Skip to content
Tech News
← Back to articles

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

read original more articles

It’s Black Hat and DefCon week, which means hackers, security researchers, cybersecurity companies, government officials, and probably a few feds are in Vegas braving the heat to break things and show off what they’ve been working on. WIRED is there covering the best of it.

Let’s get into it. Last month, OpenAI disclosed that a swarm of its AI agents went on a hacking spree that ended with a breach of Hugging Face. This week brought even more rogue-agent incidents—and, at a last-minute Black Hat talk, a bizarre new detail emerged about how some of this unfolded. OpenAI revealed that its agents had built their own internal message board, where they shared exploits, divided up work, argued, and even discussed cryptographically signing messages to weed out imposters—all without OpenAI noticing for days.

Separately, researchers at Zenity found around 20 flaws across AI-powered browsers and extensions, including attacks that got OpenAI’s Atlas browser to spam WhatsApp contacts and make an unauthorized Amazon purchase. And security researcher James Kettle found that while AI agents are still pretty bad at inventing new hacking techniques on their own, when paired with a human expert they can be extremely effective.

Security researcher Vangelis Stykas had a busy week at BlackHat. He and a colleague hacked a cheap kid’s smartwatch strapped to a WIRED reporter’s wrist, tracking them across New York, secretly taking photos, and eavesdropping on conversations—part of a broader investigation into flaws affecting tens of millions of kids’ watches and car trackers. Stykas also revealed that, after nearly two years secretly monitoring North Korean hackers’ servers, he found evidence their operations touched 1,640 companies across 57 countries, with hundreds suffering serious intrusions.

Outside of Las Vegas, the world keeps turning. Meta approved and ran more than 50 paid ads containing AI-generated child sexual abuse imagery or sexually suggestive images of minors across Facebook, Instagram, Messenger, and Threads, with some reaching thousands of people. The US Army is poised to make laser weapons an official part of its arsenal, buying up to 20 systems designed to shoot down drones.

Meanwhile, DHS also had a busy week. WIRED found that the government is trying to get access to protesters’ private Signal group chats; CBP is looking to hire private investigators to track down deported immigrants abroad, photograph their homes, and pursue unpaid fines; and DHS has been collecting migrant’s spit—and their DNA—at a staggering scale, including from children as young as 4.

And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

Flock Safety pitched a plan to collect license plate data from dashcams in Uber, Lyft, and delivery drivers’ vehicles, according to 404 Media, which obtained the sales presentation through a public records request filed by a Dunwoody, Georgia, resident. The document, prepared last August for the Georgia Attorney General's Office, describes a partnership with dashcam maker Nexar covering 350,000 devices. Flock's cameras are normally fixed to poles and scan the plate, color, make, and model of every car that passes; the Nexar deal would have turned it into a roving collection.

Flock told 404 Media it never went through with the partnership. Uber, Lyft, and Nexar did not respond to the site’s requests for comment, and there is no indication drivers would have known their cameras were feeding the network. Nexar was itself breached in September, when a hacker pulled terabytes of customer video that included footage shot around Defense Department sites.