Connect with us

Infosecurity

License plate cameras may be next target after Supreme Court reins in location tracking

Published

on

license plate cameras

A landmark ruling with a long shadow

The Supreme Court’s decision last month in Chatrie v. United States — the first major Fourth Amendment case to reach the high court in eight years — may have been about cell phone location data. But its ripple effects could reach far beyond Google’s servers.

Legal scholars and privacy advocates are now asking a pointed question: if police need a warrant to see where your phone was, why shouldn’t they need one to see where your car was?

The ruling, which found that so-called geofence searches of location history require a warrant, has thrown a spotlight on license plate cameras — the networks of automated license plate readers (ALPRs) that have quietly become a cornerstone of modern policing.

What Chatrie actually changed

For years, police have leaned on tech companies to hand over location data, letting them pinpoint which phones were near a crime scene at a specific time. The government argued these geofence searches were too brief to trigger Fourth Amendment protections.

The justices disagreed. Even a few hours of location history, they wrote, can reveal whether someone visited an “indisputably private” place — a psychiatrist’s office, an abortion clinic, an AIDS treatment center, a strip club, or a by-the-hour motel.

“Location History enables police officers to focus on precisely those sites — to see, in a given time block, who shows up,” the opinion read.

That language matters, says Michael Soyfer, an attorney at the Institute for Justice. The court zeroed in on the “retrospective and indiscriminate” nature of the surveillance — adjectives that fit ALPR data just as well.

“The justices drilled down on what was in the database and not just what police happened to access at a point in time,” Soyfer said at a recent briefing. “The court’s really emphasizing that it’s looking at the capabilities of the technology overall rather than just what police did with it.”

The Flock Safety factor

Here’s where the rubber meets the road. Flock Safety, the country’s dominant ALPR vendor, says it has between 90,000 and 100,000 cameras on public roadways. It collects data on roughly 20 billion license plates every month.

That’s not a typo. Twenty billion.

Police increasingly use this data to identify suspects — running plates through databases that can reveal where someone lives, works, and drives on a regular basis. The question is whether that kind of sweeping surveillance should require judicial oversight.

Flock Safety insists the Chatrie decision doesn’t apply to its technology. In a statement, a company spokesperson argued that the ruling addresses “geofence warrants for Google location history, which is categorically different from license plate recognition technology.”

“Google location history involves data from a person’s own mobile device and reveals continuous movements across both public and private places,” the statement said. “Flock’s ALPR technology, by contrast, captures point-in-time images of vehicles in public view.”

The company also pointed to a side note in the Supreme Court opinion that appears to differentiate the standard for what counts as a Fourth Amendment search based on whether the tracking occurs on “public roads.” Courts have “repeatedly and uniformly” treated ALPRs differently from cell-site location data, the spokesperson added.

Why ALPRs aren’t just about plates

Andrew Guthrie Ferguson, a law professor at George Washington University and author of Your Data Will Be Used Against You, isn’t convinced. He argues that modern ALPRs are just the tip of a much larger iceberg.

“Modern ALPRs are just the connecting point to a much larger system of personally revealing information stored in police and connected public databases,” Ferguson said in an interview.

Those databases often hold far more than plate reads. Ferguson points to social media activity, surveillance video from thousands of public and private cameras, body camera footage, drone video, gunshot detection sensor data, and police dashboard cameras — all linked together in ways that let officers build extraordinarily detailed dossiers on individuals.

“There are some differences with the nature of license plates that are after all designed for identification, but I think it is a mistake to think about ALPRs standing alone,” he said. “Chatrie certainly strengthens the Fourth Amendment case against the warrantless collection of ALPR data.”

What a warrant requirement would mean

If courts ultimately decide that ALPR searches require a warrant, the impact on policing would be hard to overstate. Here’s what could change:

  • Police would need to show probable cause before searching historical plate data — a significant hurdle for investigations that currently rely on quick database queries.
  • Retrospective searches — going back days or weeks to see which cars were at a scene — would likely face the toughest scrutiny.
  • Real-time alerts, like Flock’s ability to flag a stolen car the moment it passes a camera, might survive, since those are more like traditional surveillance.
  • Data retention policies would probably shrink. Why keep 30 days of data if you can’t search it without a warrant?

The Chatrie decision could also have implications beyond ALPRs. Soyfer notes it may affect reverse keyword searches, cell tower dumps, and law enforcement’s purchase of commercial location data from brokers — all practices that have grown rapidly in recent years.

