TL;DR
Wordfence blocked 17M+ attempts to exploit a Gravity SMTP bug that leaks API keys and system data from WordPress sites without authentication.
Wordfence blocked 17M+ attempts to exploit a Gravity SMTP bug that leaks API keys and system data from WordPress sites without authentication.
Attackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin that exposes API keys, OAuth tokens, and detailed system configuration data to anyone who sends a single unauthenticated HTTP request. Wordfence, the WordPress security firm owned by Defiant, says it has blocked more than 17 million exploit attempts targeting the flaw since activity began in early May 2026. The plugin is installed on approximately 100,000 WordPress sites.
The vulnerability, tracked as CVE-2026-4020 and rated 5.3 on the CVSS scale by Wordfence, affects all versions of Gravity SMTP through 2.1.4. A patch was released in version 2.1.5 on 17 March 2026, but exploitation did not begin until roughly two months later, suggesting attackers reverse-engineered the fix or discovered the flaw independently after the patch drew attention to it.
The root cause is a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback function that unconditionally returns true. That means no authentication check runs before the server processes the request. When an attacker appends the query parameter ?page=gravitysmtp-settings, the plugin’s register_connector_data() method populates internal connector data, and the endpoint returns approximately 365 KB of JSON containing the site’s full system report.
The exposed data includes API keys, secrets, and OAuth tokens for every email integration configured in the plugin. Gravity SMTP supports Amazon SES, Google, Mailjet, Resend, and Zoho, and credentials for any of these services appear in the response if they have been configured. An attacker who obtains those credentials can send email on behalf of the compromised site, a capability that is useful for phishing campaigns and business email compromise.
The system report also contains the WordPress version, PHP version and loaded extensions, the web server version, the document root path, the database server type and version, all active plugins with their version numbers, the active theme, and database table names. That information gives attackers a detailed map of the site’s software stack, significantly reducing the reconnaissance effort required to plan follow-on attacks against known vulnerabilities in specific plugin or server versions.
“The exposure of live third-party API credentials means an attacker could abuse the site’s connected email services, while the detailed system report significantly lowers the effort required to plan further attacks against the site,” Wordfence researchers wrote in their advisory.
Exploitation volume spiked sharply around 6 June 2026, with Wordfence blocking more than 4 million requests in a single day on 7 June. The attack traffic has originated primarily from a cluster of IP addresses that Wordfence published for administrators to add to blocklists. The key indicator of compromise is requests to /wp-json/gravitysmtp/v1/tests/mock-data in web server access logs, particularly those containing the ?page=gravitysmtp-settings query parameter.
CrowdSec, the open-source threat intelligence platform, independently corroborated the timeline. It deployed detection for CVE-2026-4020 on 22 May and observed the first real-world exploitation on 27 May. By 1 June, the activity had been classified as background noise, indicating it had been integrated into automated scanning routines that sweep WordPress sites at scale.
The speed at which exploitation was industrialised reflects a broader pattern in WordPress plugin security. The flaw requires no authentication, targets a widely installed plugin, and returns high-value data in a single GET request, making it trivial to automate. WordPress’s plugin ecosystem has faced repeated supply chain compromises in 2026, including an attack in which 30 plugins purchased on Flippa were backdoored and lay dormant for eight months before activation.
The Gravity SMTP vulnerability is distinct from those supply chain attacks in that it does not involve malicious code injected by a compromised developer. It is a straightforward coding error, a permission callback that should have verified the requesting user’s credentials but instead returned true for every request. The simplicity of the flaw makes its survival through development, review, and release notable.
The exposure of API credentials is particularly dangerous because those credentials often persist even after the plugin is updated. Updating to version 2.1.5 closes the vulnerable endpoint, but it does not revoke or rotate the API keys that may have already been harvested. Credential theft through software flaws is an accelerating problem across the industry, with recent research showing that exposed API credentials are exploited within minutes of discovery.
Wordfence’s advisory urges site owners running a vulnerable version of Gravity SMTP who have configured third-party email integrations to assume compromise. The recommended remediation is to update the plugin to version 2.1.5 or later, then immediately rotate all API keys, secrets, and OAuth tokens configured in the plugin’s email connectors. Administrators should also review server log files for requests from the published attacker IP addresses.
The CVE was published on 31 March 2026, two weeks after the patch shipped. Despite the three-month window between patch availability and peak exploitation, many sites remain vulnerable. The gap between when patches become available and when organisations deploy them is one of the most persistent problems in software security, and WordPress plugins are especially prone to it because many site operators do not monitor plugin changelogs or enable automatic updates.
Wordfence also issued a separate advisory this week for CVE-2026-8713, a critical unauthenticated arbitrary file-deletion vulnerability in the Avada Builder plugin, which is installed on approximately one million WordPress sites. That flaw allows attackers to delete files on the server through a path traversal bug, and deleting wp-config.php can revert a site to its initial setup state, potentially enabling a full takeover.
