Connect with us

NEWS

Bynario Raises €2.1 Million After Its Apple Bugs Hit

Bynario closed €2.1 million after Apple credited its Screen Sharing research, then attackers used the pre-auth bug to drop Monero miners on exposed Macs.

Published

on

Milan cybersecurity firm Bynario closed a €2.1 million pre-seed round on 10 September 2026, 35 days after Apple patched a Screen Sharing login bypass the lab had reported. Attackers then used that bug to drop Monero miners on Macs that still had port 5900 open.

360 Capital Partners led the round, with PranaVentures in the mix. The cheque is modest. The proof Bynario is selling is not: cheaper AI research pulled a long-shipped Apple service into the set of bugs worth hitting.

A €2.1 Million Check After Apple’s Credit

Bynario was founded in late 2025 in Milan by Alfredo Pesoli, Giancarlo Russo and Lorenzo Cavallaro. The Italian announcement of the round also names Marco Valleri and Alberto Ornaghi among the founders. Pesoli is chief executive. Russo is chief operating officer. Cavallaro, who has written about coming to systems security through 1990s Phrack culture, sits with them as a co-founder.

The company said the money will go into its AI security platform, a larger engineering bench, and work with software, cloud and enterprise customers it already claims to have. Cesare Maifredi, a partner at 360 Capital, said his firm had known most of the founding group for a long time and was buying Pesoli’s technical break and the idea of autonomous discovery, validation, ranking and repair.

Pesoli’s own pitch is about incentives, not model names.

Defense at scale needs the same depth as offense. Attackers are fundamentally incentive-driven. As AI continues to reduce the cost of vulnerability research and exploitation, more exploitable vulnerabilities become attractive targets. The challenge for defenders is only becoming more acute.

Alfredo Pesoli, CEO and co-founder, Bynario, in the 10 September 2026 funding note

That line would be easy to file as seed-round talk. The Apple programme the company ran in July and August is what makes it a product story.

Two Bugs Lived in the Same Screen Sharing Path

Pesoli’s lab pointed frontier models at Apple’s built-in Screen Sharing stack, then took what it found to Cupertino. The first public write-up, posted on 29 July 2026, is a post-login logic flaw, not a memory crash. The target Mac needed Screen Sharing or Remote Management on, the legacy setting “VNC viewers may control screen with password” enabled, and an attacker who already knew that VNC password.

On that legacy path, Pesoli wrote, Apple’s file-copy helpers kept root filesystem rights because a VNC password is not a macOS user identity. A remote viewer could read protected files as root, and in the other direction turned file copy into root command execution by dropping a valid sudoers include. The team tested the chain on macOS 26.5.2 on M4 and M5 chips with System Integrity Protection still on. Memory Integrity Enforcement and pointer authentication did not help, because the bugs are logic errors.

Apple filed both directions under CVE-2026-43760, assigned a CVSS 3.1 base score of 5.5, and described the impact as “An app may be able to access user-sensitive data.” Pesoli said that wording fits the file-read side and underplays the root write. His own conservative score is 8.0 when a later login is required to fire a callback, or 8.8 if a session is already unlocked. The fix shipped in macOS Tahoe 26.6 on 27 July 2026 and in macOS Sonoma 14.8.8. Apple’s security content of macOS Tahoe 26.6 credits Pesoli of Bynar.io alongside two other research names, wdszzml and the Atuin Automated Vulnerability Discovery Engine.

The second bug is the one that left the lab. On 6 August 2026 Apple shipped a security-only update across three still-supported systems for CVE-2026-65400. The advisory says an attacker on the network may be able to authenticate to Screen Sharing without valid credentials, and that improved state management closed the hole. Credit this time is Pesoli via Bynario Atlas alone.

THE TWO APPLE CREDITS

CVE What Apple published Fixes Credit
CVE-2026-43760 An app may be able to access user-sensitive data (Apple score 5.5) Tahoe 26.6 (27 Jul 2026), Sonoma 14.8.8 Pesoli of Bynar.io, with wdszzml and Atuin
CVE-2026-65400 Network attacker may authenticate to Screen Sharing with no valid credentials Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9 (6 Aug 2026) Pesoli via Bynario Atlas

The first bug still needed a VNC password. The second, on Apple’s own wording, did not.

Miners Landed on Exposed Port 5900

The Netherlands’ National Cyber Security Centre opened advisory NCSC-2026-0280 on 7 August 2026, the day after Apple’s three-version patch. On 12 August it revised the note: it had a report of active abuse on systems exposing port 5900 to the internet. In every case it cited, the attacker reached root and installed a Monero miner. NCSC scored the bug 7.1 under CVSS v3.

Two days after the 6 August patches, the Singapore security firm Calif posted a public proof of concept. Its researchers said they reverse-engineered Apple’s 26.6.1 patch and that, with Screen Sharing enabled, a network attacker could log in as any account without the password.

A Screen Sharing daemon left reachable on the public internet is, in that setup, a login that no longer asks for a password. Putting the service behind a VPN is the control that still works on an unpatched Mac. Waiting for every laptop to take a security-only update is not.

On 19 August, Microsoft Threat Intelligence said Defender was seeing the same CVE used on a limited set of Macs, with root Screen Sharing sign-ins, file drops, SSH persistence and XMRig 6.26.0 hidden as a fake Apple process.

