Author: Osiris

  • Automatic License Plate Recognition Explained: How ALPR Actually Works

    Automatic License Plate Recognition Explained: How ALPR Actually Works

    Automatic license plate recognition, commonly abbreviated ALPR or LPR, has become a routine part of parking facilities, gated communities, toll roads and law enforcement operations. Behind the simple output, a plate number matched or flagged in real time, sits a multi-stage pipeline that has to work reliably across widely varying lighting, weather, plate designs and vehicle speeds.

    Capturing a Usable Image

    ALPR begins with image capture, and purpose-built ALPR cameras differ meaningfully from general security cameras. They typically use infrared illumination and specialized shutter settings tuned to read the reflective, retroreflective coating on most license plates, allowing them to capture a sharp, well-exposed image of a plate at night or in bright daylight without being fooled by headlight glare or dark backgrounds. Camera placement and angle are also more exacting than for general surveillance, since a plate that is too oblique an angle or too far outside the camera’s focus range often cannot be reliably decoded regardless of processing quality.

    Locating and Reading the Plate

    Once an image is captured, software first has to locate the plate within the frame, distinguishing it from other rectangular, high-contrast regions like bumper stickers or grille badges. After the plate region is isolated, optical character recognition, increasingly built on deep-learning models rather than older template-matching techniques, extracts the individual characters. Modern systems typically also read the plate’s issuing state or country, since many alphanumeric combinations repeat across jurisdictions and are only unique when the plate’s origin is known.

    Matching Against a Database

    The extracted plate number is then checked against one or more reference lists in real time; depending on the application, that might mean a residential community’s list of authorized vehicles, a parking operator’s list of paid or subscribed vehicles, or a law enforcement hot list of stolen or wanted vehicles. Because this matching step generally happens in milliseconds, ALPR systems can trigger gate access, flag a security operator, or log a routine pass-through without a vehicle needing to slow down.

    Where Accuracy Breaks Down

    Read accuracy is highest for standard, clean, front- or rear-facing plates captured at low-to-moderate speed. Performance degrades with obscured or damaged plates, unusual plate designs or fonts the system was not trained on, extreme angles, heavy rain or snow accumulation on the plate surface, and high-speed capture where motion blur becomes a factor. Because of this, most operational deployments accept a certain rate of unreadable captures and are designed with a human review step, or a secondary confirmation method such as a transponder, rather than relying on ALPR as a sole point of failure for access decisions.

    FAQ

    Do ALPR systems store video of every vehicle? Retention practices vary by deployment and jurisdiction. Some systems store only the plate number and a timestamp, while others retain a still image or short video clip; many jurisdictions have specific retention-period rules for this data.

    Can ALPR read plates from any country or state? Most commercial systems are trained on the plate formats common to their deployment region and may perform poorly on unfamiliar international or out-of-region plate designs unless specifically configured for them.

    Is ALPR the same as general video analytics? No. ALPR is a specialized recognition pipeline built specifically around plate detection, character recognition and jurisdiction identification, distinct from general object-classification video analytics, even though both may run on similar camera hardware.

  • Radar’s Rise in Commercial Perimeter Security

    Radar’s Rise in Commercial Perimeter Security

    Radar has quietly become one of the more important sensor types in commercial perimeter security, moving well beyond its traditional home in aviation and military applications. For sites that need reliable detection across large open areas and in poor visibility, radar increasingly sits alongside cameras and fence-line sensors rather than as a niche add-on.

    Why Radar Fits Perimeter Detection

    Radar works by emitting radio waves and measuring how they reflect off objects, calculating range, speed and direction of movement independent of light or weather conditions. That makes it fundamentally different from video-based detection, which depends on adequate lighting and a clear line of sight, and from fence-mounted or buried sensors, which only detect activity at the point of intrusion rather than approach. A radar unit can detect a person or vehicle approaching a perimeter well before they reach it, in complete darkness, heavy rain, fog or blowing dust that would defeat most cameras.

    From Military-Grade to Commercially Practical

    Early security radar systems were adapted from military and airport surveillance technology, which made them expensive and often overly sensitive for typical commercial use. The current generation of ground surveillance radar is purpose-built for perimeter security, with solid-state designs, lower price points, and detection logic tuned to classify people and vehicles rather than simply flagging any movement, which has driven down the false-alarm rates that limited earlier radar deployments.

