Today in Surveillance:
- Hackers pulled a Flock camera off a roadway and walked away with its software. 404 Media and WIRED jointly reported on September 16 that the box contained about 21 days of vehicle captures, roughly 50,000 vehicles and around 1.6 million images, plus the on-device code that runs the network's plate, vehicle, bicycle, and people detection before upload [1][2].
- The Flock City PD story held the line as the second layer. 404 Media's Jason Koebler reported on September 17 that Flock accounts named "Flock City PD - Law Enforcement Demo," "Flock Intelligence," and "Flock Safety - Commercial Sales Demo" ran real ALPR and camera queries against Dunwoody, Georgia and Bryan, Texas residents on criteria including "Star of David" and "coexist bumper sticker" [3].
- The Guardian continued its Russia Max super-app investigation. The September 18 piece documents how VK's Max messenger is pre-installed on Russian handsets with no end-to-end encryption and FSB data channels built in [4][5].
- The Register reported on iFlytek AI in a US-controlled Venezuela. The Australian Strategic Policy Institute called Venezuela "one of the first countries outside China to import China's new generation of LLM-based AI systems for surveillance and control" [6].
- EFF criticized Meta's age-assurance settlement for forcing face scans and government IDs on youth users. The September 16 post argues the deal expands biometric data collection on minors and exposes activists to warrants [7][8].
- Google disclosed a zero-click Pixel baseband exploit. CVE-2026-58704 bypasses permission checks with no user interaction; CISA added it to its Known Exploited Vulnerabilities Catalog on September 16 with a three-day patch deadline for federal agencies [9].
- A four-country advisory tied North Korea's WaterPlum to more than 30,000 infected devices. The Register's September 18 piece cites the joint US-Australia-Germany-Japan advisory, including more than 7,000 compromised crypto wallets and over $10.71 million stolen [10].
- EFF published a statement on California's AI executive order. The September 18 post calls the order a starting point but argues policy must address concrete immediate harms (Flock cameras are named) rather than speculative frontier risks [11].
Continuing threads: The EFF and 404 Media audit-log pieces on Flock "LMAO," "IDK," and "asdfg" search reasons stayed in active discussion [12][13]. EFF's companion piece on police training to withhold ALPR and Stingray use from drivers and courts, including Houston officers told to "be as vague as permissible" and an Iowa county policy directing officers to describe Flock use as "county resources," continued to circulate [14]. 404 Media's Project Lily piece on OpenAI contractors reading real ChatGPT prompts continued to surface alongside the EFF Meta $17B settlement critique from September 3 [15][8].
Hackers Pulled a Flock Camera Off a Pole. Now the Tracking Code Is Public.
A group of hackers pulled a Flock Safety automatic license-plate-reader camera off a roadway, copied its data and software, and shared the files with 404 Media and WIRED. The September 16 joint investigation by Joseph Cox and Dhruv Mehrotra found roughly 21 days of camera data on the device, covering around 50,000 vehicles and about 1.6 million images, plus the camera software itself. The hackers told the reporters they intend to publish the methods so others can replicate them [1][2]. The site's Flock source-code vessel carries the full sourcing and the on-device software detail.
WIRED's preview of the joint piece confirmed the data scale and the hackers' replication plan: "The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them." Flock's response, as the article summarized it, was that unauthorized removal and tampering is illegal and that the reporters should have filed through the company's vulnerability disclosure policy rather than publishing the findings [1]. The framing matters: the camera, by Flock's own security posture, is a production system that the company argues should only be probed through a controlled channel. The hackers did not probe. They took the box.
The on-device code is the part that breaks the marketing. The camera's software, analyzed from the extracted files, includes detection code for vehicles, plates, bicycles, and people. The investigation reports no evidence of face recognition beyond unused Android defaults, but people-detection code is in the build. Flock's pitch to cities has been that the cameras capture "plates only." The on-device code includes people-detection, and the volume of images per camera, roughly 1.6 million over 21 days for one box, is the operating envelope the procurement contracts and the warrant bills are not pricing in [1][2].
Flock City PD Is the Moderation Layer on Top of the Stolen Box
404 Media's Jason Koebler reported on September 17 that Flock Safety operated accounts named "Flock City PD - Law Enforcement Demo," "Flock Intelligence," and "Flock Safety - Commercial Sales Demo" that ran real ALPR and camera queries against people and vehicles in Dunwoody, Georgia and Bryan, Texas, including by criteria that triggered Flock's own First Amendment safeguards. Searches logged in the demo environment included "coexist bumper sticker," "white truck with a trump sticker," "Star of David," "person wearing a mask," "crowd," "vehicle with a political sticker," "man holding rifle," "person in scrubs," "don't tread on me flag," "car that a pretty girl would drive," "vehicle with trump bumper sticker," "religious cars," "large group with signs," and "coexist number sticker" [3].
