Reading view

There are new articles available, click to refresh the page.

This Week in Security: It’s Patch Tuesday Again, TVs Spying, Supply Chain Worms Return, Prolonged Hack Impacts, Stolen IDs

Several times this summer, Microsoft’s Patch Tuesday, the monthly roundup of major security patches for Microsoft products, has included record-breaking numbers of security fixes. The August 2026 patch set actually seemed to catch up. Was this a sign of the bug apocalypse lessening? Ha, nope!

Brian Krebs at Krebs On Security once again brings his excellent roundup of Patch Tuesday events, with this months patch set absolutely crushing previous numbers with nearly 1,000 security fixes.

Two of the fixes are for zero-day vulnerabilities under active exploitation in the wild, both allowing privilege escalation on Windows. Privilege escalation bugs turn general vulnerabilities in applications and games into full administrator access to gain persistence and deploy ransomware, and generally make any vulnerability significantly worse.

Krebs also calls out a CVSS 9.8 (so close to a perfect 10!) vulnerability that allows remote code execution in the Windows shell with no user interaction and no authentication, a remotely exploitable DNS bug present since Windows Server 2012 and Windows 10 which will likely see exploitation in the wild soon, and over a hundred other bugs are ranked “Critical”.

How the sheer volume of vulnerabilities in this patch will fit with recent Microsoft recommendations that companies should apply the patches immediately remains to be seen. (Likely: not very well, depending on what new behavior and issues the fixes cause!)

Is Your LG TV Spying on You?

Gamers Nexus continues their trend of high-quality investigation, and they have posted another tremendous multi-hour investigatory video. This time Gamers Nexus focuses on the ecosystem of LG televisions and monitors.

It shouldn’t likely surprise many here that “smart” devices are usually more to the benefit of advertisers than consumers. Similarly, it shouldn’t be a surprise that a “smart” device harvests user data to sell to advertises. What may be surprising is the degree to which LG devices appear to collect data, how much data is sent even when collection is turned off, and how overt executives at the company are, with multiple executives making statements in pitches to advertisers that LG “owns the glass”, “owns the living room”, and is designed to correlate devices, inhabitants of the environment, and viewing habits so that ads can be served to the TV and mobile devices in the same room simultaneously.

With tracking enabled, the smart TV captures telemetry of what applications are used, as well as continually capturing the video displayed and reporting fingerprints to LG servers and ad partners. The screen content is tracked not only for TV, but for the HDMI inputs, including if the TV is used as a PC monitor. If voice control is enabled, the TV also records audio and analyzes it. The TV also continually scans the local network and nearby Wi-Fi networks, reporting all the devices it finds on the local network, including host name, MAC address, and sometimes software running depending on the MDNS advertisements. Near-by Wi-Fi networks are sufficient for very precise geolocation, so LG effectively knows the location of every customer, as well.

Gamers Nexus makes the point that while the invasive ad tech is gross, it’s mostly limited if the user does not agree to the end-user license agreement – but the infrastructure required to enable it is riddled with security flaws, both discovered and likely additional undiscovered issues. A smart TV is basically a computer, usually running either some flavor of Android or Linux, with the attendant flexibility, power, and problems. A vulnerability in the TV operating system or its apps can provide a route into your internal network. (Not that this required an exploit: LG was called out earlier this summer because 42% of apps on the official app store contained residential proxy systems to sell your home Internet connection.) But it can also access any of the attached hardware, like the microphone.

Gamers Nexus demonstrates that a LG TV can be exploited to gain local root, and from there, it can record audio from attached devices – even when the primary microphone is muted. Gamers Nexus also discovered that muting the microphone on some models does not disconnect or disable the microphone, it simply sets the gain levels extremely low; recording is still possible, and with amplification, audio is still recoverable.

Spy tech and ad tech goes hand in hand; it will be interesting to see if LG responds by at least hardening the security on the devices, or if another company finds traction in selling modern televisions and monitors without the “smart” advertising.

Shai-Halud NPM Worm Returns

Aikido.dev reports that after 111 days, the Shai-Halud worm returned to the NPM repository.

