This week Jonathan chats with Michael Meeks about Collabora! What’s the origin story in this consulting company, why do they have an outstanding office suite, and where is the world headed to accomplish digital sovereignty? Watch to find out!
Did you know you can watch the live recording of the show right on our YouTube Channel? Have someone you’d like us to interview? Let us know, or have the guest contact us! Take a look at the schedule here.
Get caught up on the latest technology and startup news from the past week. Here are the most popular stories on GeekWire for the week of July 12, 2026.
Stardew Valley, the blockbuster farming sim from solo Seattle developer Eric “ConcernedApe” Barone, is coming to Magic: The Gathering via a three-part Secret Lair drop from Renton-based Wizards of the Coast — with original pixel art from Barone himself. … Read More
F5 names former Amazon executive as its chief people officer; Rudra Mitra departs as a Microsoft CVP after more than 27 years; and Qualtrics adds leaders. … Read More
The AI-generated video is an interesting study in how technology that’s very much being built and hyped in Seattle can be used to illustrate what the city sort of looked like more than three decades ago. … Read More
Apptio co-founders Sunny Gupta and Kurt Shintaffer launched Thira, a Bellevue-based enterprise AI startup, with $21 million in seed funding led by Madrona. … Read More
JPMorgan Chase is building out a new AI software infrastructure team, with a major presence in Seattle, focused on running AI across its data centers and outside providers in a way that controls costs, protects its intellectual property, and avoids tying its fortunes to any one vendor. … Read More
Rina Hahn leaves role as Remitly’s CMO; Temporal promotes Preeti Somal to EVP amid reorganization; and Veeam and Qualtrics make leadership changes. … Read More
Dave Brown, the senior AWS executive whose departure Amazon announced this week, is joining Meta to work on its data center build-out, according to a Wall Street Journal report. … Read More
General Fusion’s stock is trading up after it became the first fusion energy company to go public on a major exchange, debuting Monday on Nasdaq. … Read More
The Good | Authorities Sanction Cybercriminals & Dismantle Russian Bulletproof Hosting Infrastructure
The EU and the United Kingdom have jointly sanctioned multiple Russian individuals and entities for targeting government networks and critical infrastructure across Europe. The sanctions specifically target senior Russia military intelligence (GRU) officers and operators, as well as four entities linked to the Federal Security Service (FSB).
Officials say that the Russian government actively utilizes these state-sponsored units alongside recruited cybercriminals and private companies to systematically destabilize international partners and compromise key infrastructure across the continent.
From the U.S. Treasury Department, two individuals and a virtual private network (VPN) provider face sanctions for actively enabling ransomware attacks against American organizations.
OFAC designated First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, for supplying infrastructure that helped cybercriminals obscure their identities and manage stolen data. The service, which law enforcement dismantled last May, notoriously ignored abuse complaints and maintained zero user logs.
Yegeniy Silayev was also sanctioned for developing cryptors designed to conceal malware. Investigators estimate these specific tools and services directly facilitated billions of dollars in financial losses across critical sectors.
U.S. Federal prosecutors also unsealed indictments this week against three Russian nationals for operatingbulletproof hostingservices that facilitated over $62 million in global ransomware damages.
Defendants Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin allegedly managed “Media Land” and “ML Cloud”, providing essential infrastructure to syndicates like Lockbit, Play, and Blacksuit. These hosting platforms actively shielded cybercriminals by disregarding victim complaints and ignoring law enforcement takedown requests.
To disrupt this supply chain, the State Department is offering a $10 million reward for actionable information regarding foreign government links to these hosting providers.
The Bad | Attackers Trojanize Popular Remote User Platforms to Deploy Starland Malware
Cybersecurity researchers identified a financially-motivated Russian threat actor tracked as UAT-11795. Active since June 2025, the actor has utilized trojanized applications to harvest usercredentialsand cryptocurrency while primarily targeting users across the United States, Germany, Romania, and Venezuela.
To distribute their payloads, UAT-11795 operators disguise malicious installers as legitimate software, including WebEx, Zoom, MobaXterm, DBeaver, and FaceIT. Researchers suspect the attackers likely deploy these files via ClickFix social engineering.
The infection chain typically starts when a victim executes a malicious HTA file. This file retrieves an altered NSIS installer harboring a hidden Python loader disguised as a standard text document. The loader then modifies the Windows Registry to ensure persistent access before decrypting and deploying the Starland remote access trojan (RAT).