Flock's moderation layer let some of those queries through and blocked others. The article logs which prompts were allowed, warned, or blocked: "vehicle a pretty girl would drive" and "Star of David" (person) were blocked; "vehicle with trump bumper sticker," "don't tread on me flag," "coexist number sticker," "religious cars," and "Star of David" (vehicle) were warned; "crowd," "a person wearing scrubs," and "large group with signs" were allowed [3]. A Flock spokesperson told 404 Media that "Flock City PD is a demo and testing organization name used for law enforcement demonstrations and for our development engineers to conduct testing," that "the Flock City PD demo environment is now isolated, and law enforcement agencies cannot form a sharing relationship with it," and that "the safeguards we built are working" [3].
Read with the stolen-camera piece above and the audit-log stories from September 14, the picture is the same Flock network in three lights. The audit logs are the search layer. The City PD account is the moderation layer. The stolen camera is the device layer. The warrant-requirement bills in Colorado (SB 26-070) and the per-query audit logic EFF documented for cops hiding ALPR and Stingray use both assume the vendor is a passive data pipe [14]. The City PD account and the stolen camera are the proof that the vendor is also a query client and a software operator, which is what the network actually is.
Russia's Max Messenger Is Pre-Installed and Has No End-to-End Encryption
The Guardian published an investigation on September 18 into how VK's Max messenger operates on Russian phones as a state surveillance tool, with no end-to-end encryption and FSB data channels built in. The piece tracks the app's expansion from a VK product into a near-mandatory component on Russian handsets, and into the social-media and government-services bundle the state is using to replace Telegram, WhatsApp, and other platforms whose operators have refused to hand over encryption keys. The investigation builds on the Telegram-throttle-to-Max story this site covered in February, and the new piece is the next beat on the same network [4][5].
A messenger that the state can read by design is a state-collected communications record. A messenger that the state forces onto every handset is a state-collected communications record for every user, not just the users who chose to install it. The FSB data channels sit on top of that and convert a chat app into a continuous reporting pipeline. The practical question readers ask is "is Max safe?" and "can I delete it?" The honest answer for users inside Russia is no and no, and the practical answer for readers outside Russia is that the Max app ecosystem is the live demonstration of what a non-encrypted, state-integrated messenger looks like at national scale. The dual-use question is the through-line to the encryption-backdoor fight that the UK Online Safety Act and the EU chat-control proposals keep reopening.
A US-Controlled Venezuela Is Adopting iFlytek, the Chinese AI Vendor Washington Tried to Sanction
The Register's Simon Sharwood reported on September 18 that Venezuela under Delcy Rodríguez is adopting iFlytek, the Chinese AI vendor the United States tried to sanction in 2019 for its role in Uyghur repression in Xinjiang, for state surveillance and AI services. The Australian Strategic Policy Institute called Venezuela "one of the first countries outside China to import China's new generation of LLM-based AI systems for surveillance and control, and the most advanced adopter in the Western Hemisphere." ASPI also said "Beijing's approach seems to be, in part, strengthening oversight of state-owned assets abroad to assist in risk protection and management," and warned that "Chinese or other AI tools could strengthen a domestically directed apparatus already used to manage dissent, restrict information and preserve political power" [6].
The angle worth holding in view is the asymmetry. The same month Washington moved to sanction Anthropic's frontier models under export-control authority, a US-installed government is adopting a sanctioned Chinese vendor's AI for the same class of state surveillance work. The export-control regime treats the capability as a national-security question on one side of the ledger and a procurement choice on the other. This site's prior Venezuela phone-searches coverage tracks the underlying state apparatus; the new piece is the US-China tech-policy layer on top of it. The reader-relevant takeaway is that the iFlytek question is no longer contained to Xinjiang. It is the Western Hemisphere, by way of a US-backed government, on equipment and software Washington has itself identified as repression infrastructure.
EFF: Meta's Settlement Forces Face Scans and Government IDs on Youth Users
EFF's Paige Collings and Kenyatta Thomas published a post on September 16 arguing that the Meta settlement with 52 states and territories on Instagram and Facebook use by young people requires Meta (and pressures TikTok and YouTube) to embed age gating that expands biometric data collection on minors. The post is a companion to EFF's earlier criticism of the Meta age-assurance deal, and pushes on the same age-verification pillar the EFF $17B settlement post from September 3 covered [7][8].
