CEO apologizes for police misuse as activists call for vandal action against license plate cameras

Flock, a company specializing in automated license plate recognition (ALPR) technology, is facing renewed scrutiny and calls for vandalism against its camera network, coinciding with an apology from its CEO regarding system misuse. Social media campaigns are encouraging individuals to disable Flock ALPRs on Halloween 2026, with the "De-Flock America" movement gaining significant traction across platforms, including over 36,500 posts on X within a two-day period.
The calls for action follow a series of controversies surrounding Flock's technology, including reports of U.S. Immigration and Customs Enforcement (ICE) agents accessing local police data without direct contracts, and instances of law enforcement officers allegedly misusing the system to stalk individuals. These incidents have also been accompanied by an increase in physical attacks on Flock cameras.
Flock CEO Garrett Langley publicly apologized after a woman was reportedly stalked using the company's ALPR system. This apology came less than two weeks after a major publication detailed 46 cases of alleged abuse by U.S. police officers accessing Flock's system, some of which involved stalking.
In response to these concerns, Flock announced several changes to its policies and features. The standard data retention period for its ALPR data has been reduced from 30 days to seven days, though customers can opt for longer retention for specific casework through a new "Evidence Mode." The company also introduced controls allowing law enforcement agencies to restrict the types of searches that external forces can conduct on their data, specifically mentioning the ability to block searches related to "immigration enforcement."
Additionally, Flock will make its existing Audit Assistance feature mandatory for all customers by the end of the year. This tool is designed to detect and flag unusual search activity, and the company states it has been linked to the arrests of several officers accused of system abuse. Currently, over a third of Flock's customers have voluntarily enabled this feature.
One specific case highlighted in recent reports involves Haines City police officer Christopher Goodson, 31, who is alleged to have used Flock's system to search for his estranged wife's license plate 717 times between September 1, 2024, and June 30, 2026. Goodson has been suspended with pay pending further investigation into these claims.
Flock's media team, when contacted about the Halloween vandalism campaign, provided an automated response indicating they were on a break. The company has not publicly detailed any specific countermeasures it plans to implement against the proposed vandalism.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a