Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks.
Impinj co-founder and CEO Chris Diorio, center, and members of the Impinj team at the Nasdaq opening bell ceremony in New York City on Tuesday, marking the 10th anniversary of the company’s IPO. (Nasdaq Photo)
Backstage at a Seattle tech event in the early 2000s, Chris Diorio was waiting his turn to speak. Next to him was Jeff Bezos, whose company was already becoming a household name.
Diorio, the leader of Impinj, then a tiny local startup, turned to the Amazon founder: “Jeff, you’ve got a much bigger near-term opportunity than we do,” Diorio recalls saying, “but we’ve got a much bigger long-term opportunity than you do.”
Before Bezos could respond, he was called onstage.
“The technology turned out to be way harder than I thought,” Diorio acknowledged after telling that story in a recent interview. “But that’s what I told him — and I still believe in those words. Our opportunity is to deliver physical intelligence for every item in the world.”
A quarter-century after that chance encounter, Diorio rang the Nasdaq opening bell Tuesday morning in New York City to mark the 10th anniversary of Impinj’s IPO. The company’s tiny, battery-free RFID chips — each smaller than a grain of sand — have been embedded in more than 160 billion items, including clothing, pharmaceuticals, airline luggage, and groceries.
An illustration of the Impinj E710 reader chip inside a handheld RFID scanner used for retail inventory. (Impinj Photo)
Impinj commands nearly two-thirds of its market, won a patent war against a rival 15 times its size, and has grown from a $250 million IPO valuation to a market cap of more than $4.2 billion. Along the way, the company survived a billion-dollar industry hype cycle that killed nearly every competitor.
And yet, Impinj has posted exactly one profitable year since going public — thanks to a $45 million legal settlement at the time. Its accumulated deficit stands at $400 million, its financial reports show. Less than 1% of the items it envisions connecting are connected today.
To Diorio, that speaks to the potential. The company is barely scratching the surface. He cited the 1% stat in his comments before ringing the Nasdaq bell on Tuesday morning, saying the “opportunity is so gigantic that we’ll still have a huge runway ahead of us 10 years from now.”
That the company has gotten to this point is as much a Seattle story as it is a technology story. Impinj has benefitted from a network of patient local investors, academic connections and supporters who gave the company the time that Silicon Valley never would have.
But no one imagined it would take this long when they got started.
From Caltech to Seattle
The origins of Impinj were at Caltech in Pasadena, Calif., in the 1990s. Diorio was a graduate student working under Carver Mead, the physicist and engineer who helped coin the term Moore’s Law and helped lay the intellectual foundation for the modern semiconductor industry.
Carver Mead, the Caltech physicist and engineer who co-founded Impinj with Diorio. (Photo by Norman Seeff, CC BY-SA 4.0)
Together, they discovered a way to change a transistor’s electrical properties after it had been manufactured — a quantum-mechanical phenomenon called “impact-ionized hot electron injection.” That made it possible to build chips so efficient and inexpensive that they could be embedded in disposable packaging. (“Impinj” is derived from that scientific name.)
In an oral history later recorded by the Science History Institute, Mead described Diorio as “a super-bright, super-high-energy guy” who “burned up the track” at Caltech.
After finishing his PhD, Diorio was recommended by Mead to the University of Washington’s computer science department. There was resistance among the UW faculty — his research in analog circuits wasn’t an obvious fit — but professor Larry Ruzzo carried the day.
Ruzzo essentially said, “This guy is brilliant, and even if he is nothing other than our gift to the rest of the university, we should hire him,” recalled Ed Lazowska, the department chair at the time.
Diorio joined the UW faculty in 1997. Over the next few years, his research earned a string of honors, including Packard and Sloan fellowships. A couple years later, Diorio met up with Mead on a trip to California, over dinner at Fresh Cream, a long-since-closed French restaurant in Monterey. Diorio asked Mead if it was time to start a company.
“Are you up for it?” Mead asked. Diorio said yes. They started the paperwork the next day.
Impinj was incorporated in April 2000, headquartered in Seattle. It quickly got the attention of two local investment firms, with behind-the-scenes help from the everpresent Lazowska.
