Anthropic said Claude was mistakenly given access to the internet.
Anthropic on Thursday (30 July) said it had found three instances where Claude models gained unintended access to the internet during cybersecurity evaluations prompted by a “misunderstanding” between the company and its testing partner Irregular.
The AI company said it launched a retrospective analysis of its testing systems on 23 July after rival OpenAI’s models were found to have hacked Hugging Face during testing earlier this month.
That breach had downstream consequences, when, earlier this week, US cloud company Modal revealed that the models also gained access to one of its customers.
Advertisement
In its analysis of more than 140,000 evaluation runs, Anthropic said it discovered three instances involving Opus 4.7, Mythos 5 and an internal research test model where the models broke through to the internet.
These occurred when the models were inside Irregular’s testing environment or interacting with it, Anthropic explained. The earliest incidents date back to April.
In one serious case, Opus 4.7 targeted a real company that shared names with a fictional company provided to it during testing, Anthropic said. Claude was able to extract application and infrastructure credentials from the business, and gained access to a database containing several hundred rows of production data, it added.
Anthropic explained that its test evaluation prompts explicitly did not allow internet access, but did not limit Claude’s reach. However, a misunderstanding between the company and Irregular left the machines conducting the tests with live internet. Neither party was aware of the errors until Anthropic’s analysis earlier this week, it said.
Advertisement
The Claude maker said it paused all cyber evaluations after identifying the breach and notified the three organisations its models hacked on Monday (27 July).
“Ultimately, many factors contributed to these incidents, but, consistent with a blameless postmortem culture, we’re approaching the fixes as if the responsibility were ours alone,” Anthropic wrote in yesterday’s blogpost.
Recent unintended cyberattacks carried out by powerful, ‘rogue’ agents have sent shockwaves across the AI industry, raising serious concerns around careful testing and models’ rapidly advancing ability to bypass boundaries.
“For threat actors with money to spend on tokens and access to less restricted models, the time taken to compromise a given target has likely reduced,” said Richard Davies, director of cyber solutions at Talion, earlier this week.
Advertisement
Hugging Face said that OpenAI’s agents accessed a sandbox hosted on a third-party provider’s infrastructure when they breached containment earlier this month. OpenAI maintained, in an updated statement, that none of its upcoming models were involved in the exploit.
Following the Hugging Face incident, members of the US Congress introduced a new bill which would require AI companies to be able to shut down, throttle or suspend their models if they go ‘rogue’.
However, some cybersecurity experts have said that missing governance and control is the reason behind the Hugging Face breach.
“The model, tooling and instructions were very loose, almost to the point it was told it could do anything on any system, which it clearly did,” said CybaVerse chief technology officer Simon Phillips.
Advertisement
“The story here isn’t about an AI model going rogue; the model did exactly what it was tasked to do.”
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Dario Amodei at the World Economic Forum Annual Meeting. Image: 2026 World Economic Forum via Flickr (CC BY-NC-SA 4.0)
If you’re a die-hard iPhone user, then there’s a strong chance that you already have access to Apple Arcade and don’t take full advantage of it. The gaming service is currently included with all tiers of the Apple One subscription — an all-in-one bundle that also includes the likes of iCloud Plus, Apple TV Plus, and Apple Music in one monthly fee.
Ultimate Guide to Apple Arcade
(Image credit: Apple / Future)
This article is part of our Ultimate Guide to Apple Arcade: the definitive guide to everything that you need to know about the gaming service. Be sure to browse the full series here.
Even if you don’t pay for Apple One, a free three-month trial of Apple Arcade comes bundled with every new iPhone, iPad, Mac, or Apple TV, plus, the service is available as a standalone subscription if you don’t want it bundled with anything else. Sounds great, right? But what actually is Apple Arcade, how much does it cost, and is it really worth the price?
Advertisement
I’ve spent this week getting to grips with all things Apple Arcade, from diving into some of its biggest exclusive games to comparing it to other competing services, in order to bring you this comprehensive breakdown of everything you need to know about it. Read on and become an Apple Arcade expert.
Latest Videos FromTechRadar
Advertisement
What actually is Apple Arcade?
Apple Arcade is a gaming subscription service by Apple designed for its iPhone, iPad, Mac, Apple TV and even Apple Vision Pro devices. It launched in September 2019 and gives you access to a huge library of more than 200 premium games that you can download and play offline.
Unlike many titles that you might download from the App Store, Apple Arcade games are wholly devoid of both ads and in-app purchases. They are complete experiences that you can dive into without the risk of annoying interruptions or being asked to shell-out real world cash for in-game items or downloadable content (DLC).
Advertisement
What kind of games are included?
Wherever you are, Apple Arcade is open | Parking Lot | Apple Arcade – YouTube
There are more than 200 games available on Apple Arcade, with options across a wide variety of genres. This includes a selection of high-quality original games such as fast-pace platformer Sonic Dream Team, cozy life simulator Hello Kitty Island Adventure, and beautiful role-playing game Fantasian.
There are also some ports of console and PC games, such as hit strategy game Sid Meier’s Civilization 7 Arcade Edition, Disney life sim Disney Dreamlight Valley Arcade Edition, and indie roguelike Cult of the Lamb.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
You will also find loads of premium versions of existing mobile titles with no ads or microtransactions in the likes of Doodle Jump 2+, Fruit Ninja Classic+, Bloons TD 6+, and much more.
You can use our quiz below for some hand-picked recommendations.
Advertisement
How much does Apple Arcade cost?
The Apple Arcade standard plan costs $6.99 / £6.99 / AU$9.99 a month.
You can save some cash by opting for an annual plan instead, which is $49.99 / £49.99 / AU$79.99 — a saving of $33.89 / £33.89 / AU$39.89 compared to 12 months of monthly payments.