    Where Radar Is Being Deployed

    Radar has found a particular niche protecting large, open sites where fence-line sensors or camera coverage alone would be impractical or prohibitively expensive: solar farms, substations, ports, logistics yards, construction sites and data center campuses. In these environments, a small number of radar units can cover distances that would require dozens of cameras, and the radar’s output can then cue nearby pan-tilt-zoom cameras to automatically point at and record a detected target, combining radar’s long-range detection with video’s ability to visually confirm and identify a threat.

    Radar as Part of a Layered System

    Security professionals generally treat radar as one layer in a broader detection strategy rather than a standalone solution. Radar excels at early, long-range detection across open ground but provides limited ability to identify what it has detected, which is why it is typically paired with video analytics for classification and verification, and sometimes with thermal cameras for confirmation in total darkness. This sensor-fusion approach, combining radar’s reach with the identification strengths of video and thermal imaging, has become a common design pattern for protecting critical infrastructure and other large perimeters.

    FAQ

    Does radar replace cameras in perimeter security? No. Radar is generally used to detect and track objects across an open area, then hand off to cameras for visual verification and identification, rather than replacing video entirely.

    Can radar work in bad weather? Yes, this is one of radar’s core advantages. Because it uses radio waves rather than visible light, radar performance is largely unaffected by darkness, fog, rain, dust and similar conditions that degrade camera performance.

    Is security radar expensive to deploy? Costs have fallen significantly compared with early military-derived systems, and because a single radar unit can cover a large area, overall system cost per square foot of coverage is often lower than achieving equivalent coverage with cameras alone.

  • Accused Ringleader of $240 Million Bitcoin Social-Engineering Heist Faces Plea Hearing

    Accused Ringleader of $240 Million Bitcoin Social-Engineering Heist Faces Plea Hearing

    Malone Lam, the alleged ringleader of a network accused of stealing more than $240 million in Bitcoin from a single victim through a social-engineering scheme, has a plea agreement hearing scheduled this week, according to the Associated Press.

    A Social-Engineering Heist Followed by a Spending Spree

    Prosecutors say the theft targeted a Washington, D.C., resident identified in court filings as “Victim 7,” who received a phone call in August 2024 from someone posing as a Google representative warning of attempts to breach his account, followed by a second call from someone claiming to represent the Gemini crypto exchange who warned of a malware attack on his crypto wallet. Prosecutors say the network Lam allegedly organized used that fabricated scenario to gain the victim’s trust and ultimately extract control of his cryptocurrency holdings.

    According to the Associated Press, Lam and his associates celebrated the heist with a monthlong spending spree that included fleets of sports cars, private jet flights, hired security guards and rented mansions in Miami and the Hamptons; Lam alone reportedly spent more than $569,000 in a single evening at a Los Angeles nightclub. FBI agents arrested Lam, an eighth-grade dropout from Singapore, after the spree, on charges of organizing the social-engineering attack. Charges have been filed against Lam and 17 others in connection with the case.

    Part of a Broader Enforcement Push

    The case is emblematic of a rapidly growing category of cybercrime: complaints of cryptocurrency investment fraud to the FBI rose by nearly 50% in 2025. Cybersecurity researcher Allison Nixon, who tracks an underground subculture of young hackers known as The Com, has called for significantly more law enforcement resources to be devoted to pursuing these networks, warning that the scale of money involved will otherwise continue to draw in new participants. A conviction for Lam would mark a significant milestone for investigators working to build cases against the loosely organized networks behind this style of large-scale crypto theft.

  • Ex-Palo Alto Networks Founder’s Startup Cylake Raises $245 Million for Sovereign Security Platform

    Ex-Palo Alto Networks Founder’s Startup Cylake Raises $245 Million for Sovereign Security Platform

    Cybersecurity startup Cylake has raised $245 million to accelerate development of its security platform, bringing its total funding to $290 million just six months after emerging from stealth.

    A Platform for Organizations That Can’t Use the Public Cloud

    Cylake is building what it describes as a complete, AI-native cybersecurity platform aimed at government agencies, highly regulated enterprises and other organizations that cannot depend on public cloud infrastructure. The platform is designed to run entirely on premises or in private cloud environments, giving customers control over their own data, infrastructure and security operations, and combining data and context from across an organization’s systems into a unified foundation for both protection and AI-powered security workflows.

    The company said the new funding will go toward platform development and team expansion ahead of a beta release targeted for the end of 2026, with general availability planned for 2027.

    A Team With Deep Palo Alto Networks Roots

    Cylake was co-founded by chief executive Nir Zuk, who founded Palo Alto Networks and served as its chief technology officer for more than two decades; chief development officer Wilson Xu, a former Palo Alto Networks engineering executive; and chief architect Ehud “Udi” Shamir, who co-founded SentinelOne before working as a distinguished software developer and security researcher at Palo Alto Networks. The team also includes René Bonvanie, previously Palo Alto Networks’ chief marketing officer.