Upon execution, Starland verifies whether it is operating within a sandbox before creating scheduled tasks and attempting to escalate its system privileges. The malware scans compromised systems for browser data, cryptocurrency wallet assets, detailed system configurations, any antivirus products, and Active Directory infrastructure such as domain structure and controllers.
Beyond data theft, Starland possesses extensive capabilities to capture desktop screenshots, execute arbitrary shell commands, and fetch secondary payloads. Depending on system architecture, the malware can inject a 64-bit shellcode chain to deliver the CastleStealer information stealer or a 32-bit chain to deploy the Remcos remote access trojan.
To maintain resilient command and control (C2) communications, the operators integrate a redundancy mechanism that queries a Polygon smart contract for a fallback domain, and control two Telegram bots to receive notification beacons, including messages with the victim’s machine fingerprints and cryptowallet inventories.
Users are reminded to avoid executing unidentified commands online and should only download confirmed software from official vendor sources.
The Ugly | Nearly 300 Imposter GitHub Repositories Distribute Infostealing Malware to Collect Sensitive Data
Threat actors have published almost 300 fabricated GitHub repositories to distribute an information stealer from the BoryptGrab malware family. The actors systematically impersonated premium security products, cryptocurrency tools, and developer utilities to deceive victims searching for free software downloads.
As part of the lure, the malicious landing pages employ highly sophisticated client-side scripts that parse referral URLs to render customized branding and spoofed trust badges, significantly increasing the likelihood of successful social engineering.
Once a targeted victim clicks the download link, the infrastructure delivers a constantly rotating ZIP archive containing a legitimate, signed WinGUP updater paired with a trojanized dynamic link library file. When the user executes the updater, the program side-loads the malicious file, which then decodes and reflectively executes the BoryptGrab-variant payload directly into system memory.
Operating without establishing long-term persistence, the malware is designed to exfiltrate maximum data in a single execution cycle. The stealer targets passwords, payment details, and session cookies across 19 different web browsers and 32 cryptocurrency wallet brands, alongside messaging tokens from Discord, Steam, and Telegram.
The infostealer’s execution workflow (Source: Arctic Wolf)
To maximize collection, operators utilize direct code injection to bypass Chrome’s native App-Bound Encryption. All newly harvested data is compressed and routed to a Russian-based C2 server. Although the malware leaves behind forensic evidence by failing to wipe temporary staging directories, the scale of the impersonation campaign poses significant risks to unsuspecting developers.
GitHub has already removed a large portion of the false repositories, though several of the malicious redirector pages remain actively online. Researchers advise users to independently verify software authenticity and exercise extreme caution when navigating unofficial portals, sharing this YARA rule to help detect BoryptGrab activity and IoCs.
This week Jonathan chats with Nariman Jelveh about Puter! It’s the project that takes the idea of the Browser-as-the-OS seriously. Why did a simulated desktop on the web take off, what the story of making it Open Source, and what’s coming next? Watch to find out!
Did you know you can watch the live recording of the show right on our YouTube Channel? Have someone you’d like us to interview? Let us know, or have the guest contact us! Take a look at the schedule here.
Get caught up on the latest technology and startup news from the past week. Here are the most popular stories on GeekWire for the week of July 5, 2026.
HashiCorp co-founder Armon Dadgar argues that convenience-driven apps and AI are pushing us toward the dystopia depicted in Pixar’s 2008 film, and makes the case for regulation and intentional living as the antidote. … Read More
Former Amazon executive Dave Clark’s supply chain startup has raised $50 million in new funding, bringing its total to $150 million, as it builds a customer base that includes Meta, Fanatics, and Kimberly-Clark. … Read More
Microsoft is cutting 4,800 jobs and overhauling its Xbox gaming business in what its new gaming CEO calls the biggest restructuring in Xbox history, while reshaping its sales and consulting division amid record AI spending and a 30% stock slide. … Read More
Former GitHub CEO Thomas Dohmke’s startup Entire is rolling out a distributed network for mirroring code repositories, making the case that centralized platforms like he once ran as part of Microsoft can’t handle the demands of AI coding agents on their own. … Read More
Past exec at Amazon, Microsoft and Google is now Dropbox’s first CPO; T-Mobile appoints a new C-suite leader and promotes another; and Xbox VP Kevin LaChapelle is laid off in Microsoft’s big round of layoffs. … Read More
While American tech giants are valued for the anticipation of perfect prototypes, Chinese manufacturers are winning the robotics race by getting paid for delivery. … Read More
Governance, risk and compliance software company LogicGate recently signed a lease in Bellevue with space for up to 25 employees and expects to have about 20 people working there by the end of the year. … Read More
A look at the science behind Elon Musk’s goal of a million-person city on Mars, and why planetary scientists say terraforming the planet to make it habitable would take centuries, if it’s possible at all. … Read More
The Good | Authorities Apprehend Pro-Russian Hacktivist & Dismantle Global Fraud Networks
Spanish authorities, acting on intelligence provided by the FBI, have apprehended a suspected core member of the pro-Russian hacktivist syndicates CyberArmy of Russia Reborn (CARR) and Z-Pentest.