Advertisement
No matter which of these two options you choose, you can share your Apple Arcade subscription with up to six family members at no extra cost.
Apple Arcade is also available as part of all Apple One tiers (Individual, Family, and Premier). Unlike Apple Arcade, Apple One is not available in an annual subscription format, so you can only pay for it on a monthly basis. You can view and compare all of the options below.
Swipe to scroll horizontally
Plan
Price
Advertisement
Included services
Sharing limit
Apple Arcade
$6.99 / £6.99 / AU$9.99 per month
Advertisement
$49.99 / £49.99 / AU$79.99 yearly
Apple Arcade
Up to six users
Apple One Individual
Advertisement
$19.95 / £18.95 / AU$24.95 per month
Apple Arcade,Apple Music, Apple TV Plus, 50GB iCloud Plus
One user
Apple One Family
Advertisement
$27.95 / £24.95 / AU$34.95 per month
Apple Arcade, Apple Music, Apple TV Plus, 200GB iCloud Plus
Up to six users
Apple One Premier
Advertisement
$39.95 / £36.95 / AU$52.95 per month
Apple Arcade, Apple Music, Apple TV Plus, Apple News Plus, Apple Fitness Plus, 2TB iCloud Plus
Up to six users
Advertisement
How to claim your Apple Arcade free trial
In most regions a new iPhone, iPad, Mac, or Apple TV now comes with a three-month free subscription to Apple Arcade. The offer is only valid for 93 days (that’s roughly three months), so if you have an eligible device you should consider claiming it quickly if you’re interested.
To do so, simply follow these four simple steps
Open the App Store on the eligible device
Tap the Apple Arcade tab at the bottom of the screen
The offer should appear automatically
Follow the on-screen instructions to redeem it
If you’re not eligible for a complimentary three-month subscription, there’s no need to worry — because new subscribers can still claim a one-month trial via the App Store.
Whether you claim three months or one month, bear in mind that a valid payment method will be required in order to get set up. This will be billed at the standard subscription price when your promotional period is over, so remember to cancel your subscription if you want to avoid any charges.
Do you need a controller to play Apple Arcade games?
The CRKD NEO S is a good pick for Apple Arcade. (Image credit: CRKD)
You don’t actually need a controller to play the majority of Apple Arcade games. On iPhone and iPad, almost every title supports full touch screen controls and can be enjoyed without any extra hardware.
If you’re playing on Mac, many titles support keyboard and mouse controls.
On Apple TV, you’re most likely to need a dedicated gamepad as there are only a few titles that work well with the included remote.
Advertisement
Of course, lots of games still allow you to use a controller on any device even if it’s not strictly required and I’d recommend it if you’re after an even more console-like gaming experience.
You can see some models that I’ve personally tested and would recommend for Apple Arcade below.
What about the competition?
If you’re strictly looking for a gaming subscription service for your iPhone, then Apple Arcade doesn’t really have much direct competition.
The biggest alternatives on that platform are cloud gaming services such as Amazon Luna, which you can access through your iPhone’s web browser. These stream games to your phone directly from a cloud server, which means that they require a constant internet connection and cannot be accessed offline.
They also don’t work too well with on-screen controls, which means a controller like the dedicated Luna Wireless Controller is required for anything but the most casual titles.
Advertisement
That said, cloud gaming does have some big advantages. You can access full console or PC games, including massive titles such as Fortnite, Fallout 4, or Shadow of the Tomb Raider. As they do not rely on your local hardware, they can also offer high-end graphics features such as maximum in-game settings and ray tracing — though slow or choppy internet can negate this by introducing visual artifacts.
If you have access to an Android Phone, Google Play Pass is a potential alternative. It’s cheaper than Apple Arcade but similarly grants access to loads of mobile games with zero ads or microtransactions. It also includes some productivity apps, meaning that it’s a little more versatile than the strictly gaming-focused Apple Arcade.
That said, its software library feels much more chaotic and less curated. It also lacks the compelling exclusive releases that I think really bring a lot of value to Apple Arcade.
Advertisement
Apple Arcade FAQs
Do Apple Arcade games work offline?
Yes, all Apple Arcade games work offline. This means that you can play them on your iPhone or iPad when you’re out of the house and don’t have a steady internet connection.
Is it worth getting Apple Arcade?
Apple Arcade can be worth getting if you frequently play mobile and want a more curated, premium experience. The lack of in-game ads and microtransactions means that you don’t have to worry about annoying distractions or impulse spending, while many of the exclusive games are high-quality experiences that are worth playing.
Do I lose my games if I cancel Apple Arcade?
You will lose access to Apple Arcade games if you cancel your subscription. You don’t need to worry about losing any progress, however, as your save data is stored by Apple via iCloud. This means you can pick up exactly where you left off if you resubscribe at a later date.
Can games leave Apple Arcade?
Although it is uncommon, games can leave Apple Arcade. When this happens you can keep playing the game for a short grace period, before it becomes unavailable on your device.
The Greenpan Frost is a frozen drink and ice cream maker. Within one hour you can be enjoying your favourite frozen treat, which is smooth and perfectly formed. I found it really easy to set up and use, but cleaning up was a bit of an operation. And whilst it is a compact design, it does still take up space on the kitchen worktop – which will become more noticeable if this appliance gets seldom use.
Makes a variety of drinks, snacks & desserts
Neat, compact design
Easy to set up & use
No single-serve
Narrow pouring shute (makes a mess)
Tricky to clean
Key Features
Introduction
Compact yet versatile, the Greenpan Frost Ice Cream Maker, Soft Serve & Frozen Drinks is a dedicated appliance that can make all sorts of frozen treats from five different modes within the hour.
Advertisement
By pressing just one button you can opt for a Slushie, Soft Ice Cream, Spiked Slushie, Sorbet or Milkshake. Turn a dial, and you can choose from seven different textures.