    Cylake emerged from stealth in March 2026 with a $45 million seed round led by Greylock Partners and has since grown to more than 40 employees, with plans to continue hiring across engineering, product and other functions as it works toward its beta launch.

  • ‘White-Hat’ Hackers Return $263 Million of $320 Million Stolen From Bitcoin’s Liquid Network

    ‘White-Hat’ Hackers Return $263 Million of $320 Million Stolen From Bitcoin’s Liquid Network

    Alleged “white-hat” hackers have returned 3,400 Bitcoin, worth roughly $262.6 million, of the approximately 4,000 Bitcoin they drained from the federation wallet of Liquid Network, a Bitcoin sidechain developed by Blockstream.

    A Weekend Heist That Froze the Network

    Liquid disclosed the incident on a Sunday, disabling its nodes and suspending all transactions in response. The stolen funds came from Liquid’s federation wallet, which held approximately 4,200 Bitcoin before the attack. Liquid said the funds were withdrawn via the SideSwap Peg-out Authorization Key, but that the key itself, along with other keys in the system, was not compromised — leaving the precise mechanism of the theft unclear. The company said exchanges had been notified and had paused or would pause LBTC deposits and withdrawals, while other assets on the network, including USDT, DePix and real-world assets, were unaffected.

    A Conditional Return

    The theft was claimed by attackers describing themselves as white-hat hackers, who said in a public blockchain message that they would return most of the stolen funds once Liquid fixed the underlying vulnerability: “Please fix the bug first. The chain is under risk at latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.”

    On Monday, the attackers followed through by returning 3,400 Bitcoin. Former Blockstream executive Samson Mow said approximately 598 Bitcoin, worth about $47 million, remained outstanding as Blockstream continued communicating with the hackers. Mow said the network would stay paused while Blockstream and federation members complete additional fixes and security improvements, resolve a resulting chain split, and prepare for a safe restart, adding that Liquid wallets and services would remain affected in the meantime.

  • ‘OVERPASS’ Flaw in SAP Passport Processing Lets Attackers Take Over Systems Before Login

    ‘OVERPASS’ Flaw in SAP Passport Processing Lets Attackers Take Over Systems Before Login

    SAP has patched a maximum-severity vulnerability in its Extended Passport (EPP) Processing component that could let an unauthenticated attacker take control of a wide range of SAP systems before a user even logs in, according to application security firm Onapsis.

    A Flaw Reached Before Security Checks Apply

    The vulnerability, tracked as CVE-2026-44756 and rated a maximum CVSS score of 10, stems from missing boundary validation during the deserialization of EPP data, which is used for tracing across multiple SAP applications. Onapsis, which dubbed the flaw OVERPASS, says it is triggered as soon as a new user session opens, meaning it executes before any of SAP’s access controls, including user locks, roles, authorization objects and logon policies, ever get a chance to evaluate the connection. “None of them is in the attacker’s way,” Onapsis said.

    The flaw resides in SAP’s kernel code and can be reached through at least three separate paths: standard web requests, the SAP GUI protocol, and Remote Function Call connections. Because the vulnerable code runs under the operating-system account that owns the SAP installation, Onapsis says successful exploitation is equivalent to gaining full control of the SAP system, allowing an attacker to run arbitrary system commands, recover database credentials and password hashes, read the live sessions of logged-in users, and modify data, configurations and SAP binaries.

    Broad Product Exposure, No Known Exploitation Yet

    The vulnerable kernel code underlies a wide range of SAP products, including S/4HANA, ERP, Business Suite (ECC), NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO and Solution Manager. Neither Onapsis nor SAP has reported evidence that the flaw has been exploited in the wild.

    SAP released the fix as part of 20 new and updated security notes issued on its September 2026 Patch Day. Three other critical vulnerabilities were resolved in the same release: CVE-2026-58240, a missing authentication check in NetWeaver; CVE-2026-76969, a credential disclosure issue in multitenant applications using the Cloud Application Programming Model; and CVE-2026-66768, an improper access control flaw in NetWeaver. SAP customers running any of the affected products are advised to apply the September patches as a priority given the pre-authentication nature of the OVERPASS flaw.

  • SWEAR Launches Video Authentication Program to Help Public Agencies Prove Footage Is Real

    SWEAR Launches Video Authentication Program to Help Public Agencies Prove Footage Is Real

    Digital content authenticity company SWEAR has launched a new program designed to help cities and public agencies verify that critical video evidence is genuine, as concerns grow over deepfakes and other synthetic media.

