A critical flaw has been discovered in macOS High Sierra that lets an attacker log in as 'root' by leaving the password field blank and trying multiple times in a row. Listen to this and “fix" it right now.
Links:
macOS High Sierra 'root' security bug: Stop and do this NOW