Whilst it’s £399 price makes it more expensive than rivals, you don’t need to freeze the mixture before using it, like you need to do with the Ninja Creami Deluxe, and it offers more customization.
Advertisement
Image Credit (Trusted Reviews)
Design and Features
Compact design
6 modes, 7 textures
Removable parts
The Greenpan Frost is a neat, compact machine that takes up little space on the kitchen worktop. Measuring 17.3(h) x 8.7(w) x 17.2(l) inches, it won’t quite fit underneath most wall cabinets, but it’s far enough away from the wall on the worktop to still be comfortably used.
It’s all controlled by a control dial and mode button; turn the dial to control the texture and press the dial to start or stop, and use the mode button to cycle between six modes.
Advertisement
Image Credit (Trusted Reviews)
Advertisement
These six modes will make you a chilled, iced drink or frozen desert in no longer than 45 minutes. Starting at number 1, you can make a slushie to make icy treats then; 2 for soft ice cream; 3 for spiked slushies; 4 for sorbets; 5 for milkshakes and 6 for extrude/clean.
It does not have an on / off switch.
You’ll do all the mixing in the 2QT (64oz or around 1.9L) mixing bowl, which is clear so that you can see the ingredients be transformed into a chilled or frozen treat.
Image Credit (Trusted Reviews)
Most of the parts are removable for cleaning. This includes the mixing bowl which unclips by turning it anti-clockwise and the stirring blade which can be slipped off. The handle can also be fixed into position with the pin latch.
Image Credit (Trusted Reviews)
Advertisement
It’s looks like a fun appliance with a pop-up cone holder and lever handle. It’s also available in a choice of five colours including Cream, Licorice, Berry, Pistachio and Cotton Candy. It arrives pretty much fully assembled; you’ll just need to attach the handle and drip tray.
Advertisement
Image Credit (Trusted Reviews)
In the box, the Greenpan Frost comes with the following accessories: bristle cleaning brush, 2x extrusion head gaskets, sealing ring, silicone cleaning brush/installation rod, handle and handle fixing pin.
Performance
All-in-one
Can make a creamy, frosted milkshake in 30 minutes
Quiet
Greenpan Frost is an all-in-one appliance that’ll stir and frost ingrients to make a selection of treats. It doesn’t do all the prep work though. For example, it won’t blend berries into a smooth pulp and it won’t dissolve sugar either.
The first treat that I made was soft ice cream. I needed to buy more whole milk, heavy (double) cream and vanilla extract. All these ingredients, along with the sugar, needed to be whisked together before pouring into the mixing bowl.
Advertisement
You’ll need a jug to pour in the whisked ingredients and a steady hand because the chute is narrow and, as I found, this can make a mess.
Image Credit (Trusted Reviews)
I then selected Soft Ice Cream Mode and chose a texture level of 4. It churned until the Frost switched to “Cool” and beeped one hour later.
At first I had a bit of bother to extract the ice cream – it didn’t start to drop when I pulled the lever down. Instead I *think* I panicked and pressed “Extract” mode and removed the handle (there’s my error) so it all started to drop onto the drip tray and I couldn’t stop it. I ended up filling up a glass vessel and spooning out the mixture into cone (the cone holder came in handy).
Advertisement
Image Credit (Trusted Reviews)
Lesson learned.
Advertisement
Next I tried making a Strawberry milkshake using “Milkshake” mode. I blended together the strawberries, vanilla and sugar before whisking in the whole milk and heavy cream before pouring in to the mixing bowl.
Again, I made a mess when pouring in the mixture to the mixing bowl.
Image Credit (Trusted Reviews)
I selected “Milkshake” mode and texture level 4. Then, 30 minutes later I heard a beep and the machine switched into “Cool” mode.
Initially I wasn’t ready to drink a cold milkshake so I left it whirling around in the mixing bowl. The Greenpan Frost will keep in “Cool” mode for two hours after the selected texture setting has been reached.
Advertisement
The recipe I had followed made enough milkshake for 3-4 people so while I enjoyed one glass of it, I extrududed the rest and put it on the fridge for the kid’s to enjoy later after school. When it was first extruded, it was too frosty for me (too frosty for a milkshake really), so it was enjoyed 30 minutes after leaving the mixing bowl; it was thick, creamy and fluffy.
Advertisement
It would have been a good idea to strain through a fine mesh to remove the seeds but, alas, I did not so some of these found there way around the seal in the extrustion head.
Image Credit (Trusted Reviews)
I also made raspberry sorbet using “Sorbet” mode. I dissolved some sugar with water and lemon zest, before adding to a bowl of blended raspberries with water. I then strained the seeds from the mix because I can’t imagine the sorbet will go down well with all the hundreds of raspberry seeds on the palette.
I poured the strained mixture into the mixing bowl and selected “Sorbet” mode, texture 1. Then, 40 minutes later it was ready to extrude.
Advertisement
Image Credit (Trusted Reviews)
The results were delicious, with the mixture evenly frosted – and it extruded perfectly. I only kept it in “Cool” mode for a few minutes before extruding because I heard a squeaking noise which I guess is from some resistance from the stirring blade inside the mixing bowl.
Advertisement
Image Credit (Trusted Reviews)
I recorded a noise level of 58dB of the GreenPan Frost when it was in use which is equivialant to a quiet street. The noise level increase to 64dB when it was in “Cool” mode.
To clean the Greenpan Frost I switched over to the Extrude/Clean mode after each recipe I tried. I poured a solution of warm water and liquid soap into the mixing bowl, to clean the bowl and stirring blade. I kept the handle levered down to empty it into a large bowl underneath (I removed the drip tray to get the bowl snug underneath the extrusion head).
