Sign in

Steve Puluka

@spuluka.bsky.social
287 followers 159 following 1.3K posts

Network & Security Engineer / Cantor & Religious Education Instructor puluka.com/home

PostsRepliesMedia
Steve Puluka @spuluka.bsky.social · 8h
Apparently ransomware gangs observe the Christmas holiday season as researchers found that attacks fall during the end of year holidays. papers.ssrn.com/sol3/papers....
papers.ssrn.com
Also Hackers go on Holiday: The Ransomware Christmas Effect
Software does not take holidays, but people do. Daily posts of victims on ransomware data leak sites from two independent trackers between 2023 and 2026 fall by
010
Steve Puluka @spuluka.bsky.social · 01/10/2026
Security researchers at Akamai have identified over 30 malicious Google Chrome extensions pretending to be financial tools that will redirect users to phishing sites. www.akamai.com/blog/securit...
akamai.com
110
Steve Puluka @spuluka.bsky.social · 30/09/2026
Interesting deep dive on the mandated Russian messaging service Max from @interseclab.bsky.social This is what state mandated surveillance looks like. interseclab.org/research/max/
interseclab.org
The Max Messenger: An Analysis of Russia’s State-Mandated Messaging Application
VK can change what the Russian Max messenger does to you, one user at a time. Its surveillance features can be switched on without you noticing. Read our full analysis.
012
Steve Puluka @spuluka.bsky.social · 29/09/2026
The @ubuntu-ls.bsky.social team is accelerating the patch cycle from every 4 weeks to every 2 weeks to respond more quickly to the flood of CVE notifications these days. canonical.com//blog/accele...
canonical.com
Accelerating delivery of CVE fixes with a new Kernel release strategy | Canonical
To combat the exponential growth of AI-driven CVEs, Canonical is shifting to a rapid 2-week Linux kernel SRU cycle published weekly. Read about the update.
000
Steve Puluka @spuluka.bsky.social · 28/09/2026
The Australian Prime Minister is very cross with OpenAI for the long delay before notification of their agents hack into their Medicare portal. www.abc.net.au/news/2026-09...
abc.net.au
OpenAI agent hacked Medicare portal, PM says
Anthony Albanese says he has spoken to the Open AI chief executive to express his concern about the incident and the length of time it took the tech company to inform the government of the breach.
100
Steve Puluka @spuluka.bsky.social · 27/09/2026
Interesting deep dive from @elttam.bsky.social on an RCE exploit to TACACS+ protocol servers commonly used in networking authentication. They believe it is already in use against telecomm companies for Chinese espionage. www.elttam.com/blog/att-cki...
elttam.com
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE - elttam
Details a pre-auth format string vulnerability in tac_plus, a popular daemon implementing TACACS+ for network device management, and the shared secret oracle that makes it a practical RCE chain.
000
Steve Puluka @spuluka.bsky.social · 26/09/2026
Interesting report on how security researchers got a bug bounty from OpenAI finding a flaw gaining access to employee accounts using the Anthropic AI as one of the tools in the hack. www.hacktron.ai/blog/hacking...
hacktron.ai
Hacking OpenAI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
020
Steve Puluka @spuluka.bsky.social · 25/09/2026
Interesting overview from the @rubygems.bsky.social team on how the discovered the OpenAI hack into their package repository in attempts to steal API keys. rubyhack.ai
rubyhack.ai
OpenAI agents carried out an undisclosed cyber-attack on RubyGems
On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents performing web-lookup tasks with significant overlap with the German Wiki Incident.
010
Steve Puluka @spuluka.bsky.social · 24/09/2026
Looks like the #AI reward system is continues to operate without ethics as now OpenAI adds to the list of crimes a person would be charged with performed by their agents. At least they are open in disclosure. openai.com/index/model-...
openai.com
Our framework for reporting model misalignment
OpenAI shares a framework for tracking, investigating, and disclosing model misalignment, alongside six reports of unexpected or concerning model behavior.