On April 21, 2000, the UW computer science chair emailed Bob Nelsen at Arch Venture Partners and Tom Alberg at Madrona. He explained that he was urging Diorio and Mead “to get some local $ for the connections,” and that he had pointed them to Arch and Madrona.
Impinj co-founder and CEO Chris Diorio discusses Gen2X, the company’s latest advancement in RFID chip technology. (Impinj Photo)
Patrick Ennis, then at Arch, reached out to Diorio that same day. As Ennis recalled in a recent interview, there were plenty of Silicon Valley firms that wanted in, thanks to Mead’s reputation, but Diorio and Mead decided to take Lazowska’s advice and go with Seattle investors.
Diorio, who likes to take walking meetings, negotiated the terms with Ennis as they made their way on foot through the University of Washington Arboretum one day. The investment closed that summer: $15 million, split evenly between Arch and Madrona.
Impinj at the time had patents, prototypes, and no real business plan.
“That’s how venture capital should be done,” said Ennis, who has since become a Madrona venture partner. “You make big bets on great technology and great people.”
Betting the company on RFID
Bill Colleran joined Impinj as CEO in January 2001. He and Diorio had designed satellite chips together at defense contractor TRW in the 1980s. Colleran had just sold his Bluetooth startup, gotten married, and gone on his honeymoon. He came home to a message from Diorio: he’d started a company in Seattle and wanted Colleran to join.
Bill Colleran, Impinj’s first CEO, was recently tapped to lead AI coding startup Adronite.
Colleran was soon in Seattle — one of six or eight people working out of what he warmly recalls as “a crappy little building” in the University District, several of them former TRW colleagues.
“We were kind of getting the band back together,” he said.
RFID wasn’t the original plan. Impinj’s first target was improving power efficiency for 3G wireless base stations, but the dot-com bust killed that market, and regardless, the company was too small to compete with the major chipmakers in the wireless industry.
The team spent two years exploring what to do with their technology. Cable modems required too much dependence on Intel, as Colleran recalled. Cell phone radios were dominated by players too big to compete against. GPS turned out to be a poor technical fit — Impinj’s chips excelled at low power, but GPS demanded low electrical noise, a different problem entirely.
So they eventually settled on RFID, the technology that uses tiny wireless chips to identify and track physical objects. The industry was young, the standards were still being written, and Impinj’s low-power technology seemed tailor-made for it.
As Madrona’s Ennis and Tim Porter write in a piece pegged to the IPO anniversary, “When you have a truly powerful, groundbreaking deep technology, it behooves you to wander the product-market fit wilderness for a while, even when that is unsettling and downright frightening, and even when it runs contrary to what you learn in a VC class in business school.”
Then, a stroke of luck: In June 2003, Walmart announced it would require its top suppliers to tag every pallet and case with RFID chips. The Impinj team celebrated their good fortune.
“We all high-fived,” Diorio recalled. “We did it. Eighteen months, we’re gonna IPO.”
In reality, it would be another 13 years.
Surviving the RFID hype cycle
Walmart’s announcement triggered a gold rush of venture capital investment into RFID technology startups. But there was no global spectrum allocated, no standard that worked, and no products ready to deliver on the promise. Walmart’s own January 2005 deadline came and went. Only half of its top suppliers could comply.
By 2008, the hype cycle had collapsed. Nearly every RFID startup died or got acquired.
“More than $1 billion of VC money got poured into RFID,” Diorio recalled. “Way up, crashing down, and only one company that made it out the other side. … We were lucky enough that it was us.”
The real inflection didn’t come until around 2010, when retailers began tagging individual items, not just pallets. Knowing exactly which products were where, in real time, could lift same-store sales by as much as 10%, by solving a basic problem: getting items out of back rooms and onto shelves, making them available for purchase before customers gave up looking for them.
“I didn’t know if I wanted to be a lifelong RFID guy,” he said.
An exit wasn’t in sight — the IPO window was shut, and a sale didn’t make sense because Impinj made both chips and readers, and “any of the companies that would be interested in boxes weren’t chip companies, and the chip companies weren’t interested in boxes.”