After this, the mixing bowl, stirring blade and drip tray all needed washing by hand with warm soapy water. I found that, especially after mixing whole milk and double cream, there was a layer of fatty residue on these parts mentioned that the Extrude/Clean mode alone doesn’t budge. The extrusion head also trapped some residue around the seal that only handwashing (and patience) can remove.
Final Thoughts
I’ve had a lot of fun using the Greenpan Frost. I’ve made icy treats that have been previously shop-bought, and the results have been delicious.
Advertisement
Through from set-up to using the Frost it has been really easy, with only one dial and one button to navigate in order to achieve a treat some 30 minutes later. Whilst there is some prep work to the ingredients such as mixing and straining, the Frost stirs to even texture and temperature throughout the mix.
However, I found bulk-making to be a nuisance, owed to a lack of space in the fridge or freezer and storage units large enough to contain the treats. And whilst the overall design of the Frost is neat and compact, if it’s only going to be used once or twice a year then you might want to think again about buying it because it’ll only take up space in the cupboard.
Advertisement
Should you buy it?
Advertisement
You reguarly enjoy iced drinks and chilled desserts
It’s quick to make a slushie, ice cream, slushie, sorbet or milkshake.
Advertisement
You want to batch make and store
This machine is best for fresh treats enjoyed there and then, and is a bit more fiddly if you want to extrude and store the results.
Advertisement
How We Test
We test every small appliance thoroughly over an extended period of time. We use industry standard tests to compare features properly. We’ll always tell you what we find. We never, ever, accept money to review a product.
Find out more about how we test in our ethics policy.
Used to make ice cream, milkshake and… to use three of the five controls
Recorded the noise level when mixing
FAQs
Does the Greenpan Frost Ice Cream Maker, Soft Serve & Frozen Drinks keep treats cold?
Yes, it will keep treats cold for up to two hours.
Engineers make progress in stabilizing mission but push back the rendezvous date
Katalyst Space has confirmed that problems with its LINK spacecraft have delayed its attempt to rescue NASA’s Swift observatory, with rendezvous now targeted for the end of August.
Katalyst disclosed the delay in an update on the spinning spacecraft. Engineers used a thruster to cut LINK’s rotation rate from 9 degrees per second to approximately 4 degrees per second, with further burns planned.
Advertisement
Katalyst and NASA are also developing a new attitude controller suited to the spacecraft’s reduced capabilities. Engineers are determining which systems remain usable and testing their plans in a simulator before trying them on the vehicle in orbit.
The trouble has pushed the targeted rendezvous to the end of August. LINK is supposed to sidle up to Swift, survey it, grapple the observatory, and carry it to a higher orbit. For now, however, Katalyst says: “We’re focused on stabilizing the spacecraft and restoring core system functionality.” Any rendezvous attempt depends on that work succeeding.
LINK launched earlier this month, less than a year after NASA awarded Katalyst Space the contract for a rescue mission. The spacecraft encountered problems during commissioning before going into a spin over the weekend. Earlier this week, Katalyst reported that two of the three reaction wheels, used to control LINK’s attitude, were inoperable, but the team was working to stabilize the vehicle using its electric propulsion thrusters.
Time is running short. Swift is expected to enter the Earth’s atmosphere in the coming months. The observatory has enjoyed a prodigiously long life and far exceeded its primary mission, but its orbit is decaying and it cannot raise itself. LINK’s success could add years to Swift’s operational lifetime.
Advertisement
In January, almost all of NASA’s models predicted that Swift would re-enter by the summer of 2026. Most science operations were paused in February to buy more time. More recent predictions indicate that it could dip below 300 km, the altitude beneath which raising its orbit becomes more difficult, around November.
Katalyst must now stabilize LINK, secure NASA’s approval for its revised plans, and reach Swift before the observatory sinks too low for a practical rescue. ®
This year, Wikipedia is celebrating 25 years as the Internet’s encyclopedia that anyone can edit. In its first decade, the quirky experiment for passionate nerds exploded in popularity. It became a ubiquitous information resource and a homework helper for schoolkids, much to the dismay of skeptical teachers.
In its second decade, amid the public’s growing dissatisfaction with the mangling of facts in popular discourse, it took on a new role as information infrastructure, helping categorize and validate information worldwide. Wired magazine deemed it “the last best place on the internet.” The hope was that the volunteer project could serve as the antidote for misinformation. Platforms from Facebook and Twitter to Alexa and YouTube began embedding Wikipedia material to ensure that users had context for what they read or saw.
That role has become more acute in recent years. Artificial intelligence developers have relied deeply on Wikipedia to train the large language models behind popular chatbots, which weight clean, reasonably reliable information sources more heavily than the rest of the web. Chatbots and AI-powered search engines have intensified Wikipedia’s significance, even as they siphon its readers by answering questions directly, with fewer people going to the source site itself.
Advertisement
But as Wikipedia’s importance – and size – has grown, the size of the volunteer corps that maintains it has not, and the number of volunteer administrators, a key moderation role, has shrunk.
The Wikipedia community is also sensitive to its rising importance, but not in the way you might think. Contributors are keenly aware of political rhetoric that takes aim at their project or threatens volunteers. But the chief effect on volunteers has been a sense of heightened obligation to their global readership, which has gradually increased quality standards.
Advertisement
As a longtime volunteer myself, I’m often taken by the community’s perseverance and the people’s desire, above all, to get on with their work of summarizing the world’s knowledge.
The English language Wikipedia has maintained a reasonably steady number of contributors since 2010 – about 40,000 – yet its size and importance have grown. In 2006, it contained 1 million articles; in May 2025, it passed 7 million. A new issue is an influx of low-qualitycontent generated by large language models.
The steady decrease in administrators is especially concerning. Administrators are a subset of trusted users, elected by the community at large, who are given powers such as the ability to delete articles or block users from editing. Unlike moderators at for-profit platforms, Wikipedia cannot simply hire more administrators. There are slightly more than 800, down from almost 1,800 in 2011, and they’re not all active.