001
Steve Puluka @spuluka.bsky.social · 23/09/2026
Looks like the #AI reward system is consistently without ethics as now Google adds to the list of agents that hack into other companies for the built in reward system. www.bbc.com/news/article...
bbc.com
Google's Gemini AI hacked three companies in security test
The AI model accessed the internet and guessed credentials to three websites, a Google official told the BBC.
000
Steve Puluka @spuluka.bsky.social · 22/09/2026
Good news that Ukrainian authorities have taken down scam centers and seized more than $2M in assets and 3k computers in the operation. cyberpolice.gov.ua/news/naczpol...
cyberpolice.gov.ua
Нацполіція провела понад 400 обшуків і припинила роботу 94 шахрайських call-центрів — Департамент Кіберполіції
Департамент Кіберполіції Національної поліції України
000
Steve Puluka @spuluka.bsky.social · 21/09/2026
Good news that Brazilian and German authorities took down a group that stole more than €30 million from German online banking customers. www.gov.br/pf/pt-br/ass...
gov.br
PF deflagra operação contra fraudes bancárias eletrônicas e lavagem de dinheiro
Ação cumpre ordens judiciais em Goiás, em São Paulo e no Rio de Janeiro
000
Steve Puluka @spuluka.bsky.social · 20/09/2026
Interesting report from @netskope.bsky.social on how they found over 5k websites hacked and used to host ClickFix-style malware campaigns. www.netskope.com/blog/malware...
netskope.com
Malware on the Blockchain: An Ongoing Campaign's New WebRTC Twist
EtherHiding, a technique that uses blockchain smart contracts as takedown-resistant payload storage, has been seen across more than 5,400 compromised
011
Steve Puluka @spuluka.bsky.social · 19/09/2026
The Five Eyes Cybersecurity agencies have all jointly issued guidelines for companies on how to report breaches telling them to stop the PR mess and just outline the facts and timelines. www.cyber.gc.ca/en/news-even...
cyber.gc.ca
Joint guidance on best practices for service providers when communicating under pressure - Canadian Centre for Cyber Security
This joint guidance explains why effective communications during outages is critical to minimize operational impacts, maintain credibility and situational awareness, and support response efforts.
000
Steve Puluka @spuluka.bsky.social · 18/09/2026
The C# programing language will get improved memory security in @threatintel.microsoft.com version 15 now in preview. devblogs.microsoft.com/dotnet/explo...
devblogs.microsoft.com
Explore new features available in C# 15 preview - .NET Blog
C# 15 ships with .NET 11. It adds union types, closed hierarchies, a preview of the updated unsafe model, and a few smaller changes that remove everyday ceremony.
000
Steve Puluka @spuluka.bsky.social · 17/09/2026
We live in interesting times as @microsoft.com notes this patch Tuesday fixed 974 vulnerabilities. The scope of these new methods of finding CVE is staggering. msrc.microsoft.com/update-guide...
msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
000
Steve Puluka @spuluka.bsky.social · 16/09/2026
Interesting deep dive from Elastic on the info stealer RevStealer that is spreading via GitHub repos and YouTube videos on game cheats. www.elastic.co/security-lab...
elastic.co
Credential harvesting that survives takedowns: REVSTEALER
REVSTEALER hides backup C2 addresses in Polygon smart contracts. Inside its sandbox scoring, credential-harvesting scope, and four undocumented modules.
000
Steve Puluka @spuluka.bsky.social · 15/09/2026
Good news that @europol.europa.eu working with the US Department of Justice successfully disrupted the Sality botnet www.europol.europa.eu/media-press/...
europol.europa.eu
Global public-private operation disrupts Sality botnet active for two decades – Peer-to-peer botnet linked to more than 11 million infected IP addresses worldwide taken down | Europol
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to distribute malicious payloads to thousands of infecte...
