A nonprofit, the Fulu Foundation, launched a bounty aimed at weakening Amazon Ring’s dependence on cloud services by rewarding a method to run Ring camera systems locally and prevent video from being transmitted to Amazon’s servers. The program offers $10,000 up front and will match community donations up to an additional $10,000, but it is explicitly not a general vulnerability bounty; it prioritizes a practical path to local control and data sovereignty, citing Ring’s prior privacy lapses and an FTC settlement as justification.
Separately, public anger over surveillance has escalated into physical attacks on Flock Safety license-plate reader (LPR) cameras, with reports of devices being dismantled, smashed, spray-painted, or cut down in multiple U.S. states. The backlash is tied to concerns that LPR data supports immigration enforcement and deportations; while Flock says it does not share data with ICE directly, reporting indicates local police sharing access to Flock systems and databases with federal authorities, prompting some communities to push for contract terminations and others to resort to vandalism.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Reports described ongoing destruction and vandalism of Flock license plate reader cameras across the United States amid anger over their perceived role in immigration enforcement and deportations. The coverage also noted that local police customers have shared Flock system access with federal authorities, despite Flock saying it does not directly share data with ICE.
The nonprofit Fulu Foundation announced a $10,000 bounty, with up to another $10,000 in matching community donations, for a method to run Amazon Ring cameras locally without sending data to Amazon’s servers. The effort was framed as both a technical challenge and advocacy around device ownership, privacy, and DMCA anti-circumvention rules.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
fsf.org
Open sourcego.theregister.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.