Google is suing to dismantle the infrastructure behind an alleged massive AI-powered cybercrime operation.
On Friday, the tech giant announced a lawsuit against an alleged Chinese cybercrime network called Outsider Enterprise, which Google says uses AI in its campaigns to send scam text messages impersonating Google and other brands to steal passwords and credit card numbers.
Outsider Enterprise has financially scammed “hundreds of thousands of victims” with losses “estimated in the millions.” The group deployed 9,000 fake websites, one million fraudulent web domains, and 2.5 million texts sent to Android users in a two-week period, according to Google.
The company said, “55,000 spam texts were flagged by Android users in just two weeks this past May — that’s more than two text spam complaints a minute.”
Advertisement
Google said it uses “AI-powered tools to fight AI-powered scams,” which enable the company to detect scams and alert users of suspicious calls and text messages, leading to the interception of more than 10 billion scam messages a month.
The company said it has been collaborating with AT&T, T-Mobile, and Verizon to block the scam text messages, and said it is coordinating with the FBI.
An FBI spokesperson told TechCrunch that the bureau, in coordination with Google and Lumen’s Black Lotus Labs, seized several domains used by the cybercriminals, as well as Shopify storefronts and accounts used to test the operation’s phishing service.
The spokesperson said that since July 2023, Outsider Enterprise’s phishing platform enabled cybercriminals to steal “at least an estimated 3,870,000 stolen credit cards and a corresponding estimated $1.9B in losses.”
Advertisement
Inside Outsider Enterprise
In its complaint filed as part of the lawsuit, Google laid out the evidence it gathered against people involved in the Outsider Enterprise operations, whom the company said are foreign-based cybercriminals whose real identities are unknown. This group “built, maintains, and uses a turn-key, online software suite that enables criminals, regardless of technical skill, to publish fraudulent websites designed to rob victims and enrich themselves,” according to the complaint.
Google said this “phishing-for-dummies” software called Outsider, which costs $88 per week or $200 per month, allows operators to create fake websites with the help of AI platforms, including Google’s own Gemini. The fake sites impersonate several services and companies, such as telecom providers, financial institutions, government agencies, and retailers.
To lure people to the fake websites, the cybercriminals collaborate with one another to send victims malicious text messages, or purchase ads. The common goal is to steal passwords and corresponding multi-factor codes as well as financial information, which the scammers can do by receiving the data that victims input into the fake websites, with the information being transmitted through Outsider’s platform in real time.
“Part of the Outsider software’s appeal is the ease with which someone with limited technical expertise — like many members of the Enterprise— can purchase the software, execute various phishing attacks, and, upon purchase, meet other members of the Enterprise who are proficient in other areas,” Google wrote, referring to Telegram channels where the cybercriminals can collaborate, train each other, discuss strategies, and develop phishing attacks. “The Enterprise brazenly coordinates its efforts in open and largely uncoded discussions on Telegram.”
Advertisement
According to Google, the Outsider platform allegedly offers cybercriminals “more than 290 pre-built templates that mimic the legitimate websites” that generate replicas of real websites “in minutes,” along with guides on how to “weaponize AI-generated code,” as well as a dashboard to track progress of phishing campaigns. The cybercriminals have allegedly used Google Drive and Google Cloud infrastructure to host the phishing websites.
“The Outsider software has been used to create over a million phishing websites to swindle innocent victims out of millions of dollars,” Google wrote in the complaint.
To give an idea of the scale of Outsider Enterprise’s operation, Google said that over a five-month period, from November 14, 2025 to April 14, 2026, the company detected more than 1.59 million URLs connected to it.
Google said the Outsider Enterprise operation is made up of several groups of cybercriminals: those who develop and maintain the phishing software and website templates; those who supply lists of targets curated from public records, social media, and data breaches; a “spammer group” that provides tools and the infrastructure to send scam texts in bulk, which includes smartphone banks, SIM cards, and modems; and those who monetize the stolen credentials and launder the stolen money.
Advertisement
A screenshot showing a Telegram message where a cybercriminal advertised stolen digital credit cards on several cellphones. Image Credits:Court document
The cybercriminals have stolen “at least 36,000 payment cards issued by financial institutions in 95 countries,” according to Google.