000
Steve Puluka @spuluka.bsky.social · 14/09/2026
Yet another large compromise of Driver License documents stored by online checking services. We really need to stop saving these copies. Just validate the age requirement and dump the images. krebsonsecurity.com/2026/09/fbi-...
krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security
000
Steve Puluka @spuluka.bsky.social · 13/09/2026
Good news that China has formed the Inter­national Alliance Combating Telecom and Cyber Fraud will also include 34 observer countries and four international organizations focused on fighting scam compounds. www.chinadaily.com.cn/a/202609/10/...
chinadaily.com.cn
Intl alliance forged to fight telecom fraud
011
Steve Puluka @spuluka.bsky.social · 12/09/2026
An interesting overview from @anthropic.com on what they have learned from the four separate incidents of their #AI agents hacking other companies this year. www.anthropic.com/research/ali...
anthropic.com
An alignment assessment of recent cybersecurity incidents
We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems.
000
Steve Puluka @spuluka.bsky.social · 11/09/2026
According to Palo Alto Networks only a dozen of over 400 #AI created exploits are showing up in their analysis of real world infections, so the #AI breach era is off to a slow start. unit42.paloaltonetworks.com/ai-enabled-m...
unit42.paloaltonetworks.com
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
000
Steve Puluka @spuluka.bsky.social · 10/09/2026
That time again to review the ten new CVE from Palo Alto Networks and get patching the affected gear. security.paloaltonetworks.com
security.paloaltonetworks.com
Palo Alto Networks Security Advisories
Palo Alto Networks Security Advisories - Latest information and remediations available for vulnerabilities concerning Palo Alto Networks products and services.
000
Steve Puluka @spuluka.bsky.social · 09/09/2026
Interesting investigation by Norwegian Norsk rikskringkasting (NRK) on a Nigerian group is behind more than 300 fake investment portals. www.nrk.no/dokumentar/x...
nrk.no
The Scam Hunt
This is the story of a sophisticated fraud network that has deceived people around the world. And the hunt for the ones who make it possible.
000
Steve Puluka @spuluka.bsky.social · 08/09/2026
The next phase of #AI is here according to Pew Research almost a third of new content published on the internet since the release of ChatGPT in 2023 is now AI generated. www.pewresearch.org/data-labs/20...
pewresearch.org
How Much of the Internet Is Written With AI?
In a random sample of 10,000 webpages collected in July 2026, one-in-ten show signs of being written or substantially edited by AI.
000
Steve Puluka @spuluka.bsky.social · 07/09/2026
Interesting break down of how the Chinese Botnet system operated by Lumen. www.lumen.com/blog/en-us/t...
lumen.com
Inside China-nexus cyber espionage infrastructure
Black Lotus Labs and the FBI uncovered China-nexus infrastructure used to hide cyber espionage, showing how early detection helps protect customers.
000
Steve Puluka @spuluka.bsky.social · 06/09/2026
Interesting report from ZeroBEC on how the BlueKit platform attack flow works. zerobec.com/blog/bluekit...
zerobec.com
BlueKit PhaaS: BitM, Geofencing, ScreenConnect | ZeroBEC
An active BlueKit BitM phishing campaign targeting financial-sector CEOs: branded PDF lures, geofencing, M365 session hijack, and ScreenConnect delivery.
000
Steve Puluka @spuluka.bsky.social · 05/09/2026
Good news that @interpol.int has helped bring down the Sality peer-to-peer botnet. They have seized servers, domains, and are now sinkholing traffic from infected devices. www.europol.europa.eu/media-press/...
europol.europa.eu
Global public-private operation disrupts Sality botnet active for two decades – Peer-to-peer botnet linked to more than 11 million infected IP addresses worldwide taken down | Europol
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to distribute malicious payloads to thousands of infecte...
000
Steve Puluka @spuluka.bsky.social · 04/09/2026
BGP route hijack report from the Virtualizor network successfully bypassed RPKI with valid but false certificates. www.virtualizor.com/blog/securit...
virtualizor.com
Security Incident – BGP Hijacking – Virtualizor
000
Steve Puluka @spuluka.bsky.social · 03/09/2026
Interesting new open source project from the Cyber Security and Privacy Foundation called Red Clippy is a PenTest management platform operating as an #AI agent. github.com/CSPF-Founder...
github.com
GitHub - CSPF-Founder/red-clippy: open-source pentest management built to be operated by an AI agent
open-source pentest management built to be operated by an AI agent - CSPF-Founder/red-clippy
010
Steve Puluka @spuluka.bsky.social · 02/09/2026
Interesting experiment from Trail of Bits on how #AI agents are able to escape VMs in a sandbox across multiple frameworks. blog.trailofbits.com/2026/08/26/v...
blog.trailofbits.com
VMs won't contain cyber-capable agents
You can no longer assume a mere VM will contain a sufficiently advanced AI agent.