Diorio took over as CEO that November. The venture investors were 14 years in and needed a path to liquidity. He spent the next two years sorting things out and getting the company ready.
The long road to IPO
Porter, now a Madrona managing director, who had worked closely with Alberg on the Impinj investment since 2007, recalled the final stretch. One of the first target dates for trading landed on the day Britain voted to leave the European Union, sending markets into a tailspin.
“It was a little bit like, are you kidding — what next?” Porter said.
But on July 21, 2016 — some 16 years after its founding — Impinj went public on the Nasdaq at $14 a share, raising $67 million at a market cap of just over $250 million.
The late investor Tom Alberg, one of Amazon’s first investors and an early backer of Impinj, looks on as Amazon CEO Jeff Bezos speaks at a Madrona event in 2015. (Madrona Photo)
Porter called Alberg’s move “a really big signal” to the market that demonstrated his long-term belief in Impinj. It was also a smart investment, as it turned out. As noted during the Nasdaq bell-ringing Tuesday morning, Impinj’s share price has grown by nearly 900% since the IPO.
But there was one last hitch. On the night before trading began, the offering was so oversubscribed that the final allocation became a drawn-out negotiation between the board and the bankers over how many shares to issue. It dragged on so long that Diorio and CFO Evan Fein, stuck in Chicago for the roadshow, missed their flight to New York.
Fein had been one of the first people hired at Impinj, joining Colleran in the University District office in 2001 and staying through the whole ride. He was not about to miss the bell-ringing.
The CFO wanted to make a run for it, but Diorio told him there was no way — the flight departed in 30 minutes from O’Hare. Fein tried anyway. He didn’t make it. They stayed in Chicago overnight and caught a flight the next morning.
The company’s CTO at the time rang the bell in Diorio’s place.
Trial by fire
The celebration was short-lived. After the IPO, demand for RFID surged — but Impinj, thinly capitalized after years of private fundraising, didn’t have the operational capacity to fill the orders. The stock quadrupled from its $14 IPO price to more than $60. Then it all came apart.
NXP Semiconductors, a Dutch chipmaker roughly 15 times Impinj’s size, moved aggressively on pricing and took business away. Customers who had been stockpiling RFID tags pulled back on orders. Revenue declined. On Feb. 2, 2018, the stock plunged 47% in a single day.
What followed was the darkest stretch in the company’s history. The company laid off 9% of its workforce. Then a former employee complaint triggered an audit committee investigation, forcing the company to miss an SEC filing deadline and drawing a deficiency notice from Nasdaq.
For months, the outcome was uncertain. Executives couldn’t trade their stock or issue grants to employees. The investigation cost $1.4 million. NXP, sensing an opportunity, continued to press its advantage.
Diorio described the investigation as mentally draining. The company was spending millions of dollars, the outside attorneys weren’t sharing their findings along the way, following the standard practice, and there was no way to know for certain how it would end.
“You firmly believe you haven’t done anything wrong,” he said, “but who knows if somebody actually did something wrong that you don’t know about.”
The investigation ultimately cleared the company, finding “no credible evidence” of wrongdoing, and Impinj received what Diorio called a rare letter from the SEC formally closing the matter. The stock surged 35% on the news.
Diorio called 2018 a turning point. “It was the year where everything got really difficult, the team and the company rallied, and it was the strength and the persistence of the team and their dedication that pulled us out the other side,” he said. “I’ll never forget that.”
The following year, Impinj went on offense. In June 2019, the company sued NXP, alleging it had copied 26 of Impinj’s patents. NXP countersued. The litigation stretched across five years and four lawsuits. In 2023, a federal jury found NXP had willfully infringed Impinj’s patents and awarded $18.5 million in damages. NXP settled in 2024, paying $45 million upfront and agreeing to ongoing royalties of roughly $17 million a year.
Where Impinj stands today
Diorio helped coin an industry term for the technology Impinj had built: RAIN RFID, short for “RAdio-frequency IdentificatioN.” It distinguished what Impinj does (using battery-free chips to identify and track individual items at scale) from other flavors of RFID used for key cards, animal tags, and contactless payments.
