Flock Safety, a company operating a large network of license plate readers and surveillance cameras, hardcoded a default ArcGIS API key in their public-facing JavaScript bundles, exposing sensitive data and potentially allowing unauthorized access to their surveillance infrastructure. The key was found in 53 separate endpoints and granted access to 50 private layers, including data on law enforcement locations, surveillance cameras, and people detections. The vulnerability was disclosed to Flock Safety's security team, but it remains unpatched after 55 days. This exposure has significant national security implications, as it could allow foreign intelligence services to gather intelligence on the movement of politicians, federal agents, and other high-value targets.