A patch for the Avada Builder flaw is available in version 3.15.4, and no active exploitation of CVE-2026-8713 has been observed yet.
Wordfence did not attribute the Gravity SMTP exploitation to a specific threat actor or group. The pattern of mass scanning from a small cluster of IP addresses is consistent with opportunistic credential harvesting rather than targeted intrusion, though the stolen credentials could be sold or shared with more sophisticated operators for follow-on attacks.
An average visitor is expected to spend around $5,400 in the US—far above the $720-$2,500 visitors to Qatar spent in 2022.
Transport at this year’s tournament is fundamentally different from that of the one-city tournament in Qatar, or in Russia in 2018, which provided free public transportation and an additional 500 trains to help people get around.
This year, because of the vast distances, the only option for fans and teams is flights, which airlines have been adding to accommodate potential World Cup travelers.
“Teams and fans now must factor in flights, not metro rides, and the carbon and cost implications are real,” Anagnostopoulos says.
The need to book flights, not trains or taxis, may also be decreasing demand for hotels simply because the travel costs are too high for some people. “US hotels are already reporting bookings below expectations,” Anagnostopoulos says. “Scale doesn’t guarantee the crowds will show up.”
For organizers and host cities, the scale of the tournament demands a massive investment in security, including against threats that would have barely crossed the minds of previous hosts.
The US federal government has issued $625 million in grants for host cities to address security issues. On top of that, the Department of Homeland Security has made over $200 million worth of grants available to states to buy anti-drone technology, with the US State Department highlighting hostile actors’ increasing access to drones and other technology.
In Canada, federal authorities have issued around $104 million worth of grants to host cities Vancouver and Toronto. That brings total public grants in Canada and the US alone to nearly $1 billion—likely just a fraction of the real costs of securing the tournament.
The size of the tournament, and the fact that it crosses borders, has pushed the price tag higher.
“Qatar 2022 benefited from a highly compact geography, with venues operating within a relatively unified environment. The 2026 World Cup will involve multiple cities, jurisdictions, agencies, and technology ecosystems across the United States, Canada, and Mexico,” says Leo Levit, chair of Onvif, a membership body focused on standardization of physical security products.
“The challenge is not simply the number of systems involved, but whether those systems can exchange information efficiently,” he adds.
The numbers tell a story of a tournament straining under its own ambition. It’s not yet clear whether these investments will pay off in terms of tickets bought and advertising slots sold. Why, then, is FIFA pursuing growth at all costs?
According to Simon Chadwick, professor of sport and geopolitical economy at the international SKEMA Business School, the reason may be growing competition from other sports.
“What [FIFA president Gianni] Infantino is trying to do is to ensure that football remains robust, relevant, prominent and that it doesn’t begin losing market share—to the NBA, which is in China, India, Africa, and the Gulf region; to the NFL, which is making moves on Europe; and to Formula One, which has grown hugely in popularity, particularly in North America,” Chadwick says.
Rumor mill: According to a source familiar with the matter and proposed legislative language reviewed by Reuters, Meta has lobbied Congress to include a provision in the Kids Online Safety Act (KOSA) that would limit companies’ exposure to child safety and privacy lawsuits. The proposal would grant platforms immunity from state-level child-harm claims involving users under 18, a change that could undercut thousands of lawsuits already filed.
The proposal comes as lawmakers and courts increasingly scrutinize how social media platforms are designed and used by minors. Features such as infinite scrolling, activity notifications, and appearance-altering photo filters – key tools for driving user engagement – have become central to legal and regulatory battles over youth safety. Critics argue these features can encourage compulsive use, particularly among younger users.
KOSA directly targets those design choices. The bill would require companies to take reasonable steps to reduce risks associated with minors’ use of their platforms, including design elements that encourage prolonged engagement. In other words, the legislation focuses not only on the content users see, but also on the systems designed to keep them online.
At the same time, Meta’s liability proposal could reshape how families and schools pursue lawsuits over those features. The proposed language would make companies “immune from suit or liability under state law with respect to all claims for loss caused by, arising out of, relating to, or resulting from the safety or privacy of individuals under the age of eighteen online or otherwise related to the provisions” of KOSA. It would also override certain state laws governing children’s online protections.
Meta has framed the proposal as a way to establish consistent national standards rather than avoid accountability. Company spokesperson Stephanie Otway said the provision “does not extinguish existing lawsuits, nor does it represent blanket immunity.”
Instead, she said, it is intended to create “uniform national standards for online youth safety, ensuring these critical issues are governed by comprehensive federal legislation, not plaintiffs’ lawyers or patchwork state legislation.”
That interpretation is disputed by legal advocates. Julia Duncan of the American Association for Justice told Reuters that the language, as written, could have sweeping consequences for ongoing litigation. “The language is pretty clear-cut immunity against every parent, every school district, that is seeking to hold any AI or social media company accountable for harm” to children, Duncan said. “There is no other way to read this language.”