Today the company employs more than 450 people, most of them based in its headquarters at 400 Fairview Ave. N. in Seattle, with a test and development lab on Beacon Hill. The workforce is a fraction of NXP’s, which has more than 32,000 employees — a reminder that Impinj has built a market-leading position with a comparatively small team.
Inside the Impinj offices in Seattle in 2018. (File Photo)
Impinj holds an estimated 64% of the global market for RAIN RFID endpoint chips, up from 51% the year before, according to ABI Research. The company first overtook rival NXP for the market lead in 2024. The industry shipped nearly 53 billion chips in 2024, roughly one for every six or seven people on Earth. Impinj has connected more than 160 billion items cumulatively.
Each chip is battery-free, costs a few pennies, can be read wirelessly from 30 feet away, and identifies individual items at a rate of up to 1,000 per second. Vision systems can’t identify individual items. QR codes require line of sight. NFC has a range of four inches. Bluetooth requires a battery.
“Name any other technology that even gets close,” Diorio said. “You won’t come up with one.”
Privacy concerns nearly killed the RFID industry in its early years, when consumer groups campaigned against the technology in the mid-2000s. Although there’s privacy innovation still to come, Diorio said those fears have largely faded. The chips carry only a number, respond only when powered by an external reader, and don’t track people.
One retailer already turns its tags invisible after the point of sale, though Diorio noted that’s “not the best solution because then that inhibits recycling.”
His longer-term goal is cryptographic security, chips that can’t be cloned, putting “a dent in global counterfeiting” while keeping consumer data protected.
Meanwhile, the competitive landscape is shifting. Diorio views NXP as the only real competitor — “everybody else in the market is a partner,” he said — but the competitor list in Impinj’s SEC filings has grown from two names at the time of the IPO to more than six, including four Chinese chipmakers. When a product costs pennies, low-cost competitors have a natural opening.
Retail apparel remains the core market. About 60% of all RAIN RFID tags go on clothing. But that reliance has made the business volatile. Three times in 10 years as a public company, demand from retailers has dropped sharply, dragging revenue and the stock with it.
Earlier this year, Impinj’s stock plunged after the company issued guidance well below expectations. Part of the challenge: the company’s top three customers account for 61% of revenue.
The financial picture reflects a company that is still proving itself. Revenue has grown from $123 million in 2018 to $361 million last year, but Impinj has posted just one profitable year since going public — a $41 million gain in 2024, boosted by the NXP settlement.
To Diorio, all of this is prelude. Apparel, he said, is “tiny” compared to the total market of every item manufactured, transported, and sold. General merchandise, supply chain logistics, pharmaceuticals, food — each is an order of magnitude larger, or more.
“We have a gigantic blue ocean,” he said. “It’s the size of the Pacific.”
Machine learning and AI
The company is also using machine learning to move beyond handheld inventory scanning. Fixed readers mounted in ceiling tiles and other locations can track items autonomously at store choke points, from receiving docks to fitting rooms to exits, replacing employees who currently walk the aisles waving handheld scanners.
More broadly, Diorio sees tagged items as a data source for AI, generating hard information at every point in a product’s journey from factory to shelf to recycling bin.
“Most of the modeling that goes on today is based on guessing,” he said. “If the models are based on hard data, it’s immensely more valuable.”
Impinj’s M800 series RAIN RFID chip, smaller than a grain of sand, is designed to be embedded in labels on individual items — including fresh groceries, one of the company’s biggest growth opportunities. (Impinj Photo)
The biggest bet ahead is food. Three of the top five U.S. grocers (Kroger, Walmart, and Albertsons/Safeway) are piloting RFID for food freshness, according to Diorio, using tags to identify items approaching their expiration dates so they can be marked down before they end up in the trash.
A European grocer is pushing toward fully automated checkout, where a basket of tagged items moves down a conveyor and is read instantly, no scanning required.
These are pilots, not deployments. The grocery market dwarfs apparel in volume, and Impinj has yet to prove it can crack it at scale. But here again, Diorio sees this as untapped potential.
“My enthusiasm is as high as it’s ever been,” he said. “We are just getting going.”
And this time, he made it to New York to ring the opening bell.