While masquerading as ideologically motivated collectives, these groups have actively executed disruptive cyberattacks against critical infrastructure, including food processing and water facilities across the United States and Europe. Investigators allege the arrested individual, residing in Palencia, provided extensive operational and logistical support to a Ukrainian hacker working for CARR, even attempting to facilitate their escape to Russia.
The individual is also suspected of coordinating cyber operations for the NoName057(16) group using encrypted messaging platforms. In a March 2026 raid, law enforcement officers seized multiple computers and successfully froze cryptocurrency wallets utilized to launder illicit proceeds generated from stolen data sales. The suspect currently faces ongoing criminal investigations for alleged collaboration with a recognized terrorist organization and severe computer damage.
In a massive global crackdown on social engineering and financial fraud, international law enforcement agencies havearrested5,811 suspects and seized approximately $293 million in illicit assets. Codenamed “Operation First Light 2026”, the coordinated initiative spanned 97 countries and specifically targeted business email compromise (BEC), investment scams, and money laundering syndicates operating between January and April. Interpol actively coordinated the extensive joint action, collaborating directly with regional policing bodies like ASEANAPOL, GCCPOL, and Europol to swiftly block over 31,000 fraudulent bank accounts and virtual wallets.
Eswatini police seized electronic devices, foreign currency, and realistic replicas of Brazilian police uniforms, signage, and equipment (Source: Interpol)
Investigators identified more than 142,000 victims worldwide and pinpointed an additional 15,600 suspects for future prosecution. This success builds upon recent international efforts, including Operation Synergia II, to dismantle the sprawling infrastructure supporting transnational cybercrime. Officials emphasize that robust, cross-border law enforcement cooperation remains essential to combat the escalating threat of organized cyber-enabled financial crimes globally.
The Bad | Threat Actors Deploy Forg365 PhaaS to Hijack Microsoft Accounts
Cyber researchers have identified a new phishing-as-a-service (PhaaS) operation dubbed Forg365, which targets Microsoft 365 enterprise accounts. Blending adversary-in-the-middle (AiTM) techniques with device-code phishing, the platform provides an integrated dashboard to manage post-compromise activities.
Forg365 works by incorporating AI to assist in generating customized phishing lures. By integrating AI directly into the control panel, Forg365 developers significantly lowered the financial cost needed to launch targeted campaigns. To remain undetected, its operators route messages through legitimate Amazon SES infrastructure while hosting their landing pages on Cloudflare.
The Forg365 panel (Source: ZeroBec)
The operation leverages the OAuth 2.0 device code authentication flow, originally designed for input-constrained devices. Attackers present victims with a deceptive verification page, tricking them into authorizing an attacker-controlled gadget rather than stealing their password directly.
Once initial access is achieved, the platform ensures persistence through a specialized browser extension called ForgCookie. Compatible with Microsoft Edge, Google Chrome, and Brave, this extension operates silently to request account data, clear session cookies, and trigger a hidden OAuth flow to capture fresh tokens. Doing so grants attackers continuous access to the victim’s Microsoft services without requiring them to ever re-authenticate.
To protect its administration panel from being accessed by security defenders, Forg365 integrates robust anti-analysis features. The platform utilizes debugger traps, polymorphic code, and dynamic sandbox checks to evade detection, redirecting connections to innocuous websites whenever a VPN is detected.
Administrators can defend against these hijacking techniques by monitoring Microsoft Entra logs for unexpected device-code authentication events. Organizations can also restrict or entirely disable device-code flows unless absolutely necessary. In the event of a suspected compromise, security teams should revoke all OAuth grants and refresh session tokens to sever access.
The Ugly | Rival Espionage Actors Breach & Spy On Pakistani Law Enforcement Networks
Between February 2024 and April 2026, suspected state-sponsored threat actors based in China and India separately converged on several Pakistani law enforcement organizations in unrelated cyberespionage campaigns.
