Feed aggregator
Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).
The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.
Proposed anti-Flock bills could spell trouble for license plate readers
Automated license plate readers (ALPRs) are cameras that photograph passing vehicles, read their number plates, and typically log the time, location, and vehicle details. On their own, the images might be used to find a stolen car or locate a suspect.
But lately there have been a lot of concerns raised about the way they are used. The main worry is caused by what happens when many cameras feed data into a shared, searchable network: it can create a detailed record of where ordinary people travel.
Some agencies have already taken it upon themselves to act on these concerns, as well as those around inaccuracy. Data errors can have serious consequences. At a recent Senate hearing, Florida resident Lindsey Isaacs described being arrested and held for 13 days after data from an AI-enabled plate-reader system incorrectly implicated her in a fatal car crash.
As a result of all this, US lawmakers from both major political parties have introduced proposals aimed at restricting automatic license plate reader networks.
Most of the reasons brought up are about Flock Safety, one of the largest suppliers of these systems in the United States, but they would apply more broadly to other ALPR vendors as well.
Flock says it deploys only 120,000 cameras operating across the country, while a researcher cited by the Senate described a much larger network of connected devices and cameras. The exact size may be disputed, but the central concern is clear: Data from a camera in one location can potentially be searched by an agency elsewhere.
Two different approachesReportedly, there are two different proposed laws in the making, while Flock says it supports a legal framework for license-plate readers and argues that the technology can improve public safety when it is used with strong oversight and accountability.
The first proposal, the Stop Flock Abuse Act, doesn’t aim to banish ALPR systems outright, it would create rules for how government agencies and vendors can use them.
Among other measures, the bill would require written approval and a record for every search, regular supervisor audits, encryption, and deletion of most vehicle-location data after ten days. It would also prohibit sharing or selling the data to non-governmental third parties, prevent ALPR networks from incorporating facial-recognition technology, and require data to stay in the US.
A second proposal, the Ban Flock Act, takes a much harder line. It would prohibit US federal agencies from using ALPRs or accessing data they collect. It would also withhold federal grant money from state and local governments that use ALPR systems and allow people to sue the federal government if their rights are violated through ALPR deployment.
Both bills are proposals, not enacted laws. In the US system, each would need to pass both the House of Representatives and the Senate in matching form, then be signed by the President.
Going forwardThere is no guarantee either bill will receive a vote, let alone become law. But their introduction shows that ALPR technology is moving from a local procurement issue to a national privacy and civil-liberties debate.
License plate data may seem less sensitive than phone-location data, but a long enough record can reveal a person’s routines, relationships, medical visits, religious activity, or attendance at protests. The debate is therefore not just about cameras on streets to fight crime and find criminals, it is about whether governments and private vendors should be able to build searchable records of everyday movement.
So for consumers, the key question is not only whether a camera is installed on a street or near a business. It is also how long the resulting data is retained, who can search it, whether those searches are logged and reviewed, whether the information can be shared beyond the original agency, and what recourse exists when the system is wrong or abused.
Your name, address, and phone number may already be for sale.
Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way.
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.
The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek.
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.
The post 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms appeared first on SecurityWeek.
Rather than viewing older datacentres as obsolete legacy assets, smart operators are unlocking commercial value by upgrading existing sites for AI and higher density
Cybergate CISO Srdjan Babic warns that organisations are adopting artificial intelligence faster than they are building the governance, oversight and workforce capabilities needed to manage it securely
Security visibility, segmentation and breach containment are becoming critical as organisations across the UAE and Saudi Arabia rush to deploy AI technologies
Gartner analysts explain when enterprises should focus on process mining and when they should use task mining
What's the point in AI saving hours of workers' time if there's no thought around what to do with all that time saved?
Exploitation Hits Rejetto HFS Vulnerability Discovered by AI
CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.
The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI appeared first on SecurityWeek.
Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity
More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.
The post Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity appeared first on SecurityWeek.
All hail electrification. But let's talk about the hard part
Article URL: https://insideclimatenews.org/news/01102026/inside-clean-energy-global-electrification-obstacles/
Comments URL: https://news.ycombinator.com/item?id=49962866
Points: 1
# Comments: 0
Apple and a Hacker's Future
Article URL: https://stratechery.com/2026/apple-and-a-hackers-future/
Comments URL: https://news.ycombinator.com/item?id=49962857
Points: 1
# Comments: 0
Integrating an Orcon ventilation system into Home Assistant
Article URL: https://elvinhome.io/blog/articles-3/hacking-my-rental-apartment-s-ventilation-to-be-smart-orcon-15rf-remote-23
Comments URL: https://news.ycombinator.com/item?id=49962854
Points: 1
# Comments: 1
IBM Bob expands to self-hosted environments
How AI-Native Companies Are Rebuilding the Management Function
Article URL: https://growthwiseteams.substack.com/p/how-ai-native-companies-are-rebuilding
Comments URL: https://news.ycombinator.com/item?id=49962834
Points: 1
# Comments: 0
Staying on the path to high performing teams
Article URL: https://lethain.com/durably-excellent-teams/
Comments URL: https://news.ycombinator.com/item?id=49962818
Points: 1
# Comments: 0
The Impossible Problem and the Perils of Writing a Physics Engine
Article URL: https://lotusspring.substack.com/p/the-impossible-problem-and-the-perils
Comments URL: https://news.ycombinator.com/item?id=49962806
Points: 2
# Comments: 0
Azure showed $21k in startup credits. Claude in Foundry billed our card $17k
Article URL: https://vegalabs.no/azure-claude-billing.html
Comments URL: https://news.ycombinator.com/item?id=49962785
Points: 2
# Comments: 0