Shai-Halud was one of several worms hitting package repositories in the Spring of 2026, installing backdoors, stealing cryptocurrency wallets, and taking every login credential and authentication token it could find before infecting every package the tokens linked to. Since then, infections have remained quiet, and repositories like NPM have stated that they now scan every package as it is uploaded.

Charlie Erkisen at Aikido.dev observed that on September 7, 2026, four additional packages uploaded to NPM were infected with Shai-Halud; not a variant of the worm, but the original code, matching the known public signatures. Whatever scanning is in place in the NPM repository didn’t filter them, and if an exact match for a known, major worm isn’t caught by the infrastructure, it’s unclear how a new threat would be.

Boston Scientific Hack Continues

The apparent ransomware attack against Boston Scientific continues to have impacts, with Boston Scientific filing a report with the SEC that the attack is expected to have an impact on the company earnings.

Boston Scientific makes medical devices, like pacemakers, stents, and monitoring equipment. It has not yet been publicly disclosed what happened, or if customer data was compromised, but the SEC filing confirms that unauthorized access on “certain systems” causing an outage. After several weeks of outages, the company reports that it is able to ship almost at capacity, and that the sterilization facilities for medical devices are online. While there is no estimate provided for full recovery, efforts are ongoing.

Commerce Sites Vulnerable

Adobe released a security bulletin that the Adobe Commerce and Magento platforms are under active exploitation from CVE-2026-75650, a flaw in the template engine.

These platforms power tens of thousands of commerce sites, and vulnerabilities in them are usually used to steal payment data or serve malware to customers during the checkout process. Previously this year, Magento patched another vulnerability which allowed uploading executable files to any store, and indications are that the current vulnerability has been exploited in the wild since early September 2026.

The current vulnerability allows implantation of PHP code by injecting custom styles into a query, which is then executed when Magento generates a failure email and renders the template. The attackers then download and install a control binary written in Rust which masquerades as a kernel thread task, which then monitors the store and collects payment data.

The vulnerability was publicly known and used for several days before Adobe made official statements of a fix being available, leaving any store running on Magento vulnerable with no official fixes, but as of writing this, Adobe has published patches and an advisory.

Microsoft to Block Unpatched Servers

Microsoft plans to block emails to to the cloud-hosted Exchange Online from unpatched on-premises Exchange servers.

Apparently the urge to self-host Microsoft Exchange is coupled with antipathy about actually patching it, to such a significant level that Microsoft is taking the steps to detect incoming mail from servers that have not patched since October 2025. While Microsoft updates rarely apply with zero problems, nearly a year is more than enough time to have tested and deployed a security fix.

“This update released nearly a year ago, and all organizations should have updated to it”: so say we all.

Hackers Pose as Recruiters

Government-backed groups in Iran have been posing as recruiters trying to infect targets with malware.

The group, designated “Nimbus Manticore”, is known to develop custom malware and remote access tools (RATs), and typically target specific individuals via spear-phishing attacks. The latest malware from the group is cross-platform and can infect Windows, macOS, and Linux, installing services to run websocket-based remote access tunnels, SSH tunnels, and a command-and-control client that allows live control of the infected device.

The group contacts targets posing as recruiters, but first the target must solve a coding challenge contained in a zip file. The zip contains a trojaned Node.js project which infects the victim system when compiled, deploying the remote access tools and setting up persistence to relaunch them if disabled. Multiple variants have already been spotted, generally targeting different countries, predominately Egypt, Afghanistan, and Ethiopia.

The latest version of the malware package also looks for settings and data from major security vendors like Symantec, CrowdStrike, and SentinelOne, as well as the contents of directories related to Google and Microsoft services.

The fake recruiting method has also been used by other groups in Iran and North Korea. Remember: any project with a build script can execute any commands as part of the build, and most IDE project files also allow embedding custom plugins and commands into the project. Triggering a compile on a project is the same as running arbitrary commands!

150 Million US Drivers Licenses Stolen

As many outlets are now reporting, a major ID validation company was compromised, leading to the theft of scans and data of 150 million US drivers licenses.