010
Steve Puluka @spuluka.bsky.social · 01/09/2026
Interesting report on the status of the EU readiness for Post Quantum Cryptography. www.sitg-consulting.com/post/europe-...
sitg-consulting.com
Europe’s Post-Quantum Readiness 2026: New EU-27 Assessment Reveals Major Differences in PQC Preparedness
SITG-Consulting has published Europe’s Post-Quantum Readiness 2026: An Empirical Assessment of the EU-27, an independent assessment of the publicly verifiable state of post-quantum cryptography readin...
000
Steve Puluka @spuluka.bsky.social · 31/08/2026
Interesting report from @openaibot.bsky.social on the details of how their model hacked into HuggingFace. Notably the malicious behavior started two months before the intrusion hack. openai.com/index/huggin...
openai.com
The Hugging Face incident and the road ahead
OpenAI shares findings from the Hugging Face security incident and the steps we’re taking to strengthen AI model security, monitoring, and alignment.
000
Steve Puluka @spuluka.bsky.social · 30/08/2026
Good news that Australian Federal Police have arrested two suspects accused of leading the TeamPCP hacking group responsible for malicious software supply chain attacks via open source software. www.afp.gov.au/news-centre/...
afp.gov.au
Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate | Australian Federal Police
Two West Australian men have been charged following a joint investigation between the AFP and Western Australia Police Force (WAPF), working in parallel with the Federal Bureau of Investigation (FBI),...
001
Steve Puluka @spuluka.bsky.social · 29/08/2026
Good news that @interpol.int with the cooperation of 22 countries have made 58 arrests and identified hundreds of suspects in west African scam centers. www.interpol.int/News-and-Eve...
interpol.int
58 arrests in global effort to dismantle West African organized crime groups
INTERPOL-coordinated operation leads to the identification of 263 suspects
010
Steve Puluka @spuluka.bsky.social · 28/08/2026
Good news that @microsoft.com is moving to have per app permissions for access to location, camera and microphone on windows systems. learn.microsoft.com/en-us/window...
learn.microsoft.com
Windows 11 Insider Experimental Preview Build 26340.9233 - Windows Insider Program
Release notes for Windows 11 Insider Experimental Preview Build 26340.9233
000
Steve Puluka @spuluka.bsky.social · 27/08/2026
Interesting report from @kasperskylab.bsky.social that a malware version able to infect an afternarket Android smart car interface and add them to a botnet. securelist.com/android-head...
securelist.com
First Android malware targeting automotive head units
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
000
Steve Puluka @spuluka.bsky.social · 26/08/2026
Interesting report from Trend Micro researchers finding 14 malicious NPM packages delivered to Linux systems via a hacking tool sold on forums. www.trendaisecurity.com/en-us/resour...
trendaisecurity.com
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant | TrendAI (US)
TrendAI™ Research provides a comprehensive analysis of the RedC2 Linux Implant, a sophisticated threat recently discovered in the npm open-source ecosystem.
000
Steve Puluka @spuluka.bsky.social · 25/08/2026
Great overview from @cloudflare.social of the BGP route leak prevention protocol features in RFC 9234. How they are intended to work and the current adoption of the protocols. blog.cloudflare.com/rfc9234-bgp-...
blog.cloudflare.com
BGP Role model: tracking the adoption of RFC 9234
RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.
000
Steve Puluka @spuluka.bsky.social · 24/08/2026
Interesting deep dive from @securitylabs.datadoghq.com on a Linux malware strain being used to target MCP and other internet connected servers. securitylabs.datadoghq.com/articles/n4d...
securitylabs.datadoghq.com
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it | Datadog Security Labs
Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime...