So Wikipedia’s role has grown, but it is held together by a relatively small, shrinking community of unpaid volunteers. To keep up, the community in general and administrators in particular have had to raise their efficiency, making trade-offs between maintaining open participation and raising article quality. These trends and their costs are well documented. They are clearly visible in one of the basic administrator routines: blocking.
Advertisement
Shown the door
Blocking is when an administrator determines that a user is so detrimental to the project that they must be prevented from making any further edits. The blocked user can still read Wikipedia, but cannot change it.
Unlike the opaque moderation systems at the large internet platforms that I normally study as a researcher, such as YouTube or TikTok, nearly every administrative action on Wikipedia is recorded in a public log. I used these logs for a study analyzing all 20 million blocks made on the English language Wikipedia over the past two decades. I looked for patterns in frequency, duration and reasons for a block. I also assessed whether those patterns corresponded to the growing trade-offs between openness and quality.
I found that the frequency of blocks has risen sharply in recent years due to administrators using bots to preemptively block proxies. Proxies are services such as virtual private networks, or VPNs, that people use to conceal their identity, often to facilitate abuse or manipulation on Wikipedia. One of these bots, ST47ProxyBot, was so active that it accounted for the most blocks in the site’s history. Preemptive proxy blocking likely prevents damage, but it can also occasionally stop good-faith contributors. Given the increasing popularity of AI agents and their disruptive potential, this practice is likely to continue to expand.
I then removed proxy blocks from the analysis so I could focus on humans who were blocked and why. In the early years, administrators made the majority of blocks for vandalism: intentionally bad or nonsensical edits. That has shrunk to about a quarter of all blocks today. Blocks have risen for promotional editing and for sockpuppetry — when one person creates multiple accounts to manipulate content. These shifts speak to Wikipedia’s increased prominence as a target for influence.
Advertisement
Signs of stress
What I found most interesting was administrators’ greater use of generalized reasons for blocking, such as “disruption.” Wikipedia defines disruption as “a pattern of editing that disrupts progress toward improving an article or building the encyclopedia.” But citing this can mean nearly anything seen as counterproductive. The trend is partly explained by “disruption” being in a list of boilerplate rationales that administrators can choose from instead of entering a customized reason.
But it’s also the kind of trend I would expect to see in a labor force stretching to keep up. Administrators don’t act arbitrarily, and their actions are publicly logged and closely scrutinized. A loss of trust leads to an administrator losing their position. But to be effective, general explanations for blocks rely on shared understandings that new users may not have. Research on blocked users shows that when a sanction feels vague or unfair, volunteers are more likely to walk away – or dig their heels in – rather than reform. Good for efficiency; bad for bringing new users into the fold.
Blocks are also lasting longer on average. That, together with preemptive blocking and generalized rationales, suggests that the volunteer community is increasingly prioritizing prevention, efficiency and content quality over efforts to rehabilitate new users.
And the work is not spread evenly among the roughly 800 administrators: For many years, the most active 10% of administrators have made about 80% of the blocks. That high number dropped to 37% in 2024, largely due to changed activity by a single prolific administrator.
Advertisement
Bearing the cost
Wikipedia’s openness is part of how its volunteer community grew in the first place. Now that Wikipedia has become infrastructure, that community is rationing openness to preserve quality for readers. If Cory Doctorow’s zeitgeist-capturing idea of platform “enshittification” is fundamentally about ruining the experience of end users for the sake of the shareholders, Wikipedia is attempting something like the opposite. The end-user experience is being preserved, and the people behind the scenes are bearing the cost.
Wikipedia has adapted remarkably well in its evolution from early web experiment to one of the most important global sources of information. The open question, for a resource that so many humans – and now machines – rely on, is how long the volunteer system can keep enduring the cost.
Ryan McGrady is Senior Research Fellow at the Initiative for Digital Public Infrastructure, UMass Amherst
Cloudflare summary logs a typhoon, two earthquakes, power failures, and thirteen government exam shutdowns
It also identified a fiber cut, drone damage to an AWS region, and a botched DNSSEC key rollover
The report’s sharpest finding is that Tanzania’s accidental power blackout looked almost identical in the data to its deliberate election-day shutdown in 2025
Cloudflare has published its latest account of what recently knocked chunks of the Internet offline, and the list reads like a catalogue of everything that can go wrong at once: a typhoon, two earthquakes a minute apart, a national power failure, ten government shutdowns timed to school exams, a fiber cut, drone damage to a cloud region, and a routine cryptographic key update that briefly made every .de website in the world unreachable.
Drawn from traffic telemetry on Cloudflare Radar, it is a useful reminder that the systems most people treat as a utility are held together by a surprisingly small number of things.
With geopolitics in the Middle East shaping traffic in Iran, the UAE, Iraq and Sudan, Cloudflare found that not only did the former’s traffic drop even after a shutdown ended two months ago, but the UAE seems to be one of the most affected by the on-again, off-again US-Iran conflict thanks to two AWS facilities being struck by Iranian drones.
Latest Videos FromTechRadar
Advertisement
An accidental blackout and a government shutdown look similar from the outside
Cloudflare’s insights tend to make for an interesting read on how the connected world functions, often defying expectations about traffic, online activity, and user behavior, with the recent FIFA 2026 World Cup being an excellent place to start.
When it comes to the most severe disruptions, one would turn to Iran’s approach, which cut off internet access during its conflict with the US, an engagement that also had ramifications for most of its Gulf neighbors.
Interestingly, Radar began picking up signs of restoration on May 26 2026, ending an 88-day shutdown that had left the country almost entirely offline since February 28, but it never reached peak pre-conflict levels.