IDScan provides drivers license and identification card scanning services used by car rental companies, bars and dispensaries, hotels, concert venues, and a multitude of other businesses. If you’ve ever had to hand your ID over for validation, there’s a high chance you’ve interacted with IDScan or a similar company.

Evidence points to IDScan being compromised for at least a year, with full scans of licenses continually exfiltrated. The scans include everything visible on a typical license or ID card, including name, license identification number, ID photo, and home address, but also the date that it was scanned in. The collection even includes additional scans of the ID in ultraviolet and infrared to catch any watermarks. With 150 million entries, the data set contains everyone from the security researcher Brian Krebs who broke the story, to government officials like Pete Hegseth.

The data has been available for sale, individually or in bulk, although with the recent press coverage the site claiming to sell the data has gone offline for now. Before disappearing, the site claimed that all data was exfiltrated into their own databases, which means it’s still available somewhere, and shutting them out of the IDScan service won’t protect data already stolen.

Many aspects of this echo the scanned ID data stolen from validation services used by Discord and other online services: almost like scanning unchangeable government IDs is a bad plan?

American Meteor Society Knocked Offline

It’s all fun and games until they come for the geek hobbies. The American Meteor Society Fireball tracking program is was knocked offline, seemingly from a ransomware attack. Fortunately it looks like as of writing this, the admins were able to restore a backup and the site is online again.

This Week in Security: Android Malware, VOIP Hijack, Signal Contact Discovery, and TeamPCP Arrests

On GitHub, [AyaanB] details buying a cheap Android TV streaming device, looking for, and finding, baked-in malware.

Multiple warnings have been issued by the FBI and CISA regarding malware on media box Android devices. Many devices have been caught participating in botnets providing residential proxies, ad-click fraud, and DDOS services. [AyaanB] sets out to discover if a $30 set-top streaming box is pre-infected with malware, and extracting it – without ever letting the device talk to the Internet or access other devices on the local network.

Picking a device named in the advisories, [AyaanB] discovered that it was, indeed, preloaded with multiple app stores and applications that wouldn’t typically make sense on a set-top TV box. After identifying the serial port test pads and obtaining a low-voltage serial adapter, they were able to gain access to the bootloader and from there dump the contents of the MMC over TFTP.

With the entire filesystem accessible out-of-body, proving it was infected with malware at the factory becomes simple: the malware is signed as a system application, baked onto the system partition of the MMC, granted SELinux exceptions to mark it as a system binary with shell privileges, and has multiple launch scripts to make sure it is executed even if partially removed. With the malware identified, [AyaanB] continues to dig through to uncover the capabilities.

By installing hooks into the low-level Android process spawning system, the malware installs hooks into every application as it is launched: even if an application isn’t trojaned already, by the time it finishes executing, it’s definitely been subverted. The functions patched and the methods used match the Vo1d botnet, which is used for account takeovers, residential proxies, free “VPN” services, and other unfriendly behavior.

Further digging into the system showed hooks for ad-click fraud, where hidden browser windows are allowed to run unthrottled and display overlays are configured to obscure ads below where the user may click. Other included tools bid in real-time ad auctions, claiming to directly publish ads to the user which may or may not be visible. To cap it all off, a root level backdoor allows botnet operators to access the systems directly and install additional tools.

Be sure to check out [AyaanB]’s writeup for more details on exfiltration methods and other malware found on the devices.

Hijacking Calls to Military Bases with DNS

In the early 2000s, a domain name scheme was developed to directly map telephone numbers to DNS records for SIP and VOIP calling. (Who knew? I didn’t!) But [Lina] did, with an excellent writeup on accidentally positioning themselves to intercept phone calls by registering an expired domain.

The e164-arpa number to name scheme was never widely adopted, and quickly forgotten about. As is the way with all forgotten standards, the infrastructure slowly fell apart. [Lina] noticed that several country records were delegated to name servers hosted in expired domains, and by simply registering them, they were able to begin resolving queries. For a five Euro registration fee, [Lina] gained control over an abandoned DNS resolution protocol for Saint Helena, Diego Garcia, and Ascension Island. After watching the logs for some time and not getting any traffic, and running into the bureaucratic tangle of standards committees and the actual United Nations, the project was shelved.