The company accused the people behind Outsider Enterprise of impersonating Google and its brands, of infringing its copyright, of racketeering activities, of committing wire fraud, and false advertising. With the lawsuit, Google is seeking compensatory and punitive damages, and an order to stop the criminals from carrying out their activities.
This story was originally published at 10:26 a.m. PDT and has since been updated with new information from Google’s complaint, and the FBI’s comment.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
John Boss needed reliable oversight for a workshop packed with projects still under wraps. Standard internet cameras record events after the fact and offer little in the moment. He chose a different route and built Walter, a workshop sentry meets security robot, instead.
Walter hangs hung from the ceiling on a unique motorized mount, which at first view resembles a high-end pan-tilt security camera. The camera module, lights, and sensors sit in the tiny black shell, but a second look changes everything, as the inclusion of a full-fledged Nerf blaster gives the whole thing personality.
A1 mini + LED Lamp Kit for Creative Light Projects: Bring your ideas to life with the included LED Lamp Kit. Simply print compatible lamp models and…
The Perfect 3D Printer for Beginners: A1 mini 3D Printer is designed to make 3D printing easy from day one with automatic calibration, simple setup…
Experience the Bambu Lab Ecosystem: Access MakerWorld’s huge library of ready-to-print models, manage prints through the Bambu Handy app, and enjoy…
A geared lazy Susan bearing controls the unit’s movement, allowing it to swivel smoothly in a full circle. Stepper motors control the pan and tilt movements through a pulley and gearing arrangement. A slip ring keeps the cables from twisting or becoming tangled as the joint rotates, while limit switches keep everything under control in either direction. Overall, the movement is relatively rapid and precise.
Advertisement
The Raspberry Pi 5 serves as the Walter’s brain, processing all of the video from the USB camera, running computer vision procedures to detect and track movement, managing network connections, and making major decisions. Meanwhile, an Arduino Nano clone serves as the motor control system, accepting direct orders from the Pi to ensure responsiveness while the Pi works on the vision and logic. An Android tablet combined with a gamepad allows you to control from anywhere while also providing a low-latency visual stream.
When Walter is left to its own devices, it operates in Sentry mode. Motion detection comes in and can even give you notifications, after which computer vision takes over and tracks whatever caused the movement. The camera and mount maintain focus on the subject without requiring human intervention at any point. Voice recognition adds an additional layer of control; a microphone listens for orders or a spoken password to activate or disable the system, and a small USB speaker allows Walter to respond, give a challenge, or send you an alert.
The defensive options are a little more intriguing, as you get two high-intensity LED floodlights that can either flood the area or generate some very blinding glare. A pair of lasers provides a couple of brilliant points of light that are useful for aiming and visual emphasis. Then there’s the Nerf blaster, which can shoot darts under human or automatic control, and the noise alone is enough to deter even the most determined unwanted visitor.
Walter is the real deal, as it watches the room like a standard camera, but also moves, speaks, shines a light, and generally participates when necessary. When not in use, the ceiling mount hides it, and the pan-tilt mechanics and software allow it to cover the entire space. For a maker space with work that isn’t quite ready for public viewing, the system provides an excellent blend of surveillance and active deterrence that seems like it’s on your side rather than simply sitting there looking technological. [Source]
OpenAI burned through $3.7bn in the first three months of 2026, more than half its revenue of $5.7bn over the same period, according to The Information, which cited documents the company shared with shareholders.
Both numbers tripled from a year earlier, a symmetry that captures the company’s peculiar position: growing faster than almost any business in history, and spending faster still.
The tripling is the figure worth pausing on. Revenue of $5.7bn in a single quarter would be the envy of nearly any technology company; revenue that grew threefold year on year is rarer still. The trouble is that the cost of producing it grew at the same rate.
Scaling has not yet bought OpenAI the operating leverage that usually rewards a company this size, because the thing it sells, frontier-model inference, gets more expensive to deliver as more people use it.
The balance sheet looks, on its face, reassuring. OpenAI held more than $73bn in cash and marketable securities at the end of the quarter, up from $40bn at the end of December.