A debate that’s just beginning

Flock Safety may be right that the Supreme Court didn’t have license plates in mind when it wrote the Chatrie opinion. But the logic of the ruling — that the government can’t build a massive, searchable database of where people have been without judicial oversight — is hard to square with the company’s business model.

The court’s emphasis on the capabilities of technology, rather than how police happened to use it in a particular case, is a direct challenge to the way ALPR networks operate. They collect everything, store everything, and search everything.

For now, the legal landscape remains unsettled. But one thing is clear: the debate over license plate cameras and the Fourth Amendment is only getting started. And after Chatrie, the burden of proof may be shifting.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

UK Legal Regulator Warns Solicitors: AI Hallucinations and Data Leaks Are a Compliance Risk

Published

on

AI misuse risks

SRA Issues Stark Warning on AI in Legal Work

The Solicitors Regulation Authority (SRA) has put the profession on notice. On August 17, it published a detailed warning notice flagging two specific dangers: AI hallucinations and the leakage of confidential client data through public AI tools.

“We are concerned that some of those operating in the regulated legal sector are not fulfilling their obligations to uphold their duties to the courts, clients and third parties,” the regulator stated. The message is blunt: appropriate human oversight and a risk-based approach are not optional extras.

What the SRA Has Observed

The regulator says it has seen real incidents, not hypotheticals. Solicitors have self-reported AI hallucinations in legal work and court submissions. There have also been reports from senior judges about potential breaches of the Code of Conduct.

Then there’s the data side. Confidential client information has been typed into public AI systems, raising serious data protection and confidentiality concerns. The consequences? Poor client outcomes, slower case progression, and a hit to public trust in the profession.

Accountability Stays With the Solicitor

The SRA takes an outcomes-based approach to regulation. It sets the standards but doesn’t dictate the exact methods. Still, the warning notice makes one thing clear: solicitors and regulated individuals remain accountable for AI output.

Firms need to put in place “effective governance structures, systems and controls” to manage AI risks. That’s not just a suggestion; it’s a compliance expectation.

Court Submissions and Contempt Risk

One of the most serious warnings relates to court submissions. If a solicitor puts AI-hallucinated “false material” before a court, it could be considered contempt of court. The SRA warns of “serious consequences” for those who mislead the courts.

Supervisors of junior or non-authorized colleagues could also be held responsible if false citations end up in court documents. The message is clear: verify every case law authority before submitting it.

Client Data and AI Tools: The Red Lines

Putting client information into a public AI tool will likely breach client confidentiality. The SRA notes that both free-to-use and paid-for AI systems pose risks. Even paid tools aren’t automatically safe.

Client information should only be entered into AI systems where “appropriate contractual, technical and organizational safeguards are in place.” Client data must always remain within a secure environment.

This is a practical concern for many firms. Lawyers often use AI for drafting or research, but the data they input can end up in training models or be exposed to third parties. The SRA is drawing a hard line: confidentiality trumps convenience.

What the Profession Should Do Now

The SRA’s warning notice includes a lengthy list of “considerations” for the profession. Here’s a quick rundown of the key points:

  • Ensure solicitors remain accountable for all AI-generated output.
  • Implement governance structures to manage AI risks.
  • Verify all case law citations are genuine and verifiable.
  • Avoid entering client data into public AI tools unless safeguards are in place.
  • Keep client data within secure environments at all times.

Brett Dixon, vice president of the Law Society of England and Wales, acknowledged the pace of change. “Technological innovation in legal processes and service delivery is advancing at speed,” he said. He called on the SRA to continue providing “swift and clear guidance” so solicitors can use AI with confidence.

Broader Context: AI Misuse Across Sectors

This isn’t just a UK issue. Similar concerns have emerged globally. In the US, lawyers have been sanctioned for submitting fake citations generated by AI. The SRA’s warning aligns with a broader regulatory trend: AI is a tool, but professional judgment remains human.

For law firms, the takeaway is straightforward. AI can improve efficiency, but it introduces new risks. Firms must balance innovation with their duties to clients and the courts. The SRA’s warning is a reminder that the rules haven’t changed—only the tools have.

If you’re a solicitor, this is the moment to review your AI policies. Check what tools your firm uses, how data flows through them, and whether your supervision structures are robust enough. The SRA is watching.