Six months later, [Lina] examined the logs of the other domains, and found hundreds of thousands of records of attempted calls, and since you read the section header, you already know where the calls were headed. Clearly some phone systems still attempt to use the ill-fated e164-arpa calling scheme even in 2026, and because the DNS records control the destination of the call, it would have been possible to hijack all the calls transparently and mine them for information, and all for five Euros. With military bases involved, and with one of the bases targeted by missiles during recent conflicts, suddenly agencies cared significantly more, and the story has the happy ending of the domains being transferred to the National Cyber Security Center in the UK.

AliExpress Fingerprinting Browsers

AliExpress has been caught using a hidden fingerprinting technique to try to identify users.

The fingerprinting plays a waveform in the background of the page with the volume set to zero, and measures variances in the computed values. Variances in the computed waveform are introduced by the browser type, CPU, audio hardware, and even the driver versions. While most of the headlines have focused on the audio fingerprinting, AliExpress also used other fingerprinting techniques to build profiles of each browser, including WebGL, WebRTC, screen resolution, and other web integrations.

The purpose of the advanced device fingerprinting is unknown: AliExpress could use it for fraud prevention, but could also be using it to identify and track customers when they have disabled traditional tracking cookies. The audio fingerprinting was discovered when a user experienced trouble with Bluetooth headphones being attached to the silent audio stream.

Unfortunately with fingerprinting techniques which leverage standard features in the browser it can be difficult to block them. Sometimes, ad blockers may be able to identify and block some of the fingerprinting resources, as can disabling some features in the browser, but many features like audio and WebGL can’t usually be turned off.

[Tom Ritter], who works for Firefox, mentions that they head this fingerprinting method off at the pass three years ago as part of their anti-fingerprinting campaign. This is clearly not the case for all browsers.

Attacking Signal’s Contact Discovery

Most chat apps allow you to discover users from your contacts list who also use that app – but then you’ve given your contact list to the app, helping them build their marketing and social graphs. Signal of course handles it differently, allowing you to discover users from your contacts list while preventing the Signal corporation from being able to access your list of contacts. Well, mostly.

Signal runs the contact discovery process inside an Intel SGX Enclave. A SGX Enclave is an Intel extension similar to a Trusted Execution Environment (TEE) on Arm, where memory and execution can be partitioned for a restricted process. In theory, code and memory inside an enclave can not be read by other processes, root processes, or even a hypervisor or virtualization system. Signal uses enclaves so that the users encrypted contacts list and the encryption key itself are fully insulated. The Signal client is then able to validate the integrity of the enclave using known measurement values baked into the client releases.

Researchers using the V12 AI agent discovered this wasn’t always the case. Because a SGX Enclave shares resources with the rest of the system, a malicious host could create exploitable race conditions in the algorithm by generating page faults and pausing execution of the enclave. The malicious server running the enclave is still unable to directly read the contents, but it could extract the secret values needed to then create false servers which could fully expose the user contact list.

A second attack would allow a malicious host to manipulate the list of clients connected to the enclave, gaining full code execution inside the enclave with the predictable result of exporting contact data.

Both of the issues were reported to Signal and fixed before the public writeup, and there is no evidence they were ever abused: to attack either flaw, a compromised host would have to be running the Signal enclave code and be part of the Signal infrastructure that clients would connect to.

Boston Scientific Hit by Cyberattack

Boston Scientific reported in a SEC filing that it has been hit with an unspecified cyber attack impacting operations, causing the stock to drop by almost 5% in a day.

The company has been unwilling to release any details of the attack, but expects to be able to resume shipping of medical products in “less than three weeks,” which sounds like a pretty major disruption. Boston Scientific manufactures defibrillators, pacemakers, and surgical equipment. It’s unclear if any patient data has been compromised, though presumably regulations will require disclosure if that’s determined to be the case.

With no additional information about the attack, it’s also unclear if any source code or other data which could aid attacking medical devices was impacted, either.

Carhartt Hit by Ransomware

The Carhartt clothing company has also been hit by ransomware, with 13 million accounts leaked.