Advertisement
That jump reflects a large funding round announced at the end of March rather than money thrown off by the business, a distinction that matters when the quarterly burn is measured in billions. The cushion is real; it is also, in part, freshly raised.
OpenAI has also said it filed confidentially for a US initial public offering that could come as early as September and value the company at up to $1tn.
A flotation at that level would be among the largest in history, and it would put the kind of quarterly numbers reported this week in front of public-market investors who tend to ask harder questions about the path to profit than late-stage private backers do. The company has moved quickly on the filing as rivals race to list.
Advertisement
The pattern is not new for OpenAI, which has spent its way through every previous stage of its growth on the bet that scale eventually pays. The company has spoken about spending on the order of tens of billions in a single year on compute, research and infrastructure, and has indicated it does not expect to turn a profit until the end of the decade.
The Q1 burn fits that trajectory rather than departing from it. The novelty is the size of the numbers and the proximity of a public listing that will expose them to a different class of scrutiny.
None of the figures in the report came from OpenAI directly, and the company did not comment publicly on the specifics. What the numbers describe, if accurate, is a business operating at a scale and a loss that are both expanding in lockstep, ahead of a listing that will ask whether the second can ever stop chasing the first.
Samsung is turning a fictional gadget from the upcoming Spider-Man: Brand New Day into a real-world experience.
The company has announced SpideyTracker.com, an interactive website inspired by a key feature from the new Marvel film.
In Brand New Day, Peter Parker’s friend Ned Leeds creates a website that helps New Yorkers track Spider-Man’s whereabouts in real time. Samsung has now recreated that idea for fans. Now, they can follow Spider-Man sightings and events leading up to the movie’s release.
The site features a pixel-art map and will track Spider-Man appearances at live events, creator collaborations and other promotional activities throughout the summer. Users can also sign up for notifications. This allows them to stay updated whenever a new sighting is reported.
Advertisement
The project ties into Samsung’s wider partnership with the film. Devices including the Galaxy Z Flip, Galaxy Z Fold and Galaxy Watch feature prominently in promotional material for Spider-Man: Brand New Day. Therefore, Samsung is positioning the tracker as an extension of the movie rather than a traditional marketing campaign.
Advertisement
While details on exactly how the tracker will operate remain limited, Samsung says the experience is designed to bring a piece of the film’s world into real life. A video explaining the platform in more detail is expected to arrive alongside the launch.
The concept may feel familiar to Spider-Man fans. Recent PlayStation games introduced the Friendly Neighbourhood Spider-Man app. This app lets New Yorkers report crimes and incidents directly to Peter Parker and Miles Morales. SpideyTracker.com appears to take a similar idea and adapt it for the real world.
Advertisement
SpideyTracker.com officially launches on June 17 at 3pm ET, timed to coincide with the release of the film’s second trailer. Meanwhile, Spider-Man: Brand New Day is set to arrive in cinemas on July31. This gives fans plenty of time to put their Spider-Man tracking skills to the test before the movie lands.
Disclaimer: Unless otherwise stated, any opinions expressed below belong solely to the author.
The headlines will tell you that Singapore’s property market is finally cooling down. In early 2026, the HDB resale price index dipped by 0.1%, signalling a long-awaited breather for exhausted homebuyers.
But don’t pop the champagne just yet.
HDB prices are showing signs of flatlining.
At the exact same time, million-dollar public housing transactions surged by over 17% quarter-on-quarter. In prime, mature estates, seven-figure price tags are no longer surprising—they are becoming the norm.
But it isn’t inflation, and it isn’t a failure of the public housing system. It is the system doing exactly what it was designed to do.
Advertisement
In fact, the slowdown in price appreciation may not be something to be happy about at all.
More than a home
Singaporeans complaining about rising prices are usually found among buyers, not sellers. And only those who are forced to purchase their homes in the resale market, rather than directly from the government, as BTOs come with significant discounts.
In reality, as long as you already own an apartment, then relative price movements don’t affect you too much, as the tide lifts all boats. You buy for more but you also sell for more.
However, from the very beginning of the HDB system, the government conceived it not only as a way to provide affordable homes to all Singaporeans but as an appreciating asset that adds to your pension when you retire.
