A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock’s system, it was just recorded as 34 DTM. Just the five large characters, no little number in the m

Flock Safety, a company providing automated license plate recognition (ALPR) cameras to law enforcement agencies, has faced scrutiny following an incident where a journalist was mistakenly identified and arrested due to a partial plate match. The incident involved a Jaguar Land Rover (JLR) media fleet vehicle with a New Jersey manufacturer plate, 34 10 DTM, which was flagged as stolen. The original police report for a different stolen vehicle listed the plate as 34 03 DTM. However, when entered into Flock's system, it was recorded simply as "34 DTM," omitting the two-digit number in the middle.
Flock's artificial intelligence system subsequently identified the journalist's vehicle, which bore the plate 34 10 DTM, as a match for the "34 DTM" entry. The company affirmed that its systems functioned as designed, stating that the machine learning correctly read the characters it was instructed to find. A company spokesperson explained that even if the "10" had been standard size, the system would still have flagged it, as it is configured to alert law enforcement if any of the characters on a "hot list" are read. This design choice is intended to accommodate situations where officers may only have partial plate information. The spokesperson emphasized that officers are trained to verify full plate numbers before taking action.
The journalist's experience revealed a broader issue: many JLR media fleet vehicles share a similar New Jersey manufacturer plate structure, 34 ## DTM. An officer involved in the incident noted that this could lead to other JLR vehicles with this structure being incorrectly flagged as stolen nationwide wherever Flock cameras are deployed. Indeed, four other 34 ## DTM vehicles were reportedly being tracked in Minnesota during the same week. JLR is reportedly working with the Los Angeles Police Department (LAPD) to correct the initial report and update Flock's system to prevent further erroneous flagging.
In addition to the ALPR system's matching logic, Flock Safety has also addressed past controversies. The company's CEO issued an apology for previously referring to privacy advocates as "terrorists."
Beyond vehicle tracking, police departments have reportedly utilized Flock camera networks to search for individuals based on physical descriptions or attire, rather than just vehicle information. Examples of such searches include "heavy-set male with a black and white hat," "person on skateboard," and "person wearing orange vest and construction hat." Some searches have also reportedly referenced a target's race or signs of political affiliation.

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as