The ShinyHunters group claims responsibility; previous victims of the group include casinos, car manufacturers, medical companies, and government agencies. The leak claims to include over 50 gigabytes of customer and employee data, with customer data including email, phone numbers, and physical shipping addresses. The group demanded $3.3 million in ransom for the data, and published it when Carhartt didn’t pay.

Have I Been Pwned linked the data to a compromise of the Databricks instance used by Carhartt, which is a platform for linking business data and AI.

AI Agents Installing Unknown Code

Multiple AI agents (Codex, Hermes, and Claude) have been observed executing arbitrary instructions and code contained in the llms.txt files on websites.

Normally, llms.txt and llms-full.txt are used to instruct AI agents on how to summarize and index the sites content, but researchers in Israel indexed the files of Fortune 500 companies, defense contractors, and tech companies and found that over a hundred of them included directions to install packages which didn’t exist or referenced domain names that were not registered. The researchers were able to create packages with matching names and record agents inside multiple high-profile companies installing and executing them.

While documenting the reach of the exposed packages, researchers found at least one had already been replaced by attackers with live malware which would execute inside whatever context the agent was executing in, potentially exposing authentication tokens or company data. The attacks which have been rampant in the NPM and PyPI package repositories can make even legitimate packages dangerous to install, but agents blindly following instructions from arbitrary websites inflates the danger even higher.

Alleged Members of TeamPCP Arrested

Finally, security reporter extraordinaire Brain Krebs brings news that suspected key operators of the TeamPCP group have been arrested in Australia.

TeamPCP has been behind some of the worst of the supply chain attacks plaguing PyPI, NPM, and VSCode plugin repositories, and have released the source code to some of the worms used in the supply chain attacks to muddy the waters and recruit new members. TeamPCP has also been involved in compromising thousands of GitHub repositories, and is affiliated with multiple other crime and malware groups.

While the identities of the arrested individuals have not been officially released, in typical Brian Krebs fashion, dozens of connections are correlated showing their likely identities and links to TeamPCP and other groups. If nothing else, this should serve as a reminder that the best time to pay attention to operational security was ten years ago.

As TeamPCP doesn’t appear to be a state-sponsored group, or even strongly organized, the arrests of a few members are unlikely to drastically slow down the compromises. Krebs details conversations held with one of the arrested men, in which they discuss struggles with sobriety and plans to leave the malware scene, stating that others have already taken over leadership roles in the group.

Filings show Amazon’s stake in electric trucking company that just struck a deal for 500 Tesla Semis

Einride plans to deploy 500 Tesla Semis for Amazon and other customers. (Tesla Photo)

Amazon is quietly accumulating a stake in Einride, the Swedish electric trucking company that said Tuesday it will deploy 500 Tesla Semis for Amazon and other customers.

Einride’s SEC filings show Amazon holding warrants for 25.2 million shares — about 12% of the company — that vest as Amazon buys freight services. The company’s financial report Tuesday, its first since going public in June, has the warrants on its books for the first time.

An Einride spokesperson confirmed that a “warrant contract asset” of 1.5 billion Swedish kronor (roughly $160 million) on the company’s balance sheet represents the Amazon warrants. It is the largest single asset on Einride’s books, worth more than its trucks and more than its cash.

At the same time, Einride is relying heavily on Amazon for growth, forecasting a 60% to 73% year-over-year revenue increase in the second half, “fueled by the Amazon ramp and other deployments in the U.S. and Europe,” as the company said in its earnings release.

Amazon announced in April that Einride would deploy 75 electric trucks with charging at five U.S. sites in its middle-mile network, the leg between warehouses and delivery stations.

Tesla Semi rollout: Einride also said Tuesday it will deploy 500 Tesla Semis across North America, calling it the largest deployment of Tesla’s electric big rigs in the world to date. The trucks will serve Amazon and other Einride customers on freight corridors in California, Texas, New Jersey, Illinois and Georgia, rolling out in phases over two years beginning in September, financed by third parties.

Tesla Semis are already hauling some Amazon freight. Nevoya, an all-electric trucking carrier based in Southern California, says it runs Amazon loads using Tesla Semis.