During his Nasdaq remarks on Tuesday morning, Diorio told the story of getting stuck in Chicago for the IPO a decade ago, using the anecdote to make a larger point.
“The team stepped in,” he said. “The team that was here covered everything, rang the bell, did all the process, and did it beautifully. In fact, probably better than we could have. And that is the story of Impinj. It’s the team.”
Editor’s note: This story was updated July 23, 2026, to reflect ABI Research’s 2025 market share estimate of 64% for Impinj, up from 51% in 2024 as originally reported. The spelling of former CFO Evan Fein’s name was also corrected.
Following the reports last week using the Windows Global Device ID (GDID) in tracking a malware operators behavior, here is a comprehensive write-up about what goes into the GDID and how it is used. It’s worth noting that the GDID itself was not used to catch the malware operator, however once a suspect was identified, the GDID was used to correlate behavior across various Microsoft products on the Internet.
The GDID is generated and assigned during a Windows install, but a re-install of Windows will generate a new GDID. Developer [SmtimesIWndr] tracks the generation and tracking of the GDID through the various Windows libraries and services, identifying where it appears to be created and how it is passed to other services like Azure.
Worth noting is your GDID is a unique, personally identifiable piece of information; if you go exploring and extract it from your Windows install, be sure to keep it private!
LAME mp3 updates
Those of us who were around for the dawn of MP3 files may remember the LAME encoder and library. After almost 10 years, there is a new LAME release.
Notably, this includes two security fixes, one for a stack buffer overflow based on malicious input to the Blade encoder, and an integer underflow in the AIFF header parser. Both of the fixed bugs feel very old-school, which seems appropriate given the age of the library and most of the related code.
Buffer overflows impacting the stack are some of the simplest and most direct forms of vulnerabilities, where it is possible to write past the end of a buffer and control how the function returns and instead execute arbitrary code. Integer under-flows, similarly, impact memory management; usually caused by allowing a variable that stores the size of a buffer to go negative. Since sizes are typically unsigned positive numbers, a negative is interpreted as an enormous positive number, writing past the proper buffer length.
Despite the new findings, the LAME codebase has been extremely resilient over the years, and considering the number of programs that likely still use LAME under the covers to process audio, seeing the project wake up with security fixes is great news.
Recovering Passwords from BIOS
Researchers have found a vulnerability in Dell BIOS code that allows extraction of the administrator password from the BIOS flash chips, either with physical access via a flash programmer, or via administrator or root level access to the operating system and reading the contents of the flash chip.
Dell used a 20 byte key to encrypt a 32 byte password field: for any admin password of 12 characters or fewer, the password is stored in completely plaintext. For longer passwords, characters beyond the first 12 are encrypted – but the random bytes are computed from the first character of the password mixed with fixed device data, yielding only 256 possible encryption seeds for the remaining bytes.
Using the BIOS admin password for evil requires local access, so the attack surface is small, however as the researchers note it controls the boot order and may allow an attacker with physical access to then boot an unsigned OS or bypass full-disk encryption, so it’s serious.
Patch Tuesday Crushes Records
Last month, Microsoft broke records for the number of security fixes in the June monthly Patch Tuesday roundup. This month, Microsoft broke records for the number of security fixes in the July monthly Patch Tuesday roundup.
This month includes a record 60 plus patches for critical vulnerabilities in Windows, as well as fixes for previous Bitlocker bypasses, and an AI prompt injection which could allow web sites to trigger Copilot in Microsoft Edge on Android and execute arbitrary prompts. Another bug patched this month allowed privilege escalation and code execution over DHCP, potentially impacting all Windows installs on the same physical network or public hotspot.
Microsoft credits AI assisted tooling with the record-breaking number of bugs discovered, and indicates it’s unlikely to slow down next month.
LegacyHive Windows Vulnerability
It’s a week with a Patch Tuesday, which now seems to mean it’s a week with a new exploit from NightmadeEclipse, the researcher who previously made news for being quite upset with the responses from the Microsoft security group. After then creating a public outcry by threatening prosecution, Microsoft recently has seemed simply to be fixing bugs disclosed by NightmareEclipse in the next series of security updates.
