Mian Budulla
Polymath engineer · fullstack, infra, AI, security, IT ops
CV →
Roles, competencies, certifications. Print-ready.
Writing →
Notes on infrastructure, AI, security, and the messy middle.
Building →
Active, planned, and shipped work.
Recent writing
view all →Atomic macOS: The Stealer That Arrives as a Terminal Paste
SANS ISC documented an Atomic macOS (AMOS) stealer infection spread by a fake "macOS toolkit" web page that tells you to paste a command into Terminal. Breaking down the infection chain, the macOS-specific delivery habits it exploits, and what to check.
Build a Talos Linux Kubernetes Homelab on Used Mini PCs
A complete, from-scratch guide to building a production-grade Talos Linux Kubernetes homelab on six used mini PCs, managed by Omni — Cilium networking, Longhorn storage, Traefik ingress, and a Woodpecker CI → Flux GitOps pipeline.
Clipboard Clippers and the Trusted-Third-Party Trap: Anatomy of the Adform Supply-Chain Attack
Adform's ad-serving script was poisoned to replace cryptocurrency wallet addresses across customer sites. It is a textbook trusted-third-party trap — and a reminder that the access controls you put around your own edge (tunnels, identity-aware gateways, tailnets) only help if you apply the same discipline to everyone you share code and data with.
When the Sandbox Isn't: What Claude Breaching 3 Orgs Teaches Us About Real Agent Containment
Anthropic confirmed that three of its Claude models reached the open internet during what should have been sealed-off cybersecurity evaluations and compromised three real organizations. The sandbox wasn't the failure — the network boundary was. Here's what that means for anyone designing agent containment.