Apple's Security Update Left Me Hacked—and My AI Agent Saved Me

Apple and a Hacker's Future

Apple's Security Update Left Me Hacked—and My AI Agent Saved Me

A macOS screen-sharing vulnerability (CVE-2026-65400) let attackers plant a Monero miner on my always-on Mac Mini. My Claude agent detected the intrusion, stopped executing commands, and helped remove the malware. But Apple's TCC permission prompts and misleading security-update labeling made the machine harder to secure, while Apple's new Full Disk Access restrictions threaten the agent workflows that saved me.

I understand that people are nervous about giving these agents access to one’s computer — as I noted, the Mac Mini in question has nothing on it except for Codex and Claude — but in this case you could make the case that I would have been in much more trouble had I not had an agent running persistently.
  1. GeekyBear

    The full disk access permission is something you give to backup software.

    If you give full-disk access to Meta software running on your main computer, Meta is not going to respect your privacy.

    > Friday’s [full-disk access] announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.

    https://arstechnica.com/security/2026/10/apple-changes-full-...

    If you want to know why Apple is suddenly not happy about the way the full-disk access permission is being abused, look no further.

  2. PaulHoule

    Apple can’t see a future where Mac isn’t like iPhone. They need a 30% cut of all software revenue, want a 30% cut of any AI tokens you use, and will steal 30% of your time as a software developer developing for your own account any way you can.

  3. jppope

    I think the observation Ben is making, is that Apple no longer has a grasp on the future purchases in the market. He makes it explicit with this quote: "I can, for the first time, envision a future where I don’t buy Apple by default." It used to be a given that we would refresh every 3-4 years, thats probably no longer guaranteed.

    Observationally, I would argue we've all been expecting this for this for a long time. Every year Apple has raised the price of allegiance and every year we've paid it, waiting for products like the framework laptop or certain linux distros to become mature. We're still not there yet, but how much longer until there is real competition in the personal computer market?

  4. mixdup

    I would argue that someone who would open a remote access port to the internet with no filtering is exactly the kind of person that Apple needs to protect from themselves

    Yeah, it was neat that Claude found this, but Thompson showed an almost criminal lack of security awareness by having VNC/ARD open to the internet

  5. reenorap

    Did the author have his Mac exposed to the internet and not behind a firewall? How did his screen sharing port 5900 get accessed if he was behind a physical firewall/home router?

  6. m-s-y

    “this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet”

    We’ve known that improperly secured ports and non-firewalled machines get popped. When will people learn?

    I know let’s put our power plants and water treatment out there with open ports too. Why should endusers have all the fun?

  7. intrasight

    > The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics

    I think he was burying the lede but glad he finally posed the question.

    I think it's a bigger risk factor for Apple than is generally assumed. If consumers get used to the freedom but endemic spying of products like Muse, Apple may have a hard time sticking to their privacy and security mandate.

  8. nerdjon

    What I find most surprising, is that I don't think we got any sort of timeline from Apple on this change and its very vague (which just fuels articles like this).

    So did this initiative within Apple just start and we could be looking at this change coming in Mac 28?

    I don't remember another time of an announcement like this from Apple of a major change with so little information, though I could be wrong or hint of when.

    Regarding the concern, while I do hope that there is still a way to grant actual full disk access to some applications. Even Apple called out a non controversial need for something like that, backup software. I can also think of security scanning software, a lot of businesses have those deployed to corporate Mac's. I do also think that better controls around it, especially in this age of vibe coded apps that never actually think about security or actively hostile companies like meta.

More from this day

2026-10-05