This month, we have LegacyHive, an exploit which allows loading the “hive”, or collection of registry settings and configuration files, of another user. The Windows registry is typically used to store preferences, settings, auto-launched applications, and other important settings, so being able to access other users registry groups seems significant.
Fairlife Dairy Suspends Production
Fairlife Dairy, owned by Coca-Cola, has suspended US operations due to a ransomware attack. Filings with the SEC simply say that production facilities are impacted and will be temporarily suspended, with no estimate as to when they will be restored.
Typically when a food-processing facility goes offline, the delays for restoring service can be significant due to the sanitization requirements.
CPAN and Perl April Task Force
The April Task Force has been announced (yes, in July) with a focus on enhancing the security posture of Perl and the CPAN library.
Given the absolute havoc wreaked on the NPM and PyPi repositories in 2026, proactive measures to protect other repositories seem prudent. Funded by the Perl and Raku Foundation and the Linux Foundation, the April Task Force will be focused on supply chain security, vulnerability patching, and processing reported vulnerabilities and CVEs.
Perl may not be the juggernaut language it once was, but it’s still used widely, so any preventative measures are good news.
Secure Boot vulnerable
Researchers from ESET enumerated 11 boot loaders signed by Microsoft that can be used to bypass secure boot protections and execute arbitrary code.
Secure Boot was designed to only boot code signed by trusted organizations (in this case, Microsoft). Those of us running Linux typically know it as “the option in the BIOS to turn off to get a kernel to run properly”, but for corporate fleets, Secure Boot protections help protect disk encryption and prevent malware installs.
During boot, a Secure Boot protected system validates the code it is about to launch to ensure it is signed by a trusted organization, establishing a chain of trust where each component then validates the next before launching. Often, to enable other tools or Linux distributions to boot, a “shim” boot loader is created and signed by an organization trusted by the UEFI install, which then loads and validates the actual boot loader or kernel.
Over the years, many such shims have been signed, but updates have lagged and security vulnerabilities have been found. Even unused old boot loader code remains signed and viable, allowing attackers to replace a modern version with a vulnerable, still valid, old version.
Microsoft has removed several of the vulnerable boot loaders via recent Windows patches, however systems that are not updated and systems that do not run Windows will still likely be vulnerable.
The Januscape vulnerability allows a user in a guest VM managed by the Linux Kernel Virtual Machine (KVM) to corrupt memory in the host system and break out of isolation.
KVM virtualization is used by major hosting platforms like Amazon AWS, Google GCP, Digital Ocean, and many more. All of the shared hosting platforms count on virtualization to isolate untrusted guest systems from the physical hardware and each other; being able to corrupt memory for all guests or break isolation presents a major threat.
The bug report says the error has been present for 16 years, which is nearly the entire lifetime of the KVM subsystem in Linux. Fixes are available in mainline, and major hosting providers who count on KVM are likely already updating.
Vulnerabilities In Balcony Solar
Micro solar, or “balcony solar”, installs have been gaining traction in Europe as a way to offset rising electrical costs by connecting solar and battery systems to a house or apartment power system.
Vulnerabilities have been found in the popular Hoymiles micro-inverter, which uses a proprietary RF radio protocol to manage the devices. Unfortunately, it looks like this protocol has no encryption or authentication beyond validating the serial number, and the serial number is also available over a wireless probe command.
Armed with a Nordic nRF radio researchers were able to discover nearby inverters in the wild and collect the serial numbers, though of course they stopped short of issuing commands to random users.
The wireless management control allows controlling the device power and output levels, as well as setting a lockout PIN, which the researchers suspect could be used to disable devices and lock the legitimate owners out completely.
There are an estimated 500,000 units in use, and currently the only known mitigation is to unplug the device entirely and disconnect the solar panels, though the team suggests that setting an anti-theft PIN may also help – or at least prevent an unknown PIN being set.
Be sure to check out the link for an in-depth analysis of the protocol and the surprising lack of protection.
The most interesting security fixes appear to be to file handling in the sftp and scp file transfer tools, a malicious remote server could cause the files to be downloaded to the wrong directories. Besides those, the security fixes seem relatively calm, making behavior more consistent when forwarding and tunneling options were in conflict, mitigating a potential denial of service, and cleaning up other behavior.