By May 27, traffic had returned to 40% of pre-outage levels, consistent with reports that access was being reintroduced selectively. It has since climbed as high as 90% before settling at roughly 59% of pre-shutdown levels, suggesting that more stringent restrictions may be in effect even as the country grapples with a war that threatens to reignite at a moment’s notice.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The most consequential item on the list, as a result of the conflict, is ironically the one that does not look like an Internet outage at all. HTTP traffic to AWS me-central-1, the cloud region in the United Arab Emirates, has remained low, matching AWS status reports at the end of April 2026 stating that the region had been damaged by the conflict in the Middle East and could not reliably support customer applications.
Advertisement
This followed earlier reports in March of physical damage to facilities in both the UAE and Bahrain caused by drone strikes, with two UAE facilities directly hit. It also highlights an interesting insight: A cloud region has become the sort of concentrated dependency that a submarine cable used to be, with the added complication of being a physical target that is much easier to locate than an undersea cable.
(Image credit: Shutterstock)
The longest single disruption came from Super Typhoon Sinlaku, the strongest storm of the 2026 Pacific typhoon season so far, which tracked through the Mariana Islands in mid-April and passed just north of Guam. The island avoided a direct hit, but tropical-storm-force winds knocked out power, disrupted water systems, and took connectivity with them. Traffic from the territory fell as much as 80% below expected levels on April 13 and 14.
Venezuela lost connectivity on June 24 when two major earthquakes struck northern Venezuela within roughly a minute of each other, at Yumare and San Felipe, followed by an aftershock near the coast outside Caracas, coinciding with a fall in traffic visible across Fibex Telecom, which serves an estimated 1.6 million users.
Advertisement
Three days later, a power outage in Tanzania produced a sharp drop in HTTP traffic lasting at least five hours, with Cloudflare drawing parallels to the country’s election-related blackout in 2025.
Saint Lucia lost most of its connectivity on June 21 when traffic on Karib Cable’s network fell to essentially zero by 21:00 UTC and remained flat for the better part of a day, reportedly due to a fiber cut near the island. Karib Cable is one of the largest providers there, so the loss was registered nationally, with the country’s overall traffic falling by around 60% compared with the previous week.
In terms of a self-inflicted wound, Germany takes the cake: On 5 May, DENIC, the registry for the .de domain, performed a DNSSEC key rollover, the routine periodic replacement of the cryptographic keys used to sign a zone’s DNS records, and the process began producing invalid signatures.
Because DNSSEC-validating resolvers only trust answers whose signatures match the current published keys, a mismatch is read as evidence of tampering, so resolvers worldwide rejected every .de lookup and returned errors until normal service resumed at 23:15 UTC. To users, it did not appear to be a cryptographic failure. It presented as German websites not loading, email bouncing, and apps timing out. It resulted in global .de query volume going up during the outage rather than down, indicating that users were, as a result, looking for ways to access said sites, amplifying the failure, at least statistically.
Advertisement
Taken together, Cloudflare’s insights about the quarter are less a parade of exotic failures than a fairly consistent argument about concentration.
One registry’s keys gate an entire national domain for the whole world. One provider carries enough of Saint Lucia’s traffic to take the country with it. One cloud region hosts applications that have no idea they are under attack by a drone strike, causing unintended blackouts. The causes are both ordinary and extraordinary. It is the dependencies, however, that are extreme, making the case for redundancies worldwide.
Donald Trump swore he could turn the Lincoln Memorial Reflecting Pool into something he could use to bask in his own reflected glory. Instead, it turned out to be everything we expect from Trump: braggadocio followed by abject failure.
Trump hired some guys he used to do some stuff to his personal pool(s) back in the day. It was a no-bid contract — one that was immediately extolled by Trump as Great Stuff. According to Trump, his personal cabana boys could get the job done right, on time, and under budget.
None of that happened. His boys took to the pool repair, doing their level best to behave like government contractors. Trump then did a Glory Roll across the unfinished sealant with his motorcade to show off for the boys back at the White House. A week or so later, the pool was refilled. For a brief moment, it showed off the “American flag blue” Trump thought was missing from the original fixture. Then it turned into a blend of algae and peeling sealant.
Instead of pulling out his receipts and asking his pool boys whether this reflecting pool refurb was still under warranty, Trump claimed the floating chunks of blue sealant bobbing around in the green muck was the work of vandals. And, of course, he had political appointees willing to press this point on his behalf. Jeanine Pirro — the US Attorney for the District of Columbia — got right on it, arresting former Olympic canoeist David Hearn on felony vandalism charges.
Advertisement
Pirro alleged Hearn had damaged “two square feet of sealant.” Well, it takes $1,000 to make vandalism charges a federal felony. While this damage estimate is subject to federal no-bid contract markup, taking someone down for doing two square feet of damage is insane, especially when Trump is still out there claiming vandals cut a 150-350 foot gash into the pool sealant.
Trump also promised there was proof of his wild allegations — something that would presumably show up as the DOJ attempted to turn vandalism arrests into federal indictments.
A key grand jury witness in a case against a former Olympic canoeist accused of tampering with the Lincoln Memorial Reflecting Pool testified that the area was already damaged and would have required repairs regardless, lawyers said in a court filing Monday.
[…]
Advertisement
The witness, who is not identified, was the only person who testified about damages, and said that the property had already been damaged before, authorities say, Hearn stuck his hands in the water, according to Hearn’s team.
Now, for those of you unaware of how grand jury proceedings work (and especially for those MAGA folks who like to show up and be deliberately ignorant), we’ll break this down quickly. A grand jury is not like a regular jury. Its sole purpose is to decide whether or not the government has enough evidence to support an indictment. The accused person is not there, nor are they represented by the lawyers. This is completely non-adversarial. And YET, the government’s witness testified to the grand jury that the pool was already damaged before the accused even arrived on the scene of the alleged crime.