    A Verifiable Record From the Moment of Capture

    The Boise, Idaho-based company announced its Community Video Integrity Project on Sept. 8. Through the program, selected municipalities, law enforcement agencies and other public-sector organizations will deploy SWEAR across high-priority cameras running on Milestone Systems’ XProtect video management platform, creating a verifiable record intended to document that footage has not been altered from the moment it was captured.

    The initiative is aimed at organizations that rely on video for investigations, public safety response and legal proceedings, and that may need to demonstrate in court or in public that a given recording is authentic rather than manipulated or fabricated.

    A Response to Growing Public Doubt

    SWEAR cited a 2025 Pew Research Center survey in its announcement showing that 53% of Americans are not confident they can distinguish content created by AI from content created by people, framing the program as a response to both the rise of convincing synthetic media and the corresponding erosion of public confidence in authentic recordings.

    “Video plays a critical role in how our customers investigate incidents, respond to events, and make important security decisions,” said Andy Schreyer, vice president of technology at Stone Security. “As AI makes sophisticated manipulation increasingly accessible, protecting that video means building on how it is captured and stored to also prove authenticity.” Schreyer said the project gives organizations a practical way to begin addressing video authentication now, ahead of wider industry adoption of similar verification standards.

  • UNECE Warns AI Data Center Growth Is Outpacing Electricity Grid Capacity Worldwide

    UNECE Warns AI Data Center Growth Is Outpacing Electricity Grid Capacity Worldwide

    The United Nations Economic Commission for Europe (UNECE) warned that AI data center buildout is outpacing electricity grid expansion worldwide, according to a press release covered by UN News. Global AI data center electricity consumption is projected to nearly double, from 485 TWh in 2025 to 950 TWh by 2030.

    UNECE noted that a data center can be built in two to five years, while new transmission infrastructure typically takes ten years or more to plan and construct — a mismatch that raises the risk of voltage oscillations and cascading grid failures, particularly on renewables-heavy grids that are less able to absorb sudden AI-driven demand spikes.

    Why it matters: The warning adds an authoritative, non-industry voice to a debate that has so far been driven mostly by hyperscalers’ own announcements of multi-gigawatt buildouts and power-purchase agreements; it frames AI infrastructure growth as a grid-stability and critical-infrastructure planning issue, not just a capacity or investment story.

    Source: UN News, September 9, 2026, citing UNECE press release, September 8, 2026.

  • Ransomware Attack Encrypts IT Systems at Bavarian Municipal Utility

    Ransomware Attack Encrypts IT Systems at Bavarian Municipal Utility

    Stadtwerke Landsberg, a German municipal utility providing electricity, water, wastewater and district heating, had its central IT network encrypted in a ransomware attack that began September 1, 2026, The Record (Recorded Future News) reported.

    The utility said it isolated its operational technology (OT) systems from the compromised IT network to keep essential services running, and warned that customer personal data — including names, addresses and bank details — may have been accessed. As of the report, no ransomware group had claimed responsibility.

    Why it matters: The incident is a textbook example of the IT/OT segmentation strategy that critical-infrastructure operators are increasingly relying on: rather than preventing every IT compromise, the goal becomes containing it before it reaches the operational systems that actually control power, water and heat delivery.

    Source: The Record (Recorded Future News), September 8, 2026.

  • German Police Arrest Suspect in Rocket-and-Wire Power-Grid Sabotage Campaign

    German Police Arrest Suspect in Rocket-and-Wire Power-Grid Sabotage Campaign

    German police arrested a 48-year-old suspect near a power plant in North Rhine-Westphalia in connection with a string of attacks on high-voltage substations across Brandenburg, North Rhine-Westphalia and Saxony, DW and the Associated Press reported.

    Investigators say the attacks used homemade rockets to fire conductive wire across transmission lines, deliberately causing short circuits. One incident briefly took roughly 4,200 MW of lignite power-plant capacity offline. Authorities say the suspect appears to have been motivated by opposition to fossil-fuel power generation, and he was found carrying explosives at the time of arrest.

    Why it matters: The attack method — using low-cost, improvised rockets to physically disrupt high-voltage infrastructure from a distance — illustrates a category of physical threat to power grids that is difficult to fully defend against with conventional perimeter security alone, and underscores why grid operators increasingly pair physical substation hardening with wide-area monitoring for this kind of attack signature.

    Source: DW (Deutsche Welle), corroborated by AP News, September 8, 2026.