Advertisement
The logic is very simple: you usually start a family in a larger apartment, fit for two adults with children, who then go on to buy their own when they grow up, making downsizing an attractive option for ageing parents.
Image Credit: allensima/ depositphotos
As long as the apartment increases in value in line with or above general inflation, the difference you pocket from buying a smaller, cheaper flat can grow and supplement your retirement income—either directly or through a CPF top-up, which can also earn you an additional government grant.
Once we accept that prices should keep going up, then it’s only inevitable that they must reach the million-dollar mark at one point.
In fact, some are approaching S$2 million already, like the recent record-setter in Bukit Merah, sold for S$1.728 million with 92 years left on its lease. Expect to see more of those each year.
Apartments outpaced incomes by less than you think
Between 2015 and 2025, the Resale Price Index increased by about 50.7%. At the same time, the median household market income has gone up by 42.7%, against cumulative inflation of around 19 %.
Advertisement
So, yes, Singaporeans are paying relatively more for housing than a decade ago, but not by much, just 8%
Now, consider the opposite scenario: what if home prices had stayed level in the same conditions?
It would certainly be a boon for buyers of second-hand HDBs, but the elderly could lose close to 1/5th of their nest egg, eaten away by inflation. It wouldn’t be a reason to celebrate. On the contrary, it would suggest that the system has failed those it was supposed to help when they really needed it.
Image Credit: Wirestock/ depositphotos
After all, new entrants still enjoy BTO benefits and make a substantial profit between the launch price and MOP. The elderly may, at most, receive a CPF grant of up to S$40,000, which wouldn’t cover their losses.
So, the ideal range within which resale HDB prices should fluctuate is above inflation but below salaries. It is where all Singaporeans benefit. Those still at work can afford bigger, better homes, while those in retirement can extract more value from theirs.
Advertisement
For the past 10 years, that range would fall between 20 and 42%—a bit below the 50.7% recorded. But even then, the number of million-dollar apartments reaching the market would still be high, and grow each year.
It’s inevitable.
And there’s no reason to complain, because one day, this relentless march upwards is going to benefit you too.
Read other articles we’ve written on Singapore’s current affairs here.
As simple of a concept flow batteries are, the used chemicals can still be somewhat problematic in the context of a school experiment. To this end [Markus Bindhammer] decided to implement a flow battery version that uses compounds from green tea for its electrolyte, based on a German research paper from 2016.
These organic flow batteries can use gallic acid, pyrogallol as well as the polyphenols in green tea, making them rather safe even in the hands of more careless students. The demonstrated flow battery uses a carbon electrode with activated carbon around it to increase surface area, a platinum wire electrode, and a graphite foil as as third electrode.
In the paper a silver electrode is also used, along with the additional electrodes, and a terracotta flower pot as the barrier between the carbon and graphite electrodes, with [Markus] further explaining that there are fortunately cheaper options than what he is using, especially with the flower pot instead of a special ceramic vessel.
The electrolyte solution has epigallocatechin gallate (EGCG) dissolved in it, which here comes in the form of finely ground green tea powder (commonly known as matcha), which so happens to be pretty rich in this substance. In the below graphic by [Markus] you can see the complete set of solutions and other relevant details.
Advertisement
Of course, the performance of this type of flow cell isn’t amazing, with a cell voltage of less than a volt and a few mA of current, but it’s enough to spin a small fan, and to light up a few LEDs. This would be more than enough to demonstrate the reaction and flow cells in general, as long as you don’t mind donating some tasty matcha to science.
The news comes amid the official opening of a new premises, which is also part of NTT Data’s €16.5m investment.
NTT Data, a Tokyo-headquartered AI, digital business and technology company has today (17 June) announced the creation of 50 jobs to be based out of a new Dublin office. The new premises replaces a previous Dublin-located base of operations and is part of a €16.5m investment into the local economy.
According to the organisation, the investment will focus primarily on jobs creation, as well as AI and digital services R&D in association with business and academic institutions. NTT Data has expanded its Ireland–based workforce by 50pc since 2025 and the newly announced roles are expected to be filled over the course of the next six months.
