www.flocksafety.com Connecticut Law Limits Flock Camera Data Use Amid Security Breach
Article Content
- •Connecticut SB397 restricts ALPR data use, effective October 1, 2026.
- •Flock Safety reported a security breach linked to a researcher mapping camera locations.
- •Some towns in Connecticut have halted partnerships with Flock Safety due to security concerns.
Connecticut's new law SB397, effective October 1, 2026, regulates the use of automated license plate readers (ALPR) like those from Flock Safety. The law mandates data deletion within 21 days and prohibits its use for immigration enforcement and certain investigations. Following the law's implementation, Flock Safety reported a security breach linked to a researcher who created a map of Flock device locations. This breach raised concerns about the security and effectiveness of Flock cameras, prompting some towns to sever ties with the company. The breach was reportedly due to vulnerabilities in Flock's systems that were previously communicated to the company by the researcher. Data from the Flock Surveillance Map included records from December 2025, with most cameras located in Hartford. The law aims to enhance privacy protections amid scrutiny over ALPR technology.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Flock Safety in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What does SB397 entail?
How did the security breach occur?
Which towns have stopped using Flock cameras?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…