Amazon’s electric semis: Amazon has been turning to other manufacturers to electrify its freight network beyond the last-mile delivery vans it buys from Rivian. It deployed nearly 50 Volvo electric semis at Southern California ports and ordered more than 200 electric big rigs from Mercedes-Benz for Europe, part of a pledge to reach net-zero carbon across its operations by 2040.

Einride, for its part, doesn’t sell trucks. It buys and finances them, hires the drivers or contracts carriers, builds the charging infrastructure, and hauls a customer’s freight for a fee — using its own software, called Saga AI, to plan routes around charging windows and battery range.

The pitch to a shipper like Amazon is that it gets electric trucking capacity without purchasing vehicles itself or creating electric charging infrastructure.

Long-term autonomy: Einride is also one of a small group of companies running fully driverless trucks in commercial service in the U.S., with Level 4 autonomous vehicles operating in Ohio and more than 5,400 driverless hours logged for customers as of June 30.

The trucks hauling Amazon’s freight, however, have drivers, as will the Tesla Semis, for now. Tesla CEO Elon Musk said on the company’s July earnings call that self-driving capability for the Semi is about a year away. That timeline would fall inside Einride’s two-year rollout.

Einride’s Amazon deal: Roozbeh Charli, the Einride CEO, said on the earnings call Tuesday that the April announcement with Amazon brought a wave of new business.

The takeaway for customers about Einride was, “If these guys can handle the complexity of Amazon’s network, they can handle ours,” he said, explaining that there was “quite a lot of inbound” following the news.

Charli said customers rarely specify hardware, and that Einride selects truck platforms based on the routes and the data. That would suggest Einride chose the Tesla Semis, not Amazon.

The Amazon warrants did not come up on the call. The terms have been technically public since April, buried in an exhibit to Einride’s merger filings with the SEC, but haven’t been previously reported, in part because Einride’s prospectuses refer to Amazon as “the Specified Party.”

Amazon’s financial arrangement with Einride follows a pattern.

  • The company struck a similar deal with Plug Power in 2017, taking warrants for up to 55.3 million shares that vested as Amazon bought fuel-cell equipment for its warehouses.
  • Amazon invested in Rivian in early 2019, then ordered 100,000 electric delivery vans from the startup later that year. The company owns about 12% of Rivian today.

Amazon did not respond to questions about the arrangement.

Editor’s Note: This story has been updated with comment from Einride. It was also corrected to note that Tesla Semis already haul Amazon freight for Nevoya, an electric trucking carrier.

Bezos and Liverpool FC, a Meta vet’s AI startup, Auger’s Dallas move, and the demise of Microsoft’s AI blob

This week on the GeekWire Podcast: What should Liverpool FC fans expect from Jeff Bezos as a member of the storied English Premier League club’s new minority ownership group? We consult the Amazon leadership principles for the answer.

Plus, a tip and an SEC filing lead to a scoop on a former Meta AI director’s new startup, the GeekWire Editorial Board convenes to decide whether Dave Clark’s Auger stays on the GeekWire 200 after moving its HQ to Dallas, and Microsoft quietly semi-retires its AI blob.

Related Stories and Links

Bezos and Liverpool FC

Noosphere and the Form D

Auger and the GeekWire 200

Microsoft and Mico

Subscribe to GeekWire in Apple Podcasts, Spotify, or wherever you listen.

This former Amazon exec is moving his startup’s HQ to Texas, and he has a few notes for Seattle

Auger co-founders Leigh Anne Clark and Dave Clark at the company’s Bellevue, Wash., office. (GeekWire File Photo / Todd Bishop)

One of the Seattle region’s most notable tech startups is moving its headquarters to Texas.

Supply chain technology startup Auger will maintain a major engineering office in Bellevue, Wash., where it got started. But the company’s co-founder and CEO, Dave Clark, the former Amazon operations chief, is officially back in Dallas, and he took the company’s HQ with him.

Founded in 2024, Auger has raised $150 million, including a $50 million Series B round led by Eclipse in July. Its software connects the systems that companies use to run their supply chains, integrating AI to help automate them. Its customers include Meta, Fanatics and Kimberly-Clark.

