Hackers from stegan0gram obtained filesystem images of Flock ALPR cameras and published them via DDoSecrets, revealing severe security vulnerabilities including obsolete Android 8.1 (no updates since 2021), outdated Linux kernel 3.18 (9+ years old), and hardcoded credentials. The cameras lack patches for multiple known exploits including CVE-2021-1905 and CVE-2018-9568 that could grant full device control.
Hackers breached a Flock Safety traffic camera, extracted its data and encryption keys, and shared findings with media outlets revealing the device tracks vehicles, people, license plates, and bicycles with computer vision software. The breach exposes how Flock's cameras feed searchable data to a national network accessible by thousands of agencies, a system that has drawn controversy over surveillance and misuse by law enforcement.
Hackers breached a Flock Safety traffic camera, extracted its data and encryption key, and shared findings with 404 Media and WIRED revealing the system tracks vehicles, people, license plates, and bicycles in detail. The disclosure exposes how Flock's cameras feed into a national network accessible to thousands of agencies, raising privacy concerns about widespread surveillance and misuse by law enforcement.