OpenSSH 10.4 introduces some experimental support for additional post-quantum encryption standards, but beyond that seems to be a normal update.
Tenda Routers (may) Have Backdoor
According to CVE-2026-11405, Tenda brand routers may have a deliberate backdoor in the web interface.
The vulnerability report claims that the httpd binary contains a fallback to a plaintext, hardcoded password that allows anything on the internal network to bypass authentication and reconfigure the router. This seems entirely plausible, based on issues found in other router firmwares, however additional reports raise doubts about the pervasiveness of the backdoor, or if it exists in all firmware versions.
If you have a Tenda brand router and are so inclined, now might be a great time to investigate OpenWRT or other alternate, updated firmware, but there’s probably not a reason to panic just yet.
Tricking the GitHub Agent With Prompt Injection
Can we go a week without discussing prompt injection in AI agents? Apparently the answer is no.
Noma Labs reveals how they were able to use prompt injection against the GitHub support agent to reveal private repositories of an organization. Leveraging the GitHub Agentic Workflows that link workflows with AI agents, Noma Labs were able to file an issue in a public repository that exposed private repositories in the same organization.
The attack appears to be as simple as filing an issue in the public repo, and requesting the contents of files in both the public and private repo, which the agent happily provided. Not only did the AI agent provide the file content of private repos, but it put it in a public issue in the public repository!
Noma Labs says in the writeup that GitHub had instituted guardrails to prevent an agent from accessing private repositories, but simply including the request to “additionally” perform other tasks was sufficient to bypass. This makes GitHub the latest in a seemingly endless chain of AI agents happily helping bypass corporate security, and it doesn’t seem like a trend that will slow down for a while.
Windows Device Identifier Catches Ransomware Operator
Windows installs contain a globally unique identifier generated during the initial install, which is used to track device behavior across Microsoft platforms. Toms Hardware reports that during an investigation of the “Scattered Spider” ransomware group, Microsoft provided records tracking the GDID of one of the ransomware operators, allowing the identification and arrest of one of the groups members.
Scattered Spider has been responsible for millions of dollars in ransomware attacks globally, including high-profile ransomware attacks against major Las Vegas resorts, Qantas airlines, Visa, and hundreds of other companies.
Court documents reveal that following the arrest of one of the suspected members of the group, the Windows global ID was used to link other behavior across Azure, video games, and other telemetry.
CISA reviews lessons learned
Mentioned here in May, the US government cybersecurity agency (CISA) suffered a disclosure of authentication tokens, cloud infrastructure, and plaintext passwords via a public GitHub repository named “Private-CISA” and operated by a contractor.
CISA has published the results of their internal review. Unsurprisingly, as a large government agency, CISA essentially followed the playbook for dealing with incidents: identify the most critical issues and disable the access of the contractor who exposed credentials, determine the full scope of disclosed data, and terminate accounts, change passwords, and expire authentication tokens which were exposed.
More NPM malware packages
Opensource Malware reports on additional infostealer malware uploaded to the NPM repository. Like most NPM-based malware, these packages rely on the install script mechanism to trigger arbitrary commands, firing immediately during package install with no additional interaction.
All of the malware packages mimic existing popular packages and depend on user typos or confusion to get selected. Once triggered, the malware collects a machine fingerprint, git user information, GitHub account information, SSH account information, and corporate identifiers. The packages are largely nonfunctional – the code in the package itself is irrelevant, once a victim triggers the install the malware payload is fired.
All of the packages were uploaded by the same source, tracked to the owner of a cybersecurity company. It is unclear if this is a misguided attempt to generate leads or hype, or if this is a research project gone wrong, but the payload of the malicious packages has been developed and tuned over time. For a company trying to build a reputation or trust, this is surely the wrong way to do it.
China warned organizations to remove certain Claude Code versions over alleged backdoor risks, while Anthropic called the feature anti-abuse protection.