According to SentinelLABS, operators heavily targeted the Balochistan Police, compromising critical network appliances and web servers. By infiltrating these critical systems, both nations actively sought independent visibility into Pakistan’s internal security posture and ongoing counter-militancy operations.
The China-nexus intrusions, leveraging PlugX, ShadowPad, and Cobalt Strike malware, were likely driven by Beijing’s concerns over the safety of Chinese nationals working on regional infrastructure projects within the China-Pakistan Economic Corridor (CPEC). Ongoing terrorist attacks have left the Chinese government dissatisfied with Pakistani protection and data from Balochistan Police would give the PRC direct insights.
Conversely, the India-nexus activity utilized Remcos backdoors to gather intelligence on the restive Balochistan province, a recurring flashpoint in the adversarial relationship between the two countries. Control over Balochistan Police networks means having invaluable visibility on how Pakistan manages their security posture as well as persistent access to civilian data.
Timeline of C2 traffic to Pakistani law enforcement organizations (Source: SentinelLABS)
One China-aligned threat actor specifically compromised the Balochistan Police Force’s Complaint Management System (CMS), a web application that actively serves both law enforcement personnel and Pakistani civilian users. The attackers uploaded custom malware implants disguised as routine portal updates, effectively weaponizing the digitalization of public policing services.
One payload masqueraded as a legitimate component of endpoint security software to evade initial detection and deploy an AsyncRAT client in order to establish persistent footholds into internal police networks while simultaneously surveilling citizens utilizing the platform.
This multi-actor convergence highlights how modernized policing infrastructure can serve as a high-value intelligence target for rival nations seeking comprehensive regional data.
This week Jonathan chats with Andrea Gallo about RISC-V! What does it mean for RISC-V to be an Open ISA? Where is RISC-V popping up, and what’s the new frontier? Watch to find out!
Did you know you can watch the live recording of the show right on our YouTube Channel? Have someone you’d like us to interview? Let us know, or have the guest contact us! Take a look at the schedule here.
Get caught up on the latest technology and startup news from the past week. Here are the most popular stories on GeekWire for the week of June 28, 2026.
GeekWire spoke with several longtime Microsoft employees who are taking the company’s first-ever voluntary retirement program, about why they decided to leave and what they’re doing next. … Read More
The group includes leaders from technology, aerospace, organized labor, higher education, tribal governments, ports and economic development organizations who will advise the governor on policies aimed at strengthening Washington’s economy. … Read More
“Microsoft Frontier Company” is a $2.5 billion initiative that will embed engineers inside customer organizations to build and run their AI systems. … Read More
Nick Parker, a 26-year Microsoft veteran who led its worldwide commercial sales business, is joining Nvidia as executive vice president of worldwide field operations, succeeding retiring sales chief Jay Puri. … Read More
Microsoft is preparing another round of layoffs, spanning Xbox, sales and consulting, as it holds down operating costs while pouring more than $100 billion into AI infrastructure. … Read More
Amazon Music names VP of product and tech; Microsoft’s corporate VP of Security, Compliance, Identity, Management & Privacy steps down while its Copilot platform undergoes a shakeup; Veeam appoints a chief marketing and customer AI officer; and Read More… Read More
The company said it eventually envisions its Bellevue office growing into a core edge AI research and development center with more than 500 employees over the next decade. … Read More
The maker of the Claude AI model recently finalized a lease at Dexter Yard North in Seattle’s South Lake Union neighborhood, capping months of speculation about the company’s expansion plans in the region. … Read More
The Good | Authorities Apprehend Iranian Cybercriminal & Extradite UNC3944 Hacker
Montenegrin law enforcement, alongside the FBI, have apprehendeda 39-year-old dual Iranian and Turkish citizen wanted by the U.S. government for several cybercrime offenses. Arrested in Kotor, the suspect faces charges in the Southern District Court of New York for conspiracy to commit computer fraud, hacking, and identity theft.
Since 2013, this individual allegedly orchestrated mass cyberattacks against more than 150 American universities and inflicted damages estimated at over $3.4 billion. Investigators say the stolen data and compromised academic credentials directly benefited the Islamic Revolutionary Guard Corps and various Iranian state entities. The case now proceeds to a High Court judge for formal extradition hearings. The arrest follows recent warnings from U.S. cybersecurity agencies regarding escalating Iranian state-sponsored operations targeting critical domestic infrastructure.