FROM DISCLOSURE TO THE CHEQUE

  1. 27 July 2026: Apple ships macOS Tahoe 26.6, fixing CVE-2026-43760 in Screen Sharing Server.
  2. 29 July 2026: Pesoli publishes the post-auth root file-copy chain and disputes Apple’s 5.5 score.
  3. 6 August 2026: Apple ships Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 for CVE-2026-65400, 10 days after 26.6.
  4. 7 August 2026: NCSC-NL warns on the authentication bypass.
  5. 8 August 2026: Calif posts a no-password proof of concept, two days after the patch.
  6. 12 August 2026: NCSC-NL confirms miners and root on internet-facing port 5900.
  7. 19 August 2026: Microsoft describes XMRig 6.26.0, SSH keys and LaunchDaemon persistence on a limited set of Macs.
  8. 10 September 2026: Bynario closes the €2.1 million pre-seed, 35 days after the 6 August patches.

The raise did not create that sequence. It arrived after the sequence had already run on Apple’s own code.

Why Cheaper Research Makes More Bugs Worth Hitting

Pesoli’s claim is not that models invent a new class of Mac bug. It is that falling cost changes which old classes are worth an attacker’s time. A logic flaw in a legacy VNC path sat behind a feature many IT teams still enable for home Macs and closet machines. Once a public proof existed, the profitable use that showed up first was a miner, not a targeted spy implant.

That is the second-order hit. When exploit work is expensive, attackers skim the highest-value targets. When a patch can be reversed in days and a miner can be dropped through the same file-copy helper Pesoli abused in July, a forgotten Screen Sharing box becomes a small, repeatable payday. Defence teams then inherit a longer list of “relevant” issues, not a shorter one.

Bynario is trying to productise the offensive side of that loop: find what is reachable in a given environment, throw out scanner noise, and push a fix. The Apple work was a research programme, not a customer report. Atlas is the name on the product that has to do the same job on code, cloud and supply-chain components other people actually run.

Verizon’s Numbers Already Show Defenders Lagging

The company’s funding note pointed at Verizon’s 2026 Data Breach Investigations Report for the wider backlog. Verizon’s own newsroom, publishing the 19th edition on 19 May 2026, said exploiting bugs had overtaken stolen passwords as the top way into a breach for the first time in the report’s history.

WHAT THE 2026 DBIR COUNTED

  • Initial access: 31% of breaches start with vulnerability exploitation, up from 20% in the prior edition, a 55% rise in that vector.
  • Passwords: Credential abuse fell to 13% of the same initial-access mix.
  • Known exploited bugs: Organisations fully closed 26% of CISA KEV items, down from 38% the year before.
  • Time to close: Median time to full resolution rose to 43 days from 32 days, an 11-day slide.

Those figures describe 2025 incidents, not Bynario’s August Mac bugs. They still describe the queue Atlas has to beat: more exploited bugs as the way in, fewer of the already-catalogued critical ones actually closed, and a slower median fix. A pre-seed lab does not change Verizon’s mix. It is betting that ranking reachable issues beats adding another scanner feed to that queue.

Atlas Tries to Rank What Scanners Only List

Bynario describes Atlas as an autonomous application-security platform that spans source, cloud infrastructure and third-party components, including compiled binaries that never come with readable code. The LinkedIn page is blunter still: the AI is meant to inspect closed-source dependencies and proprietary builds without a source tree, and the stack can run on-premise so that customer code never leaves the building.

WHAT THE LAB SAYS ATLAS MUST DO

  • Find: Hunt unknown issues in code, binaries, cloud and supply-chain pieces, not only match known CVE lists.
  • Prove: Check which findings are actually reachable in that customer’s setup, rather than dumping every scanner hit.
  • Rank: Push the reachable set to the front so a small security team can spend its week on those items.
  • Fix: Carry the work through to repair, which is the step Verizon’s 43-day median says is already slipping.

Russo’s line in the funding note is that the group mixes researchers, engineers, operators and academics so the research can ship as something a company can run. That is the untested half of the story. Apple credited the research. Customers, contract values and time-to-fix on Atlas are not in the public note.

We have known the majority of the founding team for a long time and we were deeply impressed by Alfredo’s clarity of vision and technical breakthrough. Bynario’s approach of autonomous vulnerability discovery, validation, prioritization, and remediation is what is needed in modern cybersecurity.

Cesare Maifredi, Partner, 360 Capital, in the 10 September 2026 funding note

The Lab Still Has to Turn Research Into a Product

A €2.1 million pre-seed is runway, not a platform. It pays for engineers and for the slower work of putting Atlas in front of the software, cloud and enterprise teams Bynario says it already serves. It does not, by itself, close the 11-day slide in Verizon’s median patch time, and it does not unsay the miner campaign that followed CVE-2026-65400.

The useful record is narrower. In six weeks the same Milan lab went from a post-auth root write-up, to a pre-auth credit on Apple’s three-version emergency patch, to watching other groups turn that patch into a public proof and a Monero drop. On 10 September it raised €2.1 million to sell defenders a way to run that kind of research on their own software, at a cost that still has to beat the attackers’ new floor.

Harry is the editor and lead writer of STUDIO ONE NETWORKS, an independent title he owns and runs himself. Ten years in journalism, reporting first and editing later, taught him that entertainment and business are one beat seen from two sides: a box office figure is a company number, a streaming deal is a contract, a casting rumour is not a story until someone puts their name to it. He works from the record, whether that is a distributor's statement, a licensing agreement, an interview transcript or a set of published ratings, and checks every number against it before publication. The same rule holds for the rest of the site, which covers news, technology, science, sports, lifestyle, travel, auto and gaming for an audience spread across the world. When he gets something wrong, the article is corrected and the change is noted and dated, under a corrections policy anyone can read. Reader mail is answered by him at support@studioonenetworks.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending