Today in Surveillance:

  • Flock ran a fake police department that searched its own cameras against real people. 404 Media's Jason Koebler reported September 17 that Flock accounts named "Flock City PD - Law Enforcement Demo," "Flock Intelligence," and "Flock Safety - Commercial Sales Demo" ran real ALPR and camera queries against Dunwoody, Georgia and Bryan, Texas residents, on criteria including "Star of David," "coexist bumper sticker," and "vehicle a pretty girl would drive" [1].
  • The Guardian investigated how Russia's VK Max messenger works as state surveillance. Max is pre-installed and increasingly mandatory on Russian phones, has no end-to-end encryption, and includes FSB data channels by design, building on the Telegram-to-Max throttle story this site covered in February [2][3].
  • A US-controlled Venezuela is adopting iFlytek for state surveillance. The Register reported that Delcy Rodríguez's government is deploying the same Chinese AI vendor Washington tried to sanction in 2019 for Uyghur repression, with the Australian Strategic Policy Institute calling Venezuela the most advanced Western Hemisphere adopter [4].
  • The Guardian reported UK police systems are vulnerable to compromise by US agencies and foreign states. The piece lands on the transatlantic-data-sharing question that has run through the year on the CLOUD Act and the UK-US data bridge [5].
  • EFF criticized the Meta age-assurance settlement for forcing face scans and government IDs on youth users. The September 16 post argues the deal expands biometric collection on minors and exposes activists to warrants, while ignoring the youth who called for digital literacy over surveillance [6].
  • Google disclosed a zero-click Pixel baseband exploit and CISA added it to the exploited-vulns catalog. CVE-2026-58704 bypasses permission checks with no user interaction, was patched in the September 2026 Pixel bulletin, and gives federal agencies three days to patch [7].
  • Georgia State University rescinded a TA job offer after a DHS phone-wipe prosecution. Activist Samuel Tunick, a Stop Cop City organizer, was stopped at a US airport in January 2025 after officials called ahead; he triggered GrapheneOS's duress wipe before CBP could search the device [8].
  • EFF published a statement on California's AI executive order. The September 18 piece calls the order a starting point but flags concrete, immediate AI harms (biased decisioning, AI-powered surveillance such as Flock, inflated personalized pricing) ahead of speculative kill-switch risks [9].
  • A four-country advisory tied North Korea's WaterPlum to more than 30,000 infected devices. The Register reported the joint US-Australia-Germany-Japan advisory, including more than 7,000 crypto wallets compromised and over $10.71 million stolen [10].

Continuing threads: The EFF companion piece on police training to withhold ALPR and Stingray use from drivers and courts stayed in active discussion [11]. EFF's and 404 Media's audit-logs pieces on Flock "LMAO," "IDK," and "asdfg" search reasons held attention [12][13]. 404 Media's Project Lily piece on OpenAI contractors reading real ChatGPT prompts continued to circulate, with the 900 million-user figure from the September 14 story [14]. The EFF September 14 piece on Meta's $17B settlement, the EFF September 14 piece on cops hiding spy tech, and the EFF Meta age-assurance piece below are all part of the same age-verification and biometric-ID cluster [15].

Flock Ran a Fake Police Department That Searched Its Own Cameras Against Real People

404 Media's Jason Koebler reported on September 17 that Flock Safety operated accounts named "Flock City PD - Law Enforcement Demo," "Flock Intelligence," and "Flock Safety - Commercial Sales Demo" that ran real ALPR and camera queries against people and vehicles in Dunwoody, Georgia and Bryan, Texas, including by criteria that triggered Flock's own First Amendment safeguards. Searches logged in the demo environment included "coexist bumper sticker," "white truck with a trump sticker," "Star of David," "person wearing a mask," "crowd," "vehicle with a political sticker," "man holding rifle," "person in scrubs," "don't tread on me flag," "car that a pretty girl would drive," "vehicle with trump bumper sticker," "religious cars," "large group with signs," "coexist number sticker," and "vehicle a pretty girl would drive" [1].

Flock's moderation layer let some of those queries through and blocked others. The article logs which prompts were allowed, warned, or blocked: "vehicle a pretty girl would drive" and "Star of David" (person) were blocked; "vehicle with trump bumper sticker," "don't tread on me flag," "coexist number sticker," "religious cars," and "Star of David" (vehicle) were warned; "crowd," "a person wearing scrubs," and "large group with signs" were allowed [1]. A Flock spokesperson told 404 Media that "Flock City PD is a demo and testing organization name used for law enforcement demonstrations and for our development engineers to conduct testing," that "the Flock City PD demo environment is now isolated, and law enforcement agencies cannot form a sharing relationship with it," and that "the safeguards we built are working" [1].

Jason Hunyar, the Dunwoody resident who originally discovered Flock's camera access, told 404 Media that "their willingness to continuously monitor and catalogue the actions of law abiding citizens exercising their constitutionally protected rights should worry anyone who plans to exercise them now or in the future" [1]. Read alongside the EFF and 404 Media audit-log stories on Flock search reasons of "LMAO," "IDK," and "asdfg," the picture is the same network doing the same work. The vendor-as-cop story and the cop-as-vendor story are not separate stories. Flock is the network, the demo account, and the moderation layer in one. The warrant-requirement bills in Colorado (SB 26-070) and the per-query audit logic EFF documented for cops hiding ALPR and Stingray use [11] both assume the vendor is a passive data pipe. The City PD account is the proof that the vendor is also a query client.

Russia's Max Messenger Is Pre-Installed and Has No End-to-End Encryption

The Guardian published an investigation on September 18 into how VK's Max messenger operates on Russian phones as a state surveillance tool, with no end-to-end encryption and FSB data channels built in. The piece tracks the app's expansion from a VK product into a near-mandatory component on Russian handsets, and into the social-media and government-services bundle the state is using to replace Telegram, WhatsApp, and other platforms whose operators have refused to hand over encryption keys. The investigation builds on the Telegram-throttle-to-Max story this site covered in February, and the new piece is the next beat on the same network [2][3].

The surveillance angle is the absence of end-to-end encryption and the pre-installation. A messenger that the state can read by design is a state-collected communications record. A messenger that the state forces onto every handset is a state-collected communications record for every user, not just the users who chose to install it. The FSB data channels sit on top of that and convert a chat app into a continuous reporting pipeline. The practical question readers are asking is "is Max safe?" and "can I delete it?" The honest answer for users inside Russia is no and no, and the practical answer for readers outside Russia is that the Max app ecosystem is the live demonstration of what a non-encrypted, state-integrated messenger looks like at national scale. The dual-use question is the through-line to the encryption-backdoor fight that the UK Online Safety Act and the EU chat-control proposals keep reopening.

A US-Controlled Venezuela Is Adopting iFlytek, the Chinese AI Vendor Washington Tried to Sanction

The Register's Simon Sharwood reported on September 18 that Venezuela under Delcy Rodríguez is adopting iFlytek, the Chinese AI vendor the United States tried to sanction in 2019 for its role in Uyghur repression in Xinjiang, for state surveillance and AI services. The Australian Strategic Policy Institute called Venezuela "one of the first countries outside China to import China's new generation of LLM-based AI systems for surveillance and control, and the most advanced adopter in the Western Hemisphere." Sharwood cited the ASPI report "Warning signals: Venezuela and the risk of Chinese AI-enabled digital authoritarianism." ASPI's quote: "an agreement to adopt Chinese-built AI systems … to use Chinese AI to enhance existing state-sponsored surveillance." ASPI also said "Beijing's approach seems to be, in part, strengthening oversight of state-owned assets abroad to assist in risk protection and management," and warned that "Chinese or other AI tools could strengthen a domestically directed apparatus already used to manage dissent, restrict information and preserve political power" [4].

The angle worth holding in view is the asymmetry. The same month Washington moved to sanction Anthropic's frontier models under export-control authority, a US-installed government is adopting a sanctioned Chinese vendor's AI for the same class of state surveillance work. The export-control regime treats the capability as a national-security question on one side of the ledger and a procurement choice on the other. This site's prior Venezuela phone-searches coverage tracks the underlying state apparatus; the new piece is the US-China tech-policy layer on top of it. The reader-relevant takeaway is that the iFlytek question is no longer contained to Xinjiang. It is the Western Hemisphere, by way of a US-backed government, on equipment and software Washington has itself identified as repression infrastructure.

