11/18/20253:59:14PM Sent: From: Wendy Stratton Monahan <WMonahan@ci.benicia.ca.us To: lily.ho@flocksafety.com Cc: "Mark", "Edward" Bcc: Importance: Normal Subject: FW: Benicia Must Reconsider Its Flock Safety Deployment Attachments image604200.png,image724539.png, image324275.png , image611335.png,image438156.png,image074009.png ,image158946.png,image189917.png,image585058.png ,image473993.png,image109081.png,image347389.png Lily, Pleasebepreparedtospeaktothevulnerabilityofthesystemtohacking WendyStrattonMonahan SeniorManagementAnalyst/PDPIO PoliceDepartment ENIC O:707-746-4306 EST 1941 POLICE WMonahan@ci.benicia.ca.u THE CITY OF S BENICIA www.ci.benicia.ca.us/police From:MarkMenesini<MMenesini@ci.benicia.ca.us> Sent:Tuesday,November18,20253:54PM To:WendyStrattonMonahan<WMonahan@ci.benicia.ca.us> Subject:FW:BeniciaMustReconsiderItsFlockSafetyDeployment MarkMenesini Police Chief PoliceDepartment ENIC O:707-746-4262 1941 EST. POLICE MMenesini@ci.benicia.ca.u THECITY 0 S BENICIA www.ci.benicia.ca.us/police Mario:Dowestill haveundercontractacybersecurityconsultant? I watched theVideo and the majority doesn't address the use and major issues other communities have experienced.My question to The Chief would be about the concernsrelated to thevulnerability and security of our systems fromhacking?Sent from my iPhone Terry Scott CouncilMember ElectedOfficial O:707-746-4213 TScott@ci.benicia.ca.us THECITY OF www.ci.benicia.ca.us BENICIA CityHall is closed on alternatingFridays.Learnmoreaboutclosureshere. Begin forwarded message: From: Date:November16,2025at10:49:15AMPST To: Steve Young <SYoung@ci.benicia.ca.us>, Lionel Largaespada Scott <TScott@ci.benicia.ca.us>, Kari Birdseye <Kbirdseye@ci.benicia.ca.us>, Mario Giuliani <MGiuliani@ci.benicia.ca.us>, Mark Menesini <MMenesini@ci.benicia.ca.us> Subject:BeniciaMustReconsiderItsFlockSafetyDeployment Caution: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. devices.IndependentsecurityresearchintothesameecosystemofFlockhardwaredeployed nationwidereveals systemicvulnerabilities that place public data,cityinfrastructure,and law- enforcement operations at risk—not hypothetically, but demonstrably. The whitepaper documents 51 security findings across Flock’s gunshot detection units, license plate readers, and Al compute boxes. Many are critical, including: ·Disabled Secure Boot on multiple devices, allowing attackers to load malicious firmware and gain persistent control (e.g., CVE-2025-47819). 2. Exposed debug interfaces such as UART, JTAG, and Android Debug Bridge, enabling shell accessorfull systemcompromisewithminimalskill. 3.Hardcoded Wi-Fi credentials and automaticconnectionbehavior,allowing attackers to impersonateaccesspoints and intercept traffic. 4. Unauthenticated administrative APl endpoints and multiple paths to remote code execution,includingwirelessattacksacrossdevices. APIkeys and authentication tokens. lifeOSwithnosecurityupdates.
These issues are not edge cases—they are systemic design and hardening failures. They liability. Deploying devices with known critical vulnerabilities—many carrying CVE identifiers— does not meet any reasonable security standard for systems that monitor the public or support policeoperations. Before expanding or renewing any Flock contract, Benicia must demand independent securityfailures.Publicsafetytechnologymustbesecuretobetrustworthy—and today,Flock’s ecosystemsimplyisnot. TheWhitepapercanbefound here and avideooutlining thefindingsisbelow https://zenodo.org/records/17584876 https://www.youtube.com/watch?v=uB0gr7Fh6lY
Public Records Exemptions Enclosed please find a copy of the response documents for your public process employed to review and produce the response documents. Reason Description Pages 1 of 1