000
Steve Puluka @spuluka.bsky.social · 23/08/2026
With thanks to customers for their feedback on the issue, @microsoft.com has created new procedures on how to recover from a mass disruption on Windows based systems.. techcommunity.microsoft.com/blog/windows...
techcommunity.microsoft.com
Windows device recovery in 2026: a guide for IT pros - Windows IT Pro Blog
From automated fixes to full rebuilds, explore the newest recovery tools that keep IT in control while helping address a broad range of scenarios:
000
Steve Puluka @spuluka.bsky.social · 22/08/2026
This overview blog from @nist.bsky.social organizes all the advice and processes for protecting Operational Technology systems in building, manufacturing and corporate networks. www.nist.gov/blogs/cybers...
nist.gov
NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity
020
Steve Puluka @spuluka.bsky.social · 21/08/2026
Open fro comment the US NIST is looking to update advice and processes for people in cyber security. www.nist.gov/blogs/cybers...
nist.gov
Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity
000
Steve Puluka @spuluka.bsky.social · 20/08/2026
Good news that Ukrainian authorities have taken down 94 scam call centers seized assets and identified 26 leaders of the operation for prosecution. cyberpolice.gov.ua/news/naczpol...
cyberpolice.gov.ua
Нацполіція провела понад 400 обшуків і припинила роботу 94 шахрайських call-центрів — Департамент Кіберполіції
Департамент Кіберполіції Національної поліції України
000
Steve Puluka @spuluka.bsky.social · 19/08/2026
Good news that Montenegrin police have arrested 50 suspects running a scam center near the capital. balkaninsight.com/2026/08/11/m...
balkaninsight.com
Montenegro Police Raid Nets 50 Foreigners, ‘Hundreds’ of Digital Devices, and Cash
Police seize "sophisticated equipment" and cash from more than 50 foreign nationals found in a house near Podgorica, checking possible links to high-tech crime.
000
Steve Puluka @spuluka.bsky.social · 18/08/2026
Good news that Portuguese authorities have arrested the creator the the #AI hacking tool WormGPT sold on dark web forums. jorgebranco.substack.com/p/portuguese...
jorgebranco.substack.com
Portuguese hacker to face trial for malicious ChatGPT clone // Immigrant deported thanks to two-year wait for AIMA // Tourism doing less for economy as boom slows
Portuguese news in English on Tuesday, August 11, 2026.
021
Steve Puluka @spuluka.bsky.social · 17/08/2026
Open for comments the US NIST is asking opinions on how to us #AI tools in managing the CVE process. cyberscoop.com/nist-nationa...
cyberscoop.com
NIST wants to overhaul its vulnerability database for the AI age
NIST is requesting public feedback to overhaul the National Vulnerability Database, aiming to integrate AI and automation to counter faster, machine-driven threats.
011
Steve Puluka @spuluka.bsky.social · 16/08/2026
Good news that the EU has started enforcing the need for watermarks on #AI generated content with @anthropic.com noting their compliance. support.claude.com/en/articles/...
support.claude.com
How Claude marks AI-generated content | Claude Help Center
000
Steve Puluka @spuluka.bsky.social · 15/08/2026
The FBI is investigating how a DPRK agent was able to pass all the background checks and get employment as a remote US Federal employee. federalnewsnetwork.com/technology-m...
federalnewsnetwork.com
FBI investigating North Korean remote IT staffer working for US agency | Federal News Network
Experts say the incident highlights potential gaps in government and industry vetting processes, especially for jobs like IT support work.
010
Steve Puluka @spuluka.bsky.social · 14/08/2026
Another instance of #AI agent going on a hacking spree. The OpenClaw agent was asked by a user to get them into gym class so it hacked the API on the waiting list and bumped them up to the top. www.abc.net.au/news/2026-08...?
abc.net.au
How a simple request for AI to book a gym class exposed a major threat
When Andrew asked his AI personal assistant to book him a spot in a gym class, he had no idea he would accidentally initiate an autonomous cyber attack.
000