EFF's frame: "Young people deserve a better internet than one regulated through panic." EFF writes that the deal "completely ignores the calls of youths themselves who favor digital literacy and education over surveillance and government control" and that "instead of tackling Meta's surveillance capitalism business model, this settlement gives the tech giant an opportunity to carve out a new digital world that prioritizes its own needs, not those of young people." On biometric collection, EFF writes that age estimation systems "misidentify or lock out people of color, people with disabilities, and trans or gender-nonconforming individuals," and that "for marginalized youth, social media can often be the only place to organize and build community." The through-line is the same one Cory Doctorow argued in June: every age-verification mandate builds an identity database that links a real person to specific platform activity, and that database is the surveillance prize.
Google Patched a Zero-Click Pixel Baseband Exploit and CISA Gave Agencies Three Days to Patch
The Register's Jessica Lyons reported on September 16 that Google disclosed a high-severity, zero-day improper-authorization vulnerability in Pixel phone cellular modems, tracked as CVE-2026-58704. The flaw bypasses permission checks and enables privilege escalation with no user interaction, the same delivery pattern commercial spyware vendors use. Google patched the bug in its September 2026 Pixel security bulletin. CISA added the CVE to its Known Exploited Vulnerabilities Catalog the same day, gave federal agencies three days to patch (deadline: September 19, 2026), and warned that the flaw "may be under limited, targeted exploitation" [9].
The Register also flagged two related Chromium V8 flaws (CVE-2026-85046, a type confusion flaw, and CVE-2026-87491, an out-of-bounds write) that enable remote code execution via crafted HTML pages and affect every Chromium-based browser. The chain is the standard one for commercial spyware: a zero-click baseband entry, paired with a browser-side escape, paired with a privilege escalation. The reader-side read is the same one this site has made since the iPhone NSO and Predator stories: the device you carry is the surveillance device, and the modem is the layer that is hardest to inspect and easiest to weaponize.
A Four-Country Advisory Tied North Korea's WaterPlum to More Than 30,000 Infected Devices
The Register's Connor Jones reported on September 18 that a joint advisory from agencies in the United States, Australia, Germany, and Japan tied North Korea's WaterPlum cyber group to more than 30,000 infected devices, more than 7,000 compromised cryptocurrency wallets, and over $10.71 million stolen, with proceeds funneled to Pyongyang. The targets were web designers, engineers, and cryptocurrency and Web3 specialists, recruited through bogus coding tests and recruitment files that install remote-access Trojans and information-stealers [10].
The Register also reported a separate North Korea IT-worker fraud scheme that nets the regime roughly $500 million a year, with an estimated 100,000 North Korean IT workers employed or seeking work worldwide. The surveillance angle is the dual-use tradecraft. The same operation that extracts crypto and IDs from a developer also produces identity documents, résumés, and remote-hire presence that DPRK workers use to place themselves inside Western companies. The IDs harvested in the recruiter campaign become the IDs the IT-worker campaign uses to pass background checks.
EFF: California's AI Executive Order Is a Starting Point, Not a Finish Line
EFF's Rindala Alajaji, Tori Noble, Jacob Hoffman-Andrews, and Hayley Tsukayama published a statement on September 18 on California Governor Gavin Newsom's AI executive order. The order addresses "loss-of-control incidents" and expands reporting requirements under SB 53 (2025), with third-party investigations and potential "kill switch" mechanisms. EFF calls the order "a good start" but says policy must be developed "in collaboration with those most at risk of harm" [11].
EFF's framing is the priority argument: "true safety requires California to focus on concrete, immediate, and urgent harms of AI technologies" rather than "sci-fi scenarios concerning rogue super-intelligence." The concrete harms EFF lists are biased algorithmic decision-making (employment, government benefits), AI-powered surveillance (Flock cameras are named), artificially inflated personalized pricing, and the risk such tools enable "retaliation against protected speech." The hierarchy of harms EFF proposes puts present-day AI surveillance and identity systems ahead of speculative frontier risks. The user's stake is the same as it has been: every AI-policy fight that names "kill switches" and "loss of control" as the headline risk leaves the present-day surveillance layer ungoverned.
What to Watch This Week
The published Flock playbook. Watch for the hackers' own documentation of how the camera was extracted and what they found inside. The investigation says the methods will be published. That publication is the moment the threat model for every Flock camera changes from "your data might leak" to "anyone with a ladder and a laptop can pull this and see" [1][2].