The Guardian: UK Police Case Data Is Vulnerable to Compromise by US Agencies and Foreign States

The Guardian published a separate investigation on September 18 arguing that UK police systems containing sensitive case data are vulnerable to compromise by US agencies and foreign states. The piece sits on the transatlantic-data-sharing question this site has tracked since the UK's data bridge with the US, the CLOUD Act, and the Schrems II line of decisions. Sensitive UK policing data has been reachable from the United States for years through a combination of UK cloud-provider contracts, mutual legal assistance treaties, and bilateral arrangements. The Guardian piece argues the exposure is structural, not accidental, and that the UK has not built the same kind of warrant and minimization controls the United States has begun to add to its own cross-border data flows [5].

The reader question is "what data the UK police hold on you and where it goes." The current answer is that sensitive case files, witness statements, and operational intelligence can sit on systems that are reachable, in law and in practice, from the United States and from allied foreign services, with the protections applied at the receiving end rather than at the data's origin. The piece is the data-sovereignty answer EFF argued earlier this month from the user-autonomy side, applied to a specific live system.

EFF: Meta's Settlement Forces Face Scans and Government IDs on Youth Users

EFF's Paige Collings and Kenyatta Thomas published a post on September 16 arguing that the Meta settlement with 52 states and territories on Instagram and Facebook use by young people requires Meta (and pressures TikTok and YouTube) to embed age gating that expands biometric data collection on minors. The post is a companion to EFF's earlier criticism of the Meta age-assurance deal, and pushes on the same age-verification pillar the EFF $17B settlement post from September 3 covered [6][15].

EFF's frame: "Young people deserve a better internet than one regulated through panic." EFF argues the deal "completely ignores the calls of youths themselves who favor digital literacy and education over surveillance and government control" and that "instead of tackling Meta's surveillance capitalism business model... this settlement gives the tech giant an opportunity to carve out a new digital world that prioritizes its own needs, not those of young people." On biometric collection, EFF writes that age estimation systems "misidentify or lock out people of color, people with disabilities, and trans or gender-nonconforming individuals," and that "for marginalized youth... social media can often be the only place to organize and build community." EFF also flags that Instagram's content filter has hidden posts referencing LGBTQ+ hashtags (#lesbian, #bisexual, #gay, #trans, #queer) [6]. The through-line is the same one Cory Doctorow argued in June: every age-verification mandate builds an identity database that links a real person to specific platform activity, and that database is the surveillance prize.

Google Patched a Zero-Click Pixel Baseband Exploit and CISA Gave Agencies Three Days to Patch

The Register's Jessica Lyons reported on September 16 that Google disclosed a high-severity, zero-day improper-authorization vulnerability in Pixel phone cellular modems, tracked as CVE-2026-58704. The flaw bypasses permission checks and enables privilege escalation with no user interaction, the same delivery pattern commercial spyware vendors use. Google patched the bug in its September 2026 Pixel security bulletin. CISA added the CVE to its Known Exploited Vulnerabilities Catalog the same day, gave federal agencies three days to patch (deadline: September 19, 2026), and warned that the flaw "may be under limited, targeted exploitation" [7].

The Register also flagged two related Chromium V8 flaws (CVE-2026-85046, a type confusion flaw, and CVE-2026-87491, an out-of-bounds write) that enable remote code execution via crafted HTML pages and affect every Chromium-based browser. The chain is the standard one for commercial spyware: a zero-click baseband entry, paired with a browser-side escape, paired with a privilege escalation. The reader-side read is the same one this site has made since the iPhone NSO and Predator stories: the device you carry is the surveillance device, and the modem is the layer that is hardest to inspect and easiest to weaponize.

Georgia State Rescinded a TA Offer After a DHS Phone-Wipe Prosecution

404 Media's Joseph Cox reported on September 17 that Georgia State University rescinded a Teaching Assistant job offer to activist Samuel Tunick six hours before he was to start on August 25. Tunick had been accepted into an M.S. of Geosciences program with tuition waiver and wages. The university denied his hire through an automated email saying he had failed a required background check. The denial was approved by the "Background Check Committee," the Dean of Students, and the legal department. Tunick had a dismissed misdemeanor in Fulton County. He participated in the Stop Cop City movement in Atlanta [8].

According to the demand letter Cox reviewed, an airport encounter in January 2025 led to charges after Tunick allegedly wiped his GrapheneOS phone before CBP could search it. Tunick was returning from the Dominican Republic when DHS officials called ahead to have agents stop him. He provided a code to officers; the code triggered GrapheneOS's "duress" feature, which irreversibly wiped the device. Authorities had placed a tracker on Tunick's car and subpoenaed his cellphone records and Gmail data prior to the airport encounter [8].

Tunick's lawyer Matthew Dodge called it "an instance of textbook political repression, and a high profile civil liberties case." The demand letter demands reinstatement, transparency about the hiring process, and application of an "innocent until proven guilty" principle. The case is the live civil-side companion to the criminal prosecution: even where a charge is dismissed, the arrest record becomes the basis for downstream punishment by employers and universities [8].

EFF: California's AI Executive Order Is a Starting Point, Not a Finish Line

EFF's Rindala Alajaji, Tori Noble, Jacob Hoffman-Andrews, and Hayley Tsukayama published a statement on September 18 on California Governor Gavin Newsom's AI executive order. The order addresses "loss-of-control incidents" and expands reporting requirements under SB 53 (2025), with third-party investigations and potential "kill switch" mechanisms. EFF calls the order "a good start" but says policy must be developed "in collaboration with those most at risk of harm" [9].

EFF's framing is the priority argument: "true safety requires California to focus on concrete, immediate, and urgent harms of AI technologies" rather than "sci-fi scenarios concerning rogue super-intelligence." The concrete harms EFF lists are biased algorithmic decision-making (employment, government benefits), AI-powered surveillance (Flock cameras are named), artificially inflated personalized pricing, and the risk such tools enable "retaliation against protected speech" [9]. The hierarchy of harms EFF proposes puts present-day AI surveillance and identity systems ahead of speculative frontier risks. The user's stake is the same as it has been: every AI-policy fight that names "kill switches" and "loss of control" as the headline risk leaves the present-day surveillance layer ungoverned.

A Four-Country Advisory Tied North Korea's WaterPlum to More Than 30,000 Infected Devices

The Register's Connor Jones reported on September 18 that a joint advisory from agencies in the United States, Australia, Germany, and Japan tied North Korea's WaterPlum cyber group to more than 30,000 infected devices, more than 7,000 compromised cryptocurrency wallets, and over $10.71 million stolen, with proceeds funneled to Pyongyang. The targets were web designers, engineers, and cryptocurrency and Web3 specialists, recruited through bogus coding tests and recruitment files that install remote-access Trojans and information-stealers. The advisory warns that "stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," that stolen credentials "may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc.," and that "the actors can also use stolen sensitive information for extortion" [10].

The Register also reported a separate North Korea IT-worker fraud scheme that nets the regime roughly $500 million a year, with an estimated 100,000 North Korean IT workers employed or seeking work worldwide. The surveillance angle is the dual-use tradecraft. The same operation that extracts crypto and IDs from a developer also produces identity documents, résumés, and remote-hire presence that DPRK workers use to place themselves inside Western companies. The IDs harvested in the recruiter campaign become the IDs the IT-worker campaign uses to pass background checks.

What to Watch This Week

Flock City PD account audit. Watch whether Flock publishes an audit of every query that ran through the "Flock City PD - Law Enforcement Demo," "Flock Intelligence," and "Flock Safety - Commercial Sales Demo" accounts, including which jurisdictions the queries returned data on and what happened to the data after the demo. The "safeguards we built are working" statement is a forward-looking claim, and the question on the record is what the safeguards did before they were activated [1].

Russia Max pre-installation enforcement. Watch whether Russia's communications regulator escalates the pre-installation requirement to additional handset vendors, and whether any vendor declines. The Max pre-installation is the structural surveillance lever; the FSB data channels are the operational one. Either can be widened without changing the other [2].

iFlytek response and ASPI follow-up. Watch whether iFlytek, the Venezuelan government, or the State Department respond to the ASPI report. The export-control regime treats iFlytek as a sanctioned entity on one side and a procurement partner on the other; the regulatory answer has to address both [4].

