Stratechery's Agent-Only Mac Mini Got Hacked — Claude Code Spotted the Intrusion First
Stratechery · rss · 2026-10-05
Ben Thompson details how his always-on Mac Mini, dedicated solely to Claude Code and Codex agents, was compromised via actively-exploited macOS screen-sharing bug CVE-2026-65400 (severity 7.1), which grants root through exposed port 5900 and drops a Monero miner; Apple patched it last week. His persistent Claude Code agent — with a self-restarting monitoring tool, idea-capture system, status board, and Telegram bot interface — detected the anomalous passwordless admin access during a scheduled check, halted command execution on its own, and helped Thompson pinpoint the exact four-second intrusion window before he wiped the machine. The piece also dissects Apple's new tightening of Full Disk Access, framed around growing AI agent risks. Thompson argues macOS TCC permission prompts are GUI-only and invisible to software, a disaster for headless agent hosts: agent-generated programs silently fail, requiring manual screen-sharing intervention. He calls TCC the wrong abstraction layer (permissions should target agents, not programs they write) and links it indirectly to the breach, while acknowledging the Mac's strengths: decades of scripting/automation/accessibility APIs and certified Unix tooling.
More from coding & agent
- Local models on one RTX 5090 now match Claude Code on real-task agent benchmark — dh7net · 2026-10-05
- Dev builds Followon MCP so coding agents remember their own follow-ups — TheWebUiGuy · 2026-10-05
- A Permit Layer for MCP Tool Calls: Same-Key Retries Return the Original Receipt — HotPocketWaves · 2026-10-05
- llama.cpp merges new Metal kernels, making speculative decoding 3.4x faster on M3 Ultra — ggerganov · 2026-10-05
- Alter Zero: open-source Rust terminal agent harness for coding and security — linuztxx · 2026-10-05
- Open-Source Familiar Puts Claude Inside a VRChat Moth Avatar via MCP — repligate · 2026-10-05