Flock City PD account audit. Watch whether Flock publishes an audit of every query that ran through the "Flock City PD - Law Enforcement Demo," "Flock Intelligence," and "Flock Safety - Commercial Sales Demo" accounts, including which jurisdictions the queries returned data on and what happened to the data after the demo. The "safeguards we built are working" statement is a forward-looking claim, and the question on the record is what the safeguards did before they were activated [3].
Russia Max pre-installation enforcement. Watch whether Russia's communications regulator escalates the pre-installation requirement to additional handset vendors, and whether any vendor declines. The Max pre-installation is the structural surveillance lever; the FSB data channels are the operational one. Either can be widened without changing the other [4].
iFlytek response and ASPI follow-up. Watch whether iFlytek, the Venezuelan government, or the State Department respond to the ASPI report. The export-control regime treats iFlytek as a sanctioned entity on one side and a procurement partner on the other; the regulatory answer has to address both [6].
EFF California EO follow-up. Watch whether the next round of California AI implementing guidance picks up EFF's hierarchy-of-harms framing, and whether the biometric-inference rules scheduled to phase in under the EU AI Act high-risk compliance deadline move on the same priority argument [11].
Sources
- 404 Media, Joseph Cox and Dhruv Mehrotra: Hackers Stole Flock's Camera Software, Revealing How the Company Tracks Cars and People (September 16, 2026). https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2/
- WIRED: Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works (September 16, 2026). https://www.wired.com/story/hackers-flock-camera-data-shows-how-system-works/
- 404 Media, Jason Koebler: Flock City PD: The Fake, Flock-Owned Police Department That Searched Real Cameras for Real People (September 17, 2026). https://www.404media.co/flock-city-pd-the-fake-flock-owned-police-department-that-searched-real-cameras-for-real-people/
- The Guardian: Russia's Max super-app: how the messenger became a tool for the state to spy on its citizens (September 18, 2026). https://www.theguardian.com/world/2026/sep/18/russian-super-app-max-spy-citizens
- State of Surveillance: Russia Is Throttling Telegram to Push Max, the Site's February 2026 coverage of the Telegram-to-Max migration. /news/russia-telegram-throttle-max-surveillance-app-2026
- The Register, Simon Sharwood: USA's Venezuela Takeover Comes with Bonus Exposure to Chinese AI Surveillance Tech (September 18, 2026). https://www.theregister.com/security/2026/09/18/usas-venezuela-takeover-comes-with-bonus-exposure-to-chinese-ai-surveillance-tech/5297357
- Electronic Frontier Foundation, Paige Collings and Kenyatta Thomas: Meta Settlement Yet Another Example of Online Youth Organizing Under Threat (September 16, 2026). https://www.eff.org/deeplinks/2026/09/meta-settlement-yet-another-example-online-youth-organizing-under-threat
- State of Surveillance: EFF Meta's $17B Settlement Is a Bad Deal for Teens, the brief on EFF's earlier age-assurance critique. /news/eff-meta-17-billion-settlement-age-assurance-surveillance-2026
- The Register, Jessica Lyons: Google Pixel Phones Pwned in Zero-Click Attacks (September 16, 2026). https://www.theregister.com/security/2026/09/16/google-pixel-phones-pwned-in-zero-click-attacks/5296936
- The Register, Connor Jones: North Korea's Fake Job Interviews Infected 30,000 Devices (September 18, 2026). https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30000-devices/5297461
- Electronic Frontier Foundation, Rindala Alajaji, Tori Noble, Jacob Hoffman-Andrews and Hayley Tsukayama: EFF Statement on California Governor's Executive Order on AI (September 18, 2026). https://www.eff.org/deeplinks/2026/09/eff-statement-california-governors-executive-order-ai
- State of Surveillance: Flock ALPR Audit Logs Show Cops Typing 'LMAO' and 'asdfg', the September 16 brief on the EFF and 404 Media audit-log pieces. /news/flock-alpr-audit-logs-lmao-asdfg-reason-field-2026
- 404 Media, Jason Koebler: Cops Search Thousands of Flock Cameras for Reasons of 'LMAO,' 'IDK,' 'Hehe,' and 'asdfg' (September 14, 2026). https://www.404media.co/cops-search-thousands-of-flock-cameras-for-reasons-of-lmao-idk-hehe-and-asdfg/
- State of Surveillance: EFF Cops Hide ALPR, Stingray, and Face-Recognition Use From Courts, the brief on the September 14 EFF companion piece. /news/eff-cops-hide-alpr-stingray-facial-recognition-courts-2026
- 404 Media, Joseph Cox: Inside 'Project Lily': The Humans Reading Your ChatGPT Chats (September 14, 2026). https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/