Samuel Tunick reinstatement hearing. Watch whether Georgia State University responds to the demand letter Tunick filed through counsel. The reinstatement question is the live civil-side test of whether a dismissed arrest can be the basis for a rescinded job offer [8].

EFF California EO follow-up. Watch whether the next round of California AI implementing guidance picks up EFF's hierarchy-of-harms framing, and whether the biometric-inference rules scheduled to phase in under the EU AI Act high-risk compliance deadline move on the same priority argument [9].

Sources

  1. 404 Media, Jason Koebler: Flock City PD: The Fake, Flock-Owned Police Department That Searched Real Cameras for Real People (September 17, 2026). https://www.404media.co/flock-city-pd-the-fake-flock-owned-police-department-that-searched-real-cameras-for-real-people/
  2. The Guardian: Russia's Max super-app: how the messenger became a tool for the state to spy on its citizens (September 18, 2026). https://www.theguardian.com/world/2026/sep/18/russian-super-app-max-spy-citizens
  3. State of Surveillance: Russia Is Throttling Telegram to Push Max, the Site's February 2026 coverage of the Telegram-to-Max migration. /news/russia-telegram-throttle-max-surveillance-app-2026
  4. The Register, Simon Sharwood: USA's Venezuela Takeover Comes with Bonus Exposure to Chinese AI Surveillance Tech (September 18, 2026). https://www.theregister.com/security/2026/09/18/usas-venezuela-takeover-comes-with-bonus-exposure-to-chinese-ai-surveillance-tech/5297357
  5. The Guardian: Sensitive UK police data vulnerable to compromise by US government and foreign actors (September 18, 2026). https://www.theguardian.com/uk-news/2026/sep/18/sensitive-uk-police-data-vulnerable-to-compromise-by-us-government-and-foreign-actors
  6. Electronic Frontier Foundation, Paige Collings and Kenyatta Thomas: Meta Settlement Yet Another Example of Online Youth Organizing Under Threat (September 16, 2026). https://www.eff.org/deeplinks/2026/09/meta-settlement-yet-another-example-online-youth-organizing-under-threat
  7. The Register, Jessica Lyons: Google Pixel Phones Pwned in Zero-Click Attacks (September 16, 2026). https://www.theregister.com/security/2026/09/16/google-pixel-phones-pwned-in-zero-click-attacks/5296936
  8. 404 Media, Joseph Cox: University Rescinds Job Offer to Activist Who Allegedly Wiped Phone Before DHS Could Search It (September 17, 2026). https://www.404media.co/university-rescinds-job-offer-to-activist-who-allegedly-wiped-phone-before-dhs-could-search-it/
  9. Electronic Frontier Foundation, Rindala Alajaji, Tori Noble, Jacob Hoffman-Andrews and Hayley Tsukayama: EFF Statement on California Governor's Executive Order on AI (September 18, 2026). https://www.eff.org/deeplinks/2026/09/eff-statement-california-governors-executive-order-ai
  10. The Register, Connor Jones: North Korea's Fake Job Interviews Infected 30,000 Devices (September 18, 2026). https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30000-devices/5297461
  11. State of Surveillance: EFF Cops Hide ALPR, Stingray, and Face-Recognition Use From Courts, the brief on the September 14 EFF companion piece. /news/eff-cops-hide-alpr-stingray-facial-recognition-courts-2026
  12. State of Surveillance: Flock ALPR Audit Logs Show Cops Typing 'LMAO' and 'asdfg', the September 16 brief on the EFF and 404 Media audit-log pieces. /news/flock-alpr-audit-logs-lmao-asdfg-reason-field-2026
  13. 404 Media, Jason Koebler: Cops Search Thousands of Flock Cameras for Reasons of 'LMAO,' 'IDK,' 'Hehe,' and 'asdfg' (September 14, 2026). https://www.404media.co/cops-search-thousands-of-flock-cameras-for-reasons-of-lmao-idk-hehe-and-asdfg/
  14. 404 Media, Joseph Cox: Inside 'Project Lily': The Humans Reading Your ChatGPT Chats (September 14, 2026). https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/
  15. State of Surveillance: EFF Meta's $17B Settlement Is a Bad Deal for Teens, the brief on EFF's earlier age-assurance critique. /news/eff-meta-17-billion-settlement-age-assurance-surveillance-2026