A 19-year-old dual United States and Estonian citizen, Peter Stokes, has been extraditedto face federal charges for his role as a core member of the UNC3944 (aka Scattered Spider, oktapus) cybercrime syndicate. Finnish authorities initially apprehended Stokes at the Helsinki airport as he attempted to board a flight to Japan. Prosecutors are accusing him of orchestrating multiple high-profile corporate breaches, using intense social engineering tactics against IT helpdesks to bypass multi-factor authentication controls.
Source: U.S. DoJ
In one notable May 2025 incident, UNC3944 compromised a multibillion-dollar retailer, demanding an $8 million ransom while inflicting over $2 million in operational disruption and remediation costs. UNC3944 operators are also responsible for more than 100 network intrusions globally, all of which yield upwards of $100 million in illicit extortion payments. Stokes remains in federal custody in Chicago, facing charges of fraud, conspiracy, and computer intrusion.
The Bad | Russian Intelligence Exploit Phishing Campaigns To Steal Signal Backup Keys
CISA and the FBI are warning that Russian state-sponsored threat actors have made large strides in evolving their phishing operations to target the backup recovery keys of Signal users. In an update to their March 2026 advisory, the two agencies attribute this ongoing activity to Russian Intelligence Services (RIS), including Russia’s Federal Security Service (FSB) Border Guards and the country’s military.
Tracked as UNC5792 and UNC4221, these campaigns specifically target high-value individuals, including government officials, military personnel, journalists, and policy analysts. Previously, operators focused on harvesting standard verification codes or tricking users into silently linking unauthorized devices. Now, they employ social engineering to access private communications without compromising the application’s underlying end-to-end encryption.
During targeted intrusions, attackers masquerade as official Signal support personnel and send direct messages falsely claiming the platform requires mandatory two-factor verification following alleged international cyberattacks. The operators systematically guide victims through the specific process of enabling the Secure Backups feature, instructing them to paste their newly generated recovery key directly into the chat interface.
Once adversaries obtain this critical key, they seamlessly download and decrypt the victim’s entire historical message archive onto their own controlled devices. Simply registering a new account under the same phone number does not natively invalidate a compromised key – users must actively generate a new backup key within their application settings to effectively secure future communications.
Source: U.S. Rewards for Justice Program
The U.S. Department of State recently announced a substantial reward of up to $10 million for information leading to the identification or location of these operatives. Through the Rewards for Justice program, federal authorities actively seek actionable intelligence regarding the syndicates’ operational infrastructure, illicit funding mechanisms, and direct affiliations with Russian intelligence services.
The Ugly | Unknown Hackers Breach Department of Homeland Security Information Network
The Department of Homeland Security is actively investigating a cyberattack that recently compromised its Homeland Security Information Network (HSIN). The network is an information sharing platform used by federal, state, local, and private-sector partners, specifically to share sensitive but unclassified data amongst the government and internationally.
According to an initial report, an unidentified threat actor orchestrated the intrusion between late May and early June. Investigators indicate that the attackers targeted the HSIN’s core servers alongside a SharePoint environment designed for extensive interagency collaboration.
Source: dhs.gov
While officials have not yet attributed the breach to a specific foreign government or syndicate, the full extent of data exposure remains unclear. The compromised platform routinely supports real-time incident management, intelligence exchange regarding persons of interest, and operational coordination. Because the United States is overseeing security for World Cup matches across the country, experts raise concerns that the intrusion could have exposed critical security planning, response procedures, and communication protocols.
In a public statement to the press, a departmental spokesperson confirmed the incident, clarifying that the breach strictly involved an unclassified legacy information-sharing environment. Security personnel promptly isolated the affected systems and mitigated the underlying vulnerability before starting forensics.
Officials emphasized that the attack did not impact classified networks, and the primary system remains operational for authorized partners. As the investigation continues, authorities strongly urge U.S. government staff, contractors, and associated partners to remain vigilant while defense teams harden the underlying infrastructure against further unauthorized network access attempts.
This week Jonathan chats with Andy Gryc and Aaron Basset about QNX, and the interesting Open Source history and future of that embedded OS. Why does QNX Everywhere feel more open, and why do you need to register an account to download images? All that and more — Watch to find out!
Did you know you can watch the live recording of the show right on our YouTube Channel? Have someone you’d like us to interview? Let us know, or have the guest contact us! Take a look at the schedule here.