Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

EPA Moves to End Public Comment on Air Permits for Data Centers

The EPA is proposing to eliminate a federal rule requiring states to notify the public and accept comments before approving air-pollution permits for industrial facilities, including data centers and the power plants built to supply them. A separate EPA proposal from last month would also allow developers to begin construction before permits are finalized. These changes come as data centers expand rapidly across the rural South, disproportionately affecting Black communities.

FLHSMV: DAVID driver database breached via stolen Plant City police credentials

Florida's Department of Highway Safety and Motor Vehicles confirmed the ShinyHunters extortion group breached its DAVID driver database on September 4, 2026, after the gang claimed to have stolen over 200,000 driver records. FLHSMV said the intruder used login credentials from a single Plant City Police Department account that had been improperly saved on the employee's personal device, contradicting ShinyHunters' claim that it exploited a password-reset flaw across multiple accounts.

Apple releases nine-page study backing Watch Series 12 heart rate accuracy claims

Apple published a detailed study comparing the heart rate sensing of its new Health Sensing System in Apple Watch Series 12 and Ultra 4 against rivals like Garmin, Google Pixel Watch, Huawei, Samsung, WHOOP, and Oura Ring. The test involved over 1,400 participants across five sites in the US and Malaysia, using a Polar H10 chest strap as the accuracy benchmark during activities like running, cycling, HIIT, and daily tasks.

Trezor customers hit by phishing wave after Brevo email vendor breach

Trezor disclosed that hackers who compromised 138 accounts at email marketing provider Brevo used the access to send roughly 347,000 phishing emails to its customers. The messages, disguised as security alerts, directed recipients to a fake app designed to steal their wallet backup passwords. Trezor says its own products and account systems were not breached, but the stolen credentials could let attackers drain victims' crypto holdings.

ShinyHunters-linked hackers use fake passkey alerts to breach Microsoft 365 accounts

Microsoft has detailed a social engineering campaign, active since May 2026, in which attackers tied to groups like ShinyHunters and Helix pose as corporate IT help desks and warn employees their passkey, MFA, or SSO settings need urgent updating. Victims are steered to convincing fake Microsoft login pages—often via SMS to personal phones—where attackers harvest credentials and session tokens using adversary-in-the-middle and device-code phishing techniques, rather than actually registering new passkeys.

Conviva finds io_uring underperforms mmap in Rust-based DataFusion query engine

Conviva engineers tried replacing mmap with io_uring for reading large Arrow IPC files in their DataFusion-based analytics engine, hoping to fix latency spikes seen under heavy concurrent query loads with mmap. Instead of resolving the problem, the io_uring approach ran slower, and the team's investigation traced the original mmap issue to page-cache thrashing and excessive page faults under high concurrency rather than the memory-mapping mechanism itself.

Trezor confirms 347,000 emails exposed via Brevo breach, 2,500 users phished

Trezor disclosed that a breach at its third-party email provider Brevo let attackers send fake security alerts to its opt-in newsletter subscribers, reaching roughly 347,000 email addresses. The fraudulent messages warned of a fake microcontroller vulnerability and pushed recipients to a malicious app requesting wallet backup phrases; Trezor says 2,500 people clicked the link before it disabled the domain within 20 minutes.

IDScan breach exposes 153 million driver's licenses, hackers ran year-long data theft via Nexus

ID verification company IDScan disclosed that hackers accessed its systems without authorization, a breach later linked to a criminal marketplace called Nexus selling scans of over 170 million identity documents. Security researcher Brian Krebs verified the stolen trove includes 153 million driver's licenses, 10 million ID cards, 3 million passports and travel documents, and hundreds of thousands of medical cards, mostly belonging to US residents with some Canadian records included. The attackers claimed to have quietly siphoned data from IDScan's systems for more than a year before being detected.

Today's top topics: openai anthropic apple ai safety iphone 18 pro dario amodei ios 27 artificial intelligence google nvidia
View all today's topics →