What’s absolutely wild is that the DOJ still got its indictment despite this damning testimony from its own witness. Welcome to Trump Town, I guess. But we’ll see how long this indictment lasts. Hearn’s legal reps have filed a motion demanding copies of grand jury documents because it’s pretty fucking clear some bullshit must have been pulled to get Hearn indicted even though a government witness testified that the pool was already in shambles.
Lawyers for David Hearn, a 67-year-old who represented the United States at three Olympic Games, submitted a court filing seeking access to transcripts of the grand jury testimony as well as the instructions given to the panel that ultimately indicted Hearn, claiming that there were “irregularities” in the proceedings that led to the indictment.
[…]
Advertisement
In the filing, Hearn’s legal team suggests that the jury was not “properly instructed” on the crime Hearn stands accused of, noting specifically that felony destruction of property requires the perpetrator to have caused $1,000 or more of damage. The attorneys pointed to the testimony of the federal government’s own witness, an official from the National Park Service, who suggested that the pool was damaged long before Hearn interacted with the pool and that repairs were already being sought.
The full filing [PDF] by Hearn’s legal team is embedded below. It’s worth a read. And I certainly hope the judge grants this motion because if it contains the sort of stuff these accusations suggest it the documents might contain, this won’t be the first time the Trump administration has been caught cheating even though the process already allows the government to put its prosecutorial thumb on the scales.
Morning routines often fall apart around a single stubborn task. Eggs demand attention right when attention feels scarcest. Crack one wrong and shell fragments appear. Leave the pan a second too long and yolks firm up past preference. Busy households skip the whole thing more often than they admit.
Cheffy, a small company based in San Francisco, created E.G.O.R. to make your life easier in the kitchen. The name stands for Efficient Gastronomic Operational Robot, however some early accounts simply referred to it as Egg Go On Robot, which is acceptable. The gadget just sits on your counter and solves the egg problem, allowing you to continue with your day.
THE PERFECT GIFT: Whether it’s a birthday, a White Elephant party, or Father’s Day, the Breakfast Sandwich Maker makes a fantastic gift for all…
MAKE 1 OR 2 SANDWICHES. Cook one or two sandwiches at once with this dual breakfast sandwich maker. It’s great for couples, kids and extra guests.
QUICK, EASY AND READY TO EAT IN 5 MINUTES: This sandwich maker lets you easily create a breakfast, lunch or dinner sandwich in 5 minutes or less…
Simply add whole chicken eggs into the chamber. Choose one of the seven egg styles from the little display, which includes three small buttons. Sunny side up keeps the yolks fluid and the whites perfectly set. Over easy, medium, and hard all have a finishing lid that allows the top to steam cook without any flipping. Soft, medium, and hard boiled varieties are placed in different trays for you. There’s also a crack only setting, in case you need to break eggs into a bowl or batter. It can hold two eggs in the frying pan and six in the boiling tray, from peewee to giant.
Advertisement
The patent-pending technology cracks each egg with ease. The contents fall into the pan or pot, while the shells go into a little compartment inside that you can discard later. You do not need to be concerned about seeming foolish. You can also simply put all of the elements that come into contact with food in the dishwasher, and there’s even a keep-warm function that keeps the eggs at serving temperature even if you’re running late.
T.O.A.S.T.R., an optional toaster, syncs with the egg cooker, allowing you to cook both items at the same time. You can put in thick slices of bread, bagels, or waffles, and it’s automatic, so you won’t have to jump when it raises or lowers the toast. Consistent browning and a crumb tray complete the toaster operations. Both machines have the same eggshell-white finish. The E.G.O.R. unit measures about 7.5 inches broad, 16 inches long, and 12 inches tall, weighing around 8 pounds. It uses between 500 and 1000 watts, depending on the setting.
The founder, Arjun Mehta, described the whole thing as a response to how difficult it can be for people to get by on a daily basis, particularly when it comes to simply running a family. Early supporters were parents attempting to get their kids out the door on time and people who struggle with fine motor activities. On Kickstarter, you could get the egg unit alone for anywhere from $199 (early bird discount) to $299, with the toaster costing between $349 and $499. Those backers hope to receive the egg unit in late 2026. After the campaign, they want to sell the egg unit for approximately $400.
When I started at Spectrum 25 years ago, a senior editor suggested that I find a “rabbi,” by which he meant someone who could mentor me in how EEs approach problems and evaluate potential solutions.
I didn’t find one right away. Then in 2005 we decided to do a special report, focusing on the challenges of enterprise software development. I suggested we invite IEEE Life Senior Member Robert N. Charette, a self-described risk ecologist, prolific book author, and leading authority on risk management and software engineering, to explore in our pages the myriad reasons software projects fail. His seminal article “Why Software Fails” is still read in university engineering classes today.
IEEE Life Senior Member Robert N. Charette is one of IEEE Spectrum’s most prolific authors.Robert N. Charette
It was, as they say, the beginning of a beautiful friendship. I had found my rabbi, one who shared my love of writing. We settled into a rhythm that would last more than 20 years, talking on Friday mornings about a range of topics including the growing ubiquity of software in our lives.
So when I became Spectrum’s website editor in 2007, he was the first contributor I tapped to start a regular blog (remember those?). The Risk Factor was born and over the course of more than 10 years and 1,750 posts, Bob chronicled hundreds of software debacles, culminating in “Lessons From a Decade of IT Failures,” which won a Jesse H. Neal Award for Best Infographics in 2016. Ironically, yet predictably, those infographics were created in a software package that is no longer supported and thus are lost to the bits of time.