Auger co-founders Leigh Anne Clark and Dave Clark at the company’s Bellevue, Wash., office. (GeekWire Photo / Todd Bishop)
While investors spent much of the spring concerned that frontier AI models from companies like Anthropic and OpenAI would consume the software industry, Dave Clark was closing a funding round for exactly the kind of enterprise software those models are supposedly going to replace.
Auger, the supply chain technology startup founded in Bellevue, Wash., by the former Amazon executive, has raised $50 million in Series B funding led by Eclipse, with existing investor Oak HC/FT also participating in the new round.
The round brings total funding to $150 million for the company, which has grown to about 130 employees and counts Meta’s virtual and augmented reality division, sports merchandise giant Fanatics, and consumer products maker Kimberly-Clark among its customers.
Clark’s view is that general-purpose AI can generate insights but can’t handle deeply specialized domains like running a supply chain. Making financial and operational decisions and executing them at the scale of big companies requires systems built on strong supply chain expertise — what Auger calls its ontology, essentially a detailed map of how supply chains actually work.
“Many a pure technology company died on the hill of supply chain over the last decade,” said Clark, the company’s CEO, in an interview this week. “You really need to understand the complexity and the contextual requirements.”
Auger sits on top of a company’s existing systems — ERP, warehouse management, transportation management, and demand planning tools — and unifies the data into a single operating layer. Rather than replacing those systems, it connects them, using AI agents and traditional optimization models to make decisions and execute them automatically, as much as possible.
For example, in a recent demo at the company’s Bellevue office, Clark showed how the system would handle a supplier missing a delivery commitment when there isn’t enough product to go around. Auger identifies the shortfall, determines which customers get priority, reallocates inventory, and pushes the updated plan back to the company’s existing systems.
Most supply chain software, Clark said, generates alerts and waits for a person to act. Auger is designed to make routine decisions on its own and flag the exceptions for human review.
“We’re not really a tool,” he said. “We’re really the new employee.”
At Fanatics, the sports merchandise company, Clark said about 85% of decisions in the process Auger manages are happening autonomously, with a goal of reaching the mid-90s soon. In addition to the customers it has named so far, Clark said another eight to 10 companies are in contract negotiations or pilot programs.
Clark spent 23 years at Amazon, rising to lead the company’s worldwide operations and later its worldwide consumer business. He left in 2022 and became CEO of Flexport, the freight forwarding startup, but that tenure lasted less than a year amid a turbulent period for the company.
He launched Auger in 2024 with a team that includes Leigh Anne Clark, his wife, who serves as co-founder and president of the company’s fashion and beauty division, focused on an industry Clark describes as one of the most wasteful supply chains outside of groceries.
Clark moved back to the Seattle area from Texas to tap the region’s talent pool, and raised a $100 million Series A from Oak HC/FT. The company quickly assembled a C-suite drawn heavily from Amazon’s senior ranks, along with leaders from Johnson & Johnson, Microsoft, and Salesforce, spanning supply chain operations, AI, data science, and product development.
In March, Auger was named a premier supply chain partner on Microsoft Fabric, the tech giant’s data platform. Auger’s product is built on Azure, and Microsoft sales reps can earn commission on Auger deals. Clark said the partnership has generated engagement but is still early.
Clark said Auger went out for the Series B early, before the company needed it, to avoid the distraction of fundraising during what he expects to be a busy fall of customer onboarding.
With the investment, Eclipse partner Jiten Behl joined the Auger board, which also includes Clark, president and CFO Alex Ceballos, and Oak HC/FT’s Matt Streisfeld.
Auger hasn’t disclosed revenue or other financial metrics, but Clark said the valuation was roughly double the level set by Auger’s initial round. “We didn’t shoot for the crazy astronomical valuation,” he said. “We sat at a place that we felt really comfortable with.”
That pragmatic approach extends to how Auger operates. In Bellevue, the company works out of an office it subleased after Microsoft vacated the space. Auger kept the desks, monitors, and chairs the tech giant left behind, furnishing its new offices for next to nothing.
But Clark’s ambitions for the company are anything but modest. He said Auger’s goal is to have half of U.S. GDP flowing through its platform by 2030, with revenue exceeding $1 billion.
“That requires a pretty steep curve to get there,” he said. “We’re not playing small.”