The EPA is proposing to eliminate a federal rule requiring states to notify the public and accept comments before approving air-pollution permits for industrial facilities, including data centers and the power plants built to supply them. A separate EPA proposal from last month would also allow developers to begin construction before permits are finalized. These changes come as data centers expand rapidly across the rural South, disproportionately affecting Black communities.
Nscale, a UK-based AI data center company, has named Fidji Simo, who recently departed OpenAI's No. 2 role, to its board of directors. She joins other prominent tech figures including Sheryl Sandberg, Susan Decker and Nick Clegg as the company prepares for a possible public listing this fall.
Florida's Department of Highway Safety and Motor Vehicles confirmed the ShinyHunters extortion group breached its DAVID driver database on September 4, 2026, after the gang claimed to have stolen over 200,000 driver records. FLHSMV said the intruder used login credentials from a single Plant City Police Department account that had been improperly saved on the employee's personal device, contradicting ShinyHunters' claim that it exploited a password-reset flaw across multiple accounts.
Apple published a detailed study comparing the heart rate sensing of its new Health Sensing System in Apple Watch Series 12 and Ultra 4 against rivals like Garmin, Google Pixel Watch, Huawei, Samsung, WHOOP, and Oura Ring. The test involved over 1,400 participants across five sites in the US and Malaysia, using a Polar H10 chest strap as the accuracy benchmark during activities like running, cycling, HIIT, and daily tasks.
Trezor disclosed that hackers who compromised 138 accounts at email marketing provider Brevo used the access to send roughly 347,000 phishing emails to its customers. The messages, disguised as security alerts, directed recipients to a fake app designed to steal their wallet backup passwords. Trezor says its own products and account systems were not breached, but the stolen credentials could let attackers drain victims' crypto holdings.
Microsoft has detailed a social engineering campaign, active since May 2026, in which attackers tied to groups like ShinyHunters and Helix pose as corporate IT help desks and warn employees their passkey, MFA, or SSO settings need urgent updating. Victims are steered to convincing fake Microsoft login pages—often via SMS to personal phones—where attackers harvest credentials and session tokens using adversary-in-the-middle and device-code phishing techniques, rather than actually registering new passkeys.
Oracle reported fiscal first-quarter revenue of $19.35 billion, topping analyst expectations, with net income climbing 60% to $4.7 billion. The gains were driven by a 62% jump in cloud revenue, including a 121% surge in cloud infrastructure sales, prompting shares to rise more than 6% in premarket trading.
Fidji Simo, a former OpenAI executive, has taken a seat on the board of Nscale, a startup that builds data centers for AI workloads and has raised billions in funding. The move comes as Nscale reportedly prepares for an eventual public listing.
Conviva engineers tried replacing mmap with io_uring for reading large Arrow IPC files in their DataFusion-based analytics engine, hoping to fix latency spikes seen under heavy concurrent query loads with mmap. Instead of resolving the problem, the io_uring approach ran slower, and the team's investigation traced the original mmap issue to page-cache thrashing and excessive page faults under high concurrency rather than the memory-mapping mechanism itself.
Trezor disclosed that a breach at its third-party email provider Brevo let attackers send fake security alerts to its opt-in newsletter subscribers, reaching roughly 347,000 email addresses. The fraudulent messages warned of a fake microcontroller vulnerability and pushed recipients to a malicious app requesting wallet backup phrases; Trezor says 2,500 people clicked the link before it disabled the domain within 20 minutes.
A developer found that copying the login.keychain-db file from one Mac to another no longer works on macOS Tahoe when the destination Mac has a Secure Enclave chip. Previously, users could transfer this SQLite-based keychain file and unlock it on a new machine simply by entering the correct password, but that method now fails.
ID verification company IDScan disclosed that hackers accessed its systems without authorization, a breach later linked to a criminal marketplace called Nexus selling scans of over 170 million identity documents. Security researcher Brian Krebs verified the stolen trove includes 153 million driver's licenses, 10 million ID cards, 3 million passports and travel documents, and hundreds of thousands of medical cards, mostly belonging to US residents with some Canadian records included. The attackers claimed to have quietly siphoned data from IDScan's systems for more than a year before being detected.