Remote graphical access over Screen Sharing used to be invisible to the agent. Huntress now reports each session as it starts, with the source address, session user, and authentication type. You can suppress any of those fields per host. This functionality requires Agent v0.14.196.
That visibility powers a new detection that fires when a session attaches to a root user session via a legacy authentication handshake that current clients no longer use. It's the signature of a pre-auth flaw in Apple's Screen Sharing service, disclosed in July 2026, that allows an unauthenticated remote party to read arbitrary files on an unpatched host. Cloud and VPS Macs lag behind Apple updates, so they carry the most risk.
The existing file-transfer detection stays in place for older agents and macOS below 13.0.