Advertisement
“I like the expression on the fish just before it’s going to be swallowed by the heron.”Robert N. Charette
Bob, however, was not a one-trick pony. In between his full-time job running his two management consultancies and raising a future biochemist and a future civil engineer, his daughters Maura and Megan, he also wrote many deeply reported and insightful articles. These include last year’s “The Doctor Will See Your Electronic Health Record Now,” the eye-opening 12-part series and e-book The EV Transition Explained, and my personal favorite “Automated to Death,” about the deadly consequences of the automation paradox as manifested by the cyberphysical systems that pilot planes, trains, and automobiles.
“The young bald eagle I photographed in September 2024 had bands that I could read which identified it as a female born in May 2024, near Lexington Park, St. Mary’s County, Maryland, about 65 miles away from where I live.”Robert N. Charette
His main goal all along has been to make software visible, as he told me one Friday in July. “Software is all around us, but we don’t recognize it at all,” he said. “I really wanted my stories to help people better understand complex software systems. You can’t see software, you can’t touch it, you can’t taste it. You may feel the consequences of software failure, but you never see the reason itself.”
When he told me that he was hanging up his hat as a contributing editor to focus on nature photography and to write a handful of fictional trilogies, including one entitled “The STEM Murders” featuring an engineer-turned-detective and his rabbi, I asked him which of his Spectrum articles had the biggest impact.
“The hummingbird I caught with the yellow of a road curb behind it.”Robert N. Charette
He singled out the 2013 feature “The STEM Crisis Is a Myth.” “Spectrum gave me a platform to question the assumption that we needed more STEM graduates. Until then, people didn’t really realize how much of the STEM crisis was a mythology that was perpetuated by employers and the academic community and was foisted on the IEEE community,” he said.
Advertisement
Charette made a career of questioning assumptions. The best way to mitigate risk, he told me as our Friday chat drew to a close, is to be careful making assumptions in the first place. “My main risk maxim is assumptions made are risks accepted.”
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).
Rails is a popular open-source web application framework written in Ruby for building websites and web apps. It uses the built-in Rails component Active Storage for handling file uploads and attachments.
Rails maintainers published an advisory about the CVE-2026-66066 flaw, which received a critical severity rating.
According to the security bulletin, CVE-2026-66066 is exploitable when libvips is used, allowing an attacker to upload a specially crafted image to a vulnerable application and read arbitrary files on the server.
Advertisement
Another prerequisite for the attack is that the server needs to allow image uploads from untrusted users.
If these requirements are met, an attacker may access app files, including the process environment, which typically contains ‘secret_key_base’ and credentials for databases, cloud storage, and other services.
CVE-2026-66066 impacts Active Storage before 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1.
Rails 6.x is only affected if Active Storage has been configured outside its defaults.
Advertisement
The Rails team recommends upgrading to libvips 8.13 or later and rotating the ‘secret_key_base’ (the Rails master key), database credentials, Active Storage service credentials, and any other secrets accessible to the application process.
For systems running libvips 8.13 or later, administrators can temporarily disable the vulnerable functionality by setting the VIPS_BLOCK_UNTRUSTED environment variable or calling Vips.block_untrusted(true) when using ruby-vips 2.2.1 or newer.
There is no workaround available for apps that use libvips before 8.13.
ImageMagick users are not affected by this vector. However, libvips is the default processor in the official Rails Docker images, and also Debian and Ubuntu setups.
Advertisement
The Rails team said it has intentionally withheld technical details for the vulnerability to reduce the risk of exploitation before users have time to apply the updates.
Full technical details were initially scheduled to be disclosed on August 28 on the Rails forums.
The vulnerability was discovered and responsibly reported to the Rails team by researchers from Ethiack and GMO Flatt Security Inc.
Advertisement
Security firm Akamai has also published a warning about CVE-2026-66066, naming the attack chain “KindaRails2Shell,” and warning about its RCE potential.
“With the secret_key_base compromised, the attacker holds the master cryptographic key to the application,” explains Akamai.
“They can forge session cookies, sign global IDs, and manipulate serialized data, which directly translates into full RCE on the underlying server.”
Akamai says it coordinated with Ethiack before public disclosure to prepare protections for customers, and has now released web application firewall (WAF) protections.
Advertisement
Ethiack noted that a WAF might buy admins some time, but attackers using AI tooling should be able to reconstruct the attack chain based on the patch diffs.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The last year or two has seen relatively affordable multi-material printers hit the market, and the question that [Tom Nardi] and I were kicking around when he was writing up the 2025 year-in-review article was what it was going to mean for our folks. I don’t think he got it wrong per se, but his heading for that section “Grandma is 3D-Printing in Color” only tells half the story.
He did get that part right, though. We’ve certainly seen a flourishing of multi-material designs out there that take advantage of the availability of (usually) four colors. The ability to print in color has given life to the purely decorative models, of course. Think full-color Pokemon desktop toys, for instance. But even functional prints have benefited from contrasting color labels printed right into the box, not to even mention the multi-material supports that pull off easier and cleaner than ever before.
Since most of these multi-filament machines are pretty much locked down as far as hardware tinkering goes, our sights were firmly locked on what the end-user would do with the new capability. But we overlooked the third axis of 3D printering: the software hackers. And it’s precisely in this area of slicer and path-planning that we’ve seen some of the coolest developments this year. Why? Because people have the hardware in their hands that they need to test out the algorithms.
Advertisement
FullSpectrum and the more recent ImageMap are two techniques to get the missing in-between colors out of a four-filament printer, and in particular ImageMap tries to get the job done faster, and with fewer purges. We are amazed to see two different approaches to color blending popping up in just a few months of each other, and we have no doubt that work on this is going to continue.
At the end of the day, this really is just “put new tools in the hands of creative hackers, and they’ll find new ways to use them”, so we shouldn’t have been surprised at all. But if this is what comes out of the commercialization of the multi-material printer, what’s going to come when some of the more esoteric machine designs go mainstream? We can’t wait to find out!
You must be logged in to post a comment Login