Clark, in an interview with GeekWire, said the move is about talent and family, not taxes. For one thing, Texas happens to better suit him and Auger co-founder Leigh Anne Clark, his wife. They’re running toward something rather than away, he said. They both grew up in the Southeast, and they had always intended to return to Texas at some point.

“I’d rather have a really hot month of August than a really gray month of February,” he said.

Dallas is also a place where you run into supply chain specialists at the coffee shop like you do software engineers in Seattle, he said. That’s a key talent pool for Auger at this stage in its evolution. Another bonus: Texas is more central to corporate customers across the country.

The magazine D CEO in Dallas, which first reported the news of Auger’s HQ relocation this week, noted that the company did not seek state or local incentives as part of the move.

Clark confirmed in the GeekWire interview Tuesday that taxes weren’t a factor, noting that he couldn’t even quantify what the tax advantages would be. However, he said, “There’s a lot I like about the way the state of Texas manages and works with business.”

When asked what he would say to people in Seattle who might see another warning sign in a startup like Auger moving its HQ somewhere else, he didn’t shoot down the premise.

“If you’re in that position, I think you’re right to be worried, in the sense that there’s a lot of discussion about things in the state of Washington and Seattle that are not particularly friendly to business,” he said.

Washington state lawmakers approved a “millionaires tax” this year, a 9.9% levy on personal income above $1 million. Seattle Mayor Katie Wilson drew criticism from some in tech after saying of wealthy residents who leave the state, “like, bye.”

Clark didn’t point to any particular policy or issue but said he has sensed an “anti-business” sentiment that concerns him since moving back to the Seattle area from Texas to launch Auger.

“Seattle should just be careful,” he said. “It’s not preordained that they win these things. It’s not preordained that these big companies stay in town.”

The Pacific Northwest has enormous resources to compete globally, he added, and there’s no reason it shouldn’t be “a phenomenal draw to anybody and everybody coming in.”

The region has “many, many strengths, and we should leverage them to the advantage of the community,” he said. “And sometimes I think the rhetoric gets in the way of it.”

Auger has about 115 people in Bellevue — engineers and supply chain data scientists — and Clark said he expects that office to grow 20% to 30% over the next year or two. He and Leigh Anne will both be back there regularly, he said, working alongside the team.

“Nothing’s changing there,” he said.

The company’s new HQ in North Dallas occupies part of the 15th floor of One Galleria Tower, centrally located between neighborhoods north and south of the city, with a quick run to DFW International Airport, as Clark pointed out in the D CEO article.

The office currently has about 15 people, most hired in recent months for sales, go-to-market and supply chain roles. Many of them had been traveling to Bellevue until the new space opened. Clark expects to add another 20 to 30 people in Dallas by the middle of next year.


As in Bellevue, where Auger subleased its space from Microsoft and bought the furniture for $1, the Dallas office came furnished. This time the furniture cost $10. (There goes Texas’ reputation for affordability.)

“It cost me 10 times more for the furniture in Dallas,” Clark joked. “I like nice things, cheap.”

Clark spent 23 years at Amazon, rising to lead its global operations and later its worldwide consumer business, and was one of the chief architects of the logistics network behind the company’s delivery operation. He left in 2022 to become CEO of Flexport, departing the freight startup the following year, before starting Auger.

Leigh Anne Clark is Auger’s president of fashion and beauty, leading the company’s work in an industry known for waste-prone supply chains. The couple, who met in Kentucky in 2000 while Dave Clark was at Amazon, have two sons, ages 14 and 11.

With its rapid hiring and significant early funding rounds, Auger rose quickly to No. 31 on the GeekWire 200, our ranking of Pacific Northwest tech startups. Because the GeekWire 200 is limited to companies based in the region, the headquarters move puts Auger’s standing in jeopardy.

Informed of this predicament, Clark made his pitch to stay on. “We still have a lot of dev there,” he said of the Bellevue office. “I think you get grandfathered into the list in some way, right?”

Meanwhile, the business keeps growing. Clark said Auger signed two major contracts Tuesday with customers he declined to name. The Bellevue office marked them with a bell-ringing, and the two offices celebrated together over a video call. A second bell is on order for Dallas.

“We’ll have dual bells that we’ll ring together,” Clark said.

❌