make AI content detectable, while an actively exploited macOS Screen Sharing vulnerability (CVE-2026-65400) gives unauthenticated attackers full control of internet-exposed Macs to deploy Monero miners. Also today: Kaspersky details the Russia-nexus Armored Likho (Sticky Werewolf) group's expanded STILL toolkit that steals Telegram sessions and records audio; Fortinet analyzes the multi-functional Evooo1Bot Linux botnet extending Mirai beyond DDoS; and xAI escalates its First-Amendment fight against Minnesota's nudification-deepfake ban.

Anthropic Claude AI-watermarking content-provenance Apple macOS Screen-Sharing CVE-2026-65400 Monero cryptomining Armored-Likho Sticky-Werewolf STILL-toolkit Kaspersky Telegram spyware Evooo1Bot Mirai Linux-botnet DDoS Fortinet xAI Grok nudification deepfake Minnesota CISO-Digest

Provenance and Exploitation on the Same Day: Claude Watermarks Its Text as Attackers Seize Macs Over Screen Sharing

Anthropic announced it will watermark text generated by Claude, embedding a statistical signal in the model’s word choices so that AI-authored content can later be detected without changing how the text reads to a human. The company frames the move as an accountability measure for a period in which AI-written prose is increasingly indistinguishable from human writing — a direct response to abuse cases spanning academic fraud, influence operations, and automated fraud. Anthropic acknowledges the mark is a “nudge” on token selection rather than a cryptographic guarantee: it can survive light editing but degrades under heavy paraphrasing or translation, and it is detectable only with Anthropic’s own tooling. The disclosure lands amid an industry-wide provenance debate, with OpenAI, Google DeepMind (SynthID), and regulators all pushing competing schemes for labeling synthetic media and text.

The same day underscored why provenance is only half the battle. Security researchers confirmed that a macOS Screen Sharing vulnerability, CVE-2026-65400, was being actively exploited in the wild against internet-exposed Macs. The flaw lets an unauthenticated attacker gain full control of a target Mac — no password required — by abusing Apple’s Screen Sharing / Remote Management service, and attackers have been chaining it to deploy Monero (XMR) cryptocurrency miners on compromised machines. Because Screen Sharing is a built-in macOS service and many Macs sit directly reachable on the internet or on flat office networks, the exploit path is short and the blast radius is broad; researchers urged organizations to disable Screen Sharing where it is not required, block the service at the network edge, and apply Apple’s fix immediately.

Why This Matters for Enterprise Risk

  • Content provenance is becoming a vendor-differentiated control, not a standard. Claude’s watermark, SynthID, and OpenAI’s efforts are mutually incompatible and detectable only by their originators. CISOs evaluating AI-content risk (fraud, impersonation, disinformation) cannot assume interoperable detection — provenance coverage now depends on which model produced the text.
  • “No password required” flaws in built-in remote-access services are top-tier exposure. CVE-2026-65400 abuses a native macOS capability that is trivial to leave enabled. Remote-management surfaces (Screen Sharing, RDP, VNC, SSH) on internet-facing endpoints deserve continuous external attack-surface monitoring, not one-time hardening.
  • Cryptomining is the low-noise monetization of full device control. An attacker with root-equivalent access chose mining — a deliberately quiet payload. The same access supports data theft, ransomware staging, or lateral movement, so a “just a miner” finding should be treated as evidence of full compromise.

🔗 Reference: Coverage from (Anthropic, TechCrunch, The Hacker News, Ars Technica)


Active Threats This Week

📌 macOS Screen Sharing flaw CVE-2026-65400 exploited to install Monero miners — no password needed Researchers confirmed that CVE-2026-65400, a vulnerability in Apple’s macOS Screen Sharing / Remote Management service, is being exploited against internet-exposed Macs to gain full, unauthenticated control of the device and deploy Monero cryptominers. The attack requires no credentials, and because Screen Sharing is a native macOS service frequently left reachable, exposure is widespread. Defenders should disable Screen Sharing where unneeded, restrict it at the network boundary, and patch to the fixed macOS build. 🔗 Reference: The Hacker News, Ars Technica

📌 Anthropic begins watermarking Claude-generated text Anthropic will embed an invisible statistical watermark into text produced by Claude, letting the company later identify AI-generated content without altering readability. Anthropic is explicit that the mark is a probabilistic “nudge” on word choice — robust to light edits but weakened by heavy paraphrasing or translation, and detectable only with Anthropic’s tooling. The change adds to a fragmented provenance landscape alongside Google’s SynthID and OpenAI’s labeling work. 🔗 Reference: Anthropic, TechCrunch

📌 Armored Likho (Sticky Werewolf) expands its STILL toolkit to steal Telegram sessions and record audio Kaspersky’s Securelist detailed how the Russia-nexus Armored Likho group (also tracked as Sticky Werewolf) has broadened its STILL toolkit with implants that hijack Telegram sessions, capture microphone audio, and conduct persistent cyber-espionage against government and industrial targets. The toolkit uses modular components and covert delivery to maintain long-dwell surveillance, reflecting a shift from smash-and-grab intrusions toward continuous intelligence collection. 🔗 Reference: Securelist (Kaspersky), CyberSecurityNews

📌 Evooo1Bot: multi-functional Linux botnet pushes Mirai capabilities beyond DDoS Fortinet’s FortiGuard Labs analyzed Evooo1Bot, a multi-functional Linux botnet built on the Mirai lineage but extended well beyond DDoS into credential abuse, propagation, and modular payload delivery. The botnet targets exposed Linux servers and IoT devices, and its expanded feature set signals the continued commoditization of Mirai-derived code for broader criminal operations. 🔗 Reference: Fortinet FortiGuard Labs, The Hacker News

📌 xAI escalates First-Amendment challenge to Minnesota’s nudification-deepfake ban Elon Musk’s xAI continued its legal fight against Minnesota’s first-in-the-nation law restricting AI “nudification” deepfake technology, arguing the statute violates the First Amendment. The case — closely watched because it pits generative-AI platform liability against free-speech claims — will help define how far states can regulate the outputs of general-purpose image models. Minnesota’s Attorney General is defending the ban as a protection against non-consensual intimate imagery. 🔗 Reference: NBC Chicago, Minnesota Reformer


OPSWAT Can Help

Today’s most actionable enterprise threat is a remote-access exposure rather than a file-borne one — CVE-2026-65400 is best addressed by disabling and firewalling macOS Screen Sharing and patching promptly. Where AI-content provenance matters (fraud, impersonation, synthetic-document submissions), organizations should note that watermark detection is vendor-specific and incomplete. For the file-based tail of today’s activity — botnet droppers and espionage implants delivered as binaries or documents — MetaDefender Multi-Scan inspects incoming files with 30+ antimalware engines, and MetaDefender CDR (Content Disarm & Reconstruction) neutralizes weaponized documents and archives before they reach endpoints.