Continue Reading

Infosecurity

Evooo1Bot: New Mirai-Based Linux Botnet Turns Hacked Devices Into Proxies

Published

on

Evooo1Bot Mirai botnet

Evooo1Bot: A New Twist on an Old Threat

Security researchers have spotted a fresh Linux botnet that borrows its core from the infamous Mirai malware — but adds some serious upgrades. Dubbed Evooo1Bot by Fortinet’s FortiGuard Labs, this modular threat is actively exploiting a wide range of vulnerabilities in routers and edge devices. The goal? Not just DDoS attacks, but turning victims into covert proxies.

The botnet gets its name from the hardcoded string “evooo1” found in every binary. Analyst Yi Ping (Cara) Lin published the technical breakdown on August 13, after observing a string of exploit attempts tied to a single loader URL: 91.92.40[.]118/wget.sh.

That URL was the common thread linking attacks against at least ten distinct CVEs, spanning vendors like Alcatel, NETGEAR, Tenda, D-Link, and Mitsubishi Electric.

Targets: Old and New Vulnerabilities

Evooo1Bot isn’t picky. It goes after legacy flaws that have been public for years, alongside more recent disclosures. Some of the key CVEs in its arsenal:

  • CVE-2007-3010 — Alcatel OmniPCX Enterprise RCE
  • CVE-2016-6277 — NETGEAR multiple routers RCE
  • CVE-2018-14558 — Tenda AC7, AC9, AC10 command injection
  • CVE-2020-10987 — Tenda AC15 RCE
  • CVE-2021-46422 — Telesquare SDT-CW3B1 command injection
  • CVE-2022-37055 — D-Link routers buffer overflow
  • CVE-2024-29269 — Telesquare TLR-2005KSH command injection
  • CVE-2025-10123 — D-Link DIR-823X command injection
  • CVE-2025-55583 — D-Link DIR-868L B1 command injection

That mix of old and new is a deliberate strategy. Many of these devices are end-of-life, meaning vendors won’t patch them. And plenty of still-supported gear never gets updated by users anyway.

More Than Just DDoS

Mirai’s original claim to fame was massive distributed denial-of-service attacks, powered by armies of compromised IoT cameras and routers. The source code leaked in September 2016, after creator Paras Jha and his co-conspirators released it to muddy the waters as the FBI closed in. That leak spawned a thousand copycats.

Evooo1Bot follows that lineage, but it’s not content to just flood targets with traffic. The malware includes a 28-command remote administration interface, encrypted C2 communications, and an SSH brute-force scanner. It also packs a credential sniffer and multiple layers of obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation.

What really sets it apart, according to Lin, is the reverse SOCKS relay module. That feature turns a compromised device into a persistent proxy. An attacker can route traffic through the victim’s machine, hiding their true origin and pivoting deeper into internal networks.

“These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” Lin wrote in her analysis.

How the Proxy Relay Works

The SOCKS relay is arguably the most operationally significant part of the botnet. Here’s why it matters:

  • Anonymity — Attackers route traffic through victim devices, making attribution much harder.
  • Pivoting — Once inside a network, they can move laterally to other systems.
  • Follow-on operations — The same proxy can be used for credential theft, data exfiltration, or further exploitation.

In other words, your router could be someone else’s getaway car.

Who’s Being Targeted?

Lin’s analysis suggests Evooo1Bot has been actively scanning for internet-facing devices since at least July 2026. The campaign appears to span multiple regions, with no single geographic focus. Any organization with exposed routers, switches, or IoT gear is a potential victim.

That’s a wide net. Small offices, home users, industrial control networks — all rely on edge devices that are often forgotten once installed.

How to Protect Yourself

There’s no single silver bullet, but basic hygiene goes a long way:

  • Patch everything — Apply firmware updates as soon as they’re available. For end-of-life devices, replace them.
  • Change default credentials — Mirai’s original trick was guessing weak passwords. Don’t give it a chance.
  • Disable remote management — If you don’t need admin access from the internet, turn it off.
  • Segment your network — Keep IoT devices on a separate VLAN so a compromise doesn’t spread.
  • Monitor for anomalies — Unexpected outbound connections from routers or cameras are a red flag.

For more on how these attacks unfold, check out our guide on Mirai botnet variants and IoT security. And if you’re wondering about the broader threat landscape, read about router vulnerabilities and how to fix them.