The legal stakes are not theoretical. Meta and Google’s YouTube are already facing thousands of lawsuits over alleged harms to minors. Earlier this year, the companies lost the first case to go to trial, resulting in a combined $6 million in damages. Both have said they plan to appeal.
Behind the scenes, the liability proposal appears tied to broader negotiations over KOSA’s future. The bill, sponsored by Senators Marsha Blackburn and Richard Blumenthal, passed the Senate in 2024 with strong bipartisan support but stalled in the House. It has since been reintroduced and is now part of discussions involving the White House, as well as other measures related to artificial intelligence and federal preemption of state laws.
A spokesperson for Blackburn said the office had not seen the specific liability language and would not support it.
According to the source, Meta has offered to drop its opposition to KOSA if the provision is included – a signal of how high the stakes have become for companies whose core products rely on engagement-driven design. For engineers and product teams, the result could reshape how they design recommendation algorithms, notifications, and interface features for users under 18.
For now, the issue remains unsettled. Lawmakers are trying to impose guardrails on the very technologies that define modern social platforms, while companies are seeking clearer – and potentially narrower – rules on how those systems can be challenged. It is not yet clear how Congress will reconcile these competing aims.
As India searches for a homegrown contender in the global artificial intelligence race, billionaire Mukesh Ambani is positioning Reliance Industries as a national champion, rolling out AI services for phone calls, mobile apps, and connected homes.
At its annual shareholder meeting on Friday, the Mumbai-based conglomerate announced Jio Call Agent, an AI assistant that can join phone calls to transcribe conversations, generate summaries, and perform tasks such as booking cabs, ordering food, and making reservations. The service, which can be activated by saying “Hey Jio,” is expected to launch later this year for Jio’s more than 500 million users.
By embedding the service directly into its telecom network rather than offering it as a stand-alone app, Jio is betting AI assistance can become a native feature of phone calls. The approach could reduce consumers’ reliance on third-party call-assistant apps and give Reliance a powerful distribution advantage in an increasingly crowded AI market.
Reliance also unveiled an AI-powered version of its MyJio app that can perform tasks on behalf of users, from activating eSIMs to selecting roaming plans, through natural-language requests. The company further introduced TeleFrame, a home display that uses AI agents to proactively surface information and recommendations, such as weather alerts, schedules, and household reminders. The product appears to echo a broader industry push toward ambient AI assistants for the home, an area being explored by companies such as Amazon and Google.

The announcements mark the next phase of Reliance’s AI ambitions as India seeks to build domestic capabilities in a field largely dominated by U.S. and Chinese technology companies. The push follows the launch of Reliance Intelligence last year, through which the conglomerate aims to develop AI infrastructure and services for consumers, businesses, and governments, including applications that support 22 Indian languages.
“India should not be a mere consumer of AI created elsewhere. It must become a creator, adopter, and a global leader in AI,” Ambani, age 69, said.
Reliance has been ramping up its AI ambitions through partnerships with Google, Meta, and Nvidia. Earlier this year, the company announced plans to invest $110 billion in AI infrastructure as it seeks to establish itself as a major player in India’s emerging AI ecosystem.
At the shareholder meeting, Reliance also unveiled a suite of AI services for healthcare, education, agriculture, and small businesses. The products, branded JioHealthIQ, JioLearnIQ, JioKrishiIQ, and AI Vyapar, are designed to operate across multiple Indian languages and cater to local needs, the company said.
The shareholder meeting also brought a major development for investors awaiting Jio’s stock market debut. Ambani said Jio Platforms’ board had approved a draft prospectus for an initial public offering that would include a fresh issue of up to 270 million shares, according to a stock exchange filing.
The announcements also raise questions about how Reliance will handle user data as it expands AI services across phone calls, mobile apps, and connected homes. While the company said the services would operate with user consent, it did not answer questions about whether data generated through the products could be used to train AI models or shared with technology partners.
Reliance’s AI ambitions come as Indian companies remain heavily reliant on foreign AI models and cloud providers. Recent restrictions on access to some of Anthropic’s latest models have underscored that dependency, showing how decisions made overseas can affect startups and businesses building AI products in India — the kind of supply-chain risk that’s pushing Indian conglomerates toward building their own stack rather than renting someone else’s.
Last week, Reliance announced a collaboration with Meta to establish an AI data center in the western state of Gujarat, building on Meta’s earlier investment in Jio Platforms and a joint venture launched last year to develop AI solutions for enterprise customers in India and overseas markets.
Reliance is not alone in pursuing AI opportunities. Tata Consultancy Services, Infosys, and rival Adani Group have also expanded their AI initiatives and partnerships with global players, including Anthropic, Google, and OpenAI, as India’s largest corporations race to secure a leading role in the country’s AI future.
Nonetheless, for Reliance, the stakes are particularly high; it’s preparing Jio for a long-awaited stock market debut and needs new growth drivers, with the conglomerate’s shares