NTT Data has stated it regards Ireland as a critical market and its Irish client base includes a range of insurance companies, banks, and telecoms firms such as Three Ireland and Eir. The company also said the new Dublin office will illustrate a commitment to supporting Ireland’s businesses with the latest research and technologies.
Advertisement
Commenting on the announcement, Michael Lohan, the CEO of IDA Ireland, said: “NTT Data’s new Dublin office and investment of €16.5m is a strong vote of confidence in Ireland and a clear sign of the company’s long-term commitment to growing its presence here.
A key part of IDA Ireland’s strategy is to support Ireland as a global location for next-generation technologies, including AI and to help companies scale high-value capabilities from Ireland for international markets.
“NTT Data’s focus on research and development strengthens the wider technology ecosystem, deepening collaboration with Irish talent and academia and driving innovation that will benefit businesses and communities across the country.”
Niccolo Spataro, the executive managing director for the UK and Ireland at NTT Data, added, “Ireland has a growing economy and a well-established and dynamic tech sector. Today’s announcement reflects our commitment to Ireland. The organisations that move decisively on AI will define their industries for years to come, and we intend to be the partner that helps Ireland’s leading enterprises do exactly that.”
Advertisement
In late May, in Galway, global healthcare technology company Medtronic also announced the creation of new roles amid the establishment of a European software development hub for its patient care systems function.
New roles at the Galway site will be in areas such as leadership, software engineering and systems reliability and the hub will serve as a global ‘centre of excellence’ for cardiac digital health.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
As geopolitical uncertainty continues to constrict the world’s supply of fossil fuels, plenty of countries are weighing up their options for finding alternative energy sources. Nuclear power remains a controversial option, with the fallout from disasters like Chernobyl still continuing decades later, but it’s a very efficient solution. A single average nuclear power plant can generate around 900 megawatts, which is enough to power hundreds of thousands of homes. Renewable energy sources like wind and solar are less controversial, but you’ll also need a whole lot more of them to power the same number of homes.
According to John Parsons, the deputy director of the MIT Center for Energy and Environmental Policy Research, matching the output from an average nuclear reactor would mean building roughly 800 wind turbines. There are a variety of factors to consider, not the least of which is when you switch on a nuclear power plant, it operates at capacity all the time. Wind farms, on the other hand, are dependent on external factors.
To build such a huge wind farm, you’d need around 1,000 times more land than a nuclear reactor would need, if you measure the total size of the farm. Much of that land is the space in between each turbine, which could potentially be used as farmland, but even if you measure only the space taken up by the turbines themselves, the wind farm will still take up 10 times as much space as the nuclear reactor.
Advertisement
Researchers are trying to develop more efficient wind turbines
Wind and solar power remain much greener than fossil fuels, with almost all of their emissions being generated during the manufacturing process and the construction of the power plants. However, the land requirements and production costs to build these plants are still major limiting factors for now.
Advertisement
Researchers continue to work on ways to make wind and solar power more efficient, with one company in China currently developing unique wind turbines that fly above the ground rather than being built on it. According to the Chinese state-affiliated Global Times, the airborne wind turbine, which looks like a cross between a blimp and a cartoon rocket ship, successfully took its maiden flight in January 2026.
Operating at 2,000 meters above ground level, the turbine is subjected to stronger, more consistent wind than a traditional land-based wind turbine. This stronger wind allows it to produce significantly more energy, which is then transferred along a cable that anchors it to the ground. Speaking to the Global Times, a researcher working on the project said that they envisioned the turbine being used as an energy supply in remote outposts, as well as “complement[ing] traditional ground-based wind power systems.”
The data gathered during the initial flight suggested that the airborne turbine prototype could generate up to 3 megawatts of power. That would mean that only 300 of these turbines could match the output of a nuclear reactor, compared to 800 average ground-based turbines.
Advertisement
Bigger is better when it comes to wind turbines
Sjo/Getty Images
Although the Chinese prototype wind turbine looks promising, it isn’t yet in production. If and when it arrives, its makers reportedly plan to prioritize the Chinese market at first, so it’s safe to assume that the rest of the world won’t be generating power using floating wind turbines anytime soon. Thankfully, it’s not the only way that researchers are trying to make wind turbines more efficient.
One development that’s already happening in America is the introduction of increasingly large surface-level wind turbines. A bigger wind turbine has the potential to generate significantly more energy, and turbines built in the 2020s are already far larger on average than the turbines built in previous decades.
This increase in size is expected to continue, with offshore wind turbines expected to reach an average height of almost 500 feet by 2035, up from around 330 feet in 2016. Each new turbine in 2035 is expected to generate almost 3 times as much energy as its 20-year-old predecessors. A smaller number of large turbines takes up less space than a larger number of small turbines, and it also makes it cheaper to generate the same amount of energy.
Advertisement
It turns out that wind farms might have some unexpected environmental benefits too. Despite lingering concerns about sea birds hitting turbines, studies have found that some aquatic wind turbine farms have become places of shelter for everything from harbor seals to fish and lobsters.
The Tour de Suisse 2026, the 89th edition of the race, will be five days long rather than the usual eight and in an innovative move to give the fans more chance to see the action each day, the stages will start and finish in the same town.
Heading the list of contenders is the GOAT himself Tadej Pogačar who will be racing for the first time since winning the Tour de Romandie at the end of April. Challenging for the overall will be Tom Pidcock, Primož Roglič and Richard Carapaz then of those looking for stage wins keep a close eye on Matthew Brennanand Mathieu van der Poel.
Read on and we’ll show you how to watch a Tour de Suisse 2026 live stream from anywhere, and potentially for FREE.
Advertisement
How to watch the 2026 Tour de Suisse for FREE
Cycling fans in Switzerland will get to watch a Tour de Suisse 2026 live stream for FREE in a choice of three languages, German, French and Italian.
Those Belgium and Austria can also watch for free. Here’s where:
If you’re a resident of Switzerland, Belgium or Austria and you’re abroad right now, don’t worry about missing the action – all you need to do is download a VPN to re-connect to your home streaming coverage. You’ll find more details below.
Advertisement
Use a VPN to watch any Tour de Suisse 2026 live stream
Tour de Suisse 2026 is streaming on lots of platforms around the world, but what if you’re abroad and don’t want to take out a new subscription just to watch the race, or you want your familiar, favorite commentary?
This is where a VPN can help. It’s a handy piece of software that can make your device appear to be back home, so you can unlock your usual service or subscription from wherever you find yourself.
The best VPN right now? We recommend NordVPN – it does everything you want it to do at great speeds and an even better price.
Advertisement
How to watch 2026 Tour de Suisse live streams in the US
(Image credit: Other)
Cycling fans in the US can watch the Tour de Suisse 2026 on FloBikes.
A subscription to FloBikes will set you back US$155.88 for the year or US$39.99 on a monthly basis.
If you’re out of the US but still want to watch the 2026 Tour de Suisse then don’t forget to explore the VPN route set out above, which will help you access your subscriptions from anywhere.
Advertisement
How to watch 2026 Tour de Suisse live streams in the UK
The Tour de Suisse 2026 is on TNT Sports in the UK.
TNT Sports’ cycling coverage in the UK has now moved from Discovery+ to the HBO Max platform. It costs £30.99 per month, though there is a better value £25.99 “saver plan” available if you sign up for a 12-month term.
If you’re currently traveling overseas, don’t worry as you can use NordVPN to watch your usual service from abroad.
Advertisement
How to watch 2026 Tour de Suisse live streams in Canada
(Image credit: Other)
Fans in Canada can watch the Tour de Suisse 2026 on FloBikes.
A subscription to Flobikes, which has pretty much every race you could wish to watch, costs CA$49.99 a month or CA$215.88 for the year.
Not at home right now? Use NordVPN or another VPN service to make your device believe you’re still in Canada.
Advertisement
How to watch 2026 Tour de Suisse live streams in Australia
(Image credit: free)
As yet no TV broadcaster in Australia has the rights to the Tour de Suisse 2026.
However, the Age of Sports YouTube channel is listed on the Tour de Suisse 2026 website as showing the race Down Under. We’d recommend checking it out when the race starts on Wednesday.
Not at home right now? Use NordVPN or another VPN service to trick your device into thinking you’re still in Australia.
Advertisement
Tour de Suisse 2026 – Preview
Tadej Pogačar shouldn’t face too much resistance in his bid to win his first Tour de Suisse as his main rivals are all racing elsewhere or camped out at altitude preparing for the big one in a week’s time. Tom Pidcock should hopefully push him hard, and likewise Primož Roglič will be upset if he’s not in the mix for a podium spot, but if Pogačar is in the same shape that saw him win so prolifically in the spring, it will be a walk in the park.
This year there are only five stages, down from the usual eight to make it more attractive to riders preparing for the Tour and each day will start and finish in the same town. This will work brilliantly for fans who can see both the start and finish of a stage, and if they are resourceful maybe even catch the action halfway.
The five stages kick off with three hilly/mountainous affairs followed by a 23km time trial on stage four then an absolute monster Queen stage to end with. Starting half way up the Col de la Croix and crossing its summit three times in a row it finishes uphill and will be an awesome spectacle for the fans.
We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2. Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.
Cyber Essentials has always been the UK’s baseline cybersecurity standard.
It’s a practical floor designed to block common attacks and ensure business resilience when organizations implement them, rather than treating the scheme as lip service.
The April 2026 update raises the floor, introducing auto-fail outcomes for missing key controls, meaning that certain gaps now end an assessment immediately, rather than becoming items to fix later.
Advertisement
Latest Videos From
Robert Kehoe
For a lot of organizations, that’s not just a compliance issue but a commercial one; as Cyber Essentials certifications are increasingly a requirement by customers and suppliers.
What actually changed in April 2026?
Three changes define the update to Cyber Essentials, with two aspects now resulting in an “auto-fail” if they are not met.
Advertisement
Firstly, patching deadlines are now strict requirements, with high-risk and critical security updates needing to be applied within 14 days of release across systems.
Second, multi-factor authentication has moved from a strong recommendation to mandatory for cloud services. Where MFA is available and not enabled, the assessment ends. The room to treat it as optional is gone.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Advertisement
Third, cloud services can no longer be excluded from scope. IT infrastructure and services hosted in the cloud are now within assessment boundary, shutting down any ambiguity that many organizations had used, on purpose or not, to simplify their certifications.
Why the 14 day rule is no longer a “nice target”
It’s tempting to read 14 days as aggressive until you compare it to how quickly disclosure becomes exploited in today’s environment. Security teams are operating in a world where attacker collaboration and automation compress timelines throughout the attack cycle, and incident data shows how fast campaigns can progress once initial access is achieved.
The UK’s National Cyber Security Centre has been clear with its warnings: organizations need to prepare for a vulnerability patch wave, driven by AI-enabled actors exploiting technical debt at scale and at pace. Organizations need to have processes that deploy updates quickly, more often, and prioritize internet-facing attack surfaces.
Advertisement
Cyber essentials now treat 14-day patching as a minimum, not a nice-to-have, benchmark. Informal patching practices like monthly scheduled windows or manual processes where IT runs updates when they get a chance aren’t enough.
Beyond compliance, unpatched systems are a routine entry points attackers use to disrupt operations – making fast patch management a direct investment in business resilience, not just a box-ticking exercise.
Advertisement
Who is most exposed by the new auto fail approach?
The organizations most likely to struggle aren’t always those with the worst intentions. In practice, the biggest risk sits with teams that can describe compliant controls but can’t run them consistently across their full environment. The update is designed to punish inconsistency because inconsistency is what attackers exploit.
Patching is the obvious pressure point. A 14-day commitment is difficult to keep if devices drift from management, if network hardware runs on separate update schedules, or if legacy applications are prone to breaking when updated. Under the new rules, it’s not enough to patch the easy things; the requirement is framed across the entire scope, which is exactly where many environments reveal hidden gaps.
MFA is the other common tripwire – less technical than organizational. Many businesses have strong MFA coverage for core systems like secure email or admin consoles, but not the long tail of cloud services that have never been brought into line. Under the new rules, that tail is now in scope and the “MFA where available” rule matters.
Cloud scoping will catch organizations that historically treated cloud as “the provider’s responsibility.” The updated requirements explicitly describe shared responsibility expectations and make clear that applicants remain responsible for ensuring controls are implemented.
Advertisement
Finally, organizations that relied on narrow scoping to simplify certification are likely to face more scrutiny. The scheme changes around scope descriptions, exclusions, and transparency, are intended to make it harder to present a subset that doesn’t represent the real operating environment.
How to prepare without turning it into a paperwork exercise
The fastest way to get ready is to stop thinking of Cyber Essentials as a yearly submission and start treating it as ongoing routines.
That doesn’t mean building a bureaucracy; it means choosing a small number of repeatable disciplines that keep you continuously within the standard. Embedding these routines makes organizations more operationally resilient, as they are better prepared to absorb and recover from disruption.
Advertisement
The starting point is understanding scope properly. Cloud services that host or process organizational data are now in scope and can’t be excluded. So, the first task is establishing which services are being used, and who owns them operationally.
Once you have that picture, the MFA requirement becomes a finite task: ensure MFA is enabled wherever it is available and ensure that you can demonstrate it reliably across users rather than assuming “most people probably turned it on.”
Next, treat patching as a pipeline rather than an event. The NCSC’s guidance to prepare for faster, more frequent patching aligns with what Cyber Essentials is now enforcing through auto-fail. Routines are needed to ensure that updates are discovered quickly and prioritize what matters like internet-facing exposure – within the 14-day window.
Where updates genuinely cannot be applied without breaking critical systems, the expectation shifts towards containment and risk management rather than leaving systems exposed and hoping the next cycle catches up.
Advertisement
Compliance that keeps pace with attackers
Incident response reporting continues to show how quickly intrusion timelines are shrinking once initial access is achieved. Threat intelligence reporting is also increasingly clear that adversaries are using automation and AI to accelerate parts of the attack chain.
The implication for a baseline standard like Cyber Essentials is straightforward: controls that slow attackers down early and increase business resilience – rapid patching, strong authentication, and realistic scoping – matter more than ever, because they buy you time you may not otherwise have.
If you take one lesson from the April 2026 update, it should be this: the scheme is no longer optimized for organizations that are “mostly compliant most of the time.” It is increasingly aligned to the reality that attackers only need one neglected service, one unpatched edge device, or one MFA gap to turn a baseline weakness into a breach.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Microsoft confirmed that it’s working on a security patch for a Defender zero-day vulnerability named “RoguePlanet,” disclosed one week ago.
The security researcher who published a RoguePlanet exploit during the June 2026 Patch Tuesday (known as Nightmare Eclipse) said it affects fully patched Windows 10 and Windows 11 devices and allows attackers to spawn command prompts with SYSTEM privileges via a Microsoft Defender race condition.
He shared a proof-of-concept exploit in a self-hosted Git repository, claiming that Microsoft had previously targeted and removed their repos hosting exploits on GitHub and GitLab.
“The exploit is a race condition, so it’s a hit or miss. I have managed to get a 100% success rate on some machines while it struggled to work on others,” Nightmare Eclipse said.
“Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” a Microsoft spokesperson told BleepingComputer when asked for a statement at the time.
Advertisement
On Tuesday, one week after the RoguePlanet flaw was disclosed, Microsoft assigned the CVE-2026-50656 ID to this security flaw and confirmed it’s currently working on a patch, but didn’t acknowledge that Nightmare Eclipse was the one who found the vulnerability.
“Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘RoguePlanet,’ it said in an advisory published yesterday. “We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.”
The RoguePlanet release is part of an ongoing dispute between Nightmare Eclipse and Microsoft over the latter’s bug bounty and vulnerability disclosure practices.
Over the past several months, the researcher has publicly leaked multiple Windows zero-day exploits, including for the BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend flaws. Some of these zero-days affect Microsoft Defender, while others target BitLocker and Windows components.
Advertisement
The company reacted to Nightmare Eclipse’s disclosures by issuing warnings of legal action when people engage in “malicious activity causing real harm to our customers,” leading cybersecurity experts and researchers to believe that Microsoft was threatening the researcher.
Microsoft fixed the GreenPlasma, MiniPlasma, and YellowKey flaws last week as part of the June 2026 Patch Tuesdayupdates.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
You must be logged in to post a comment Login