The Bottom Line

Evooo1Bot is a reminder that old code never dies — it just gets repurposed. Mirai’s leaked source has fueled a decade of malware, and this latest variant shows how far the genre has evolved. The DDoS engine is still there, but the proxy relay and encryption make it a far more dangerous tool.

If you have internet-facing devices, assume they’re being scanned right now. Patch what you can, replace what you can’t, and don’t rely on default settings to keep you safe.

Stay ahead of the threat. Learn more about botnet protection strategies to keep your network clean.

Continue Reading

Infosecurity

ExfilSquad’s Data Leaks: 13 Organizations Exposed, Researchers Confirm

Published

on

ExfilSquad data leak

ExfilSquad’s Claims Check Out

New research from Fortra’s Intelligence and Research Experts (FIRE) has confirmed that the ExfilSquad data extortion group really did get its hands on sensitive data. The criminals claimed they had exfiltrated information from 15 organizations. Now, the evidence shows they weren’t bluffing.

FIRE reviewed the public data samples and concluded that the group’s access to sensitive data is real. At least 13 victims have been hit, spanning government, education, financial services, and manufacturing. That’s not a small-time operation.

The group first surfaced on July 26. By August 7, they had published data dumps for 13 of the 15 claimed victims via torrents, saying those organizations didn’t meet their demands. The full archive, named “[victim]_exfilsquad,” was up for download. The total haul? A staggering 382.64 GB and 27 million records.

Who Got Hit?

The victim list reads like a cross-section of public and private sectors. The City of Atlanta (atlantaga.gov), the UK Department for Education (education.gov.uk), and the UK Police National Legal Database all appear. The District of Columbia Public Schools (DCPS) is also on the list.

For DCPS, the attackers took an unusual stance. They wrote: “We are not going to dox a bunch of school children, but we are going to expose how incompetent DCPS is at keeping children as young as six’s information safe. Thus, we are releasing a censored version of the leak and have shredded the original entirely from our servers.”

In that case, 60,000 records were leaked, containing student names, dates of birth, and unique student identifiers—classic personally identifiable information (PII).

Notably, Zenith Bank Plc and Analog Devices were on the original 15-victim list but didn’t appear in the dumps. The FIRE team flagged this as a possible sign that those negotiations went differently, or the data wasn’t ready to be released.

The Likely Attack Vector: Misconfigured Microsoft Power Pages

So how did ExfilSquad pull this off? Fortra’s researchers believe the breaches stem from unauthorized access to Microsoft D365 CRM and ERP instances. The leading theory? Misconfigured Microsoft Power Page portals that allowed public read access.

Power Pages is a SaaS platform for building external-facing business websites. If set up wrong, it can expose data to anyone who knows where to look. The leaked data formations matched Microsoft Dataverse exports, which suggests unauthorized read access was achieved during the incidents.

The attackers probably found their targets by crawling for misconfigured Power Portals or using other enumeration techniques. It wasn’t a sophisticated zero-day exploit. It was a configuration error—and that’s what makes it so dangerous.

Why It’s Not a D365 Vulnerability

Fortra was quick to note that because the breach hit only 15 victims, not tens of thousands, a systemic vulnerability in D365 is unlikely. Instead, the issue is specific to how Power Pages is configured.

There’s a known problem: when the Anonymous Users web role is assigned to a table permission, anyone visiting the site can read the table’s data. Power Pages can be accessed via an API at https://<portal>/_api/*. Microsoft’s own documentation advises against using this role in publicly exposed sites, but not everyone follows the guidance.

Fortra’s research even found over 10,000 potential Power Pages instances accessible to the public. That’s a lot of attack surface.

What This Means for Organizations

This incident is a wake-up call. Data extortion groups like ExfilSquad are actively scanning for misconfigured systems. They don’t need to break in—they just need a door left open.

For any organization using Microsoft Power Pages or D365, the takeaway is clear: audit your table permissions, disable Anonymous Users roles on public sites, and monitor API access. A few minutes of configuration review could save you from a 382 GB leak.

If you’re dealing with a similar threat, understanding the data extortion group tactics can help you prepare. And if you’re using Microsoft Power Pages security settings, double-check them now.

The ExfilSquad data leak is a reminder that cybercriminals are patient and methodical. They find the weak spots, and they exploit them. Don’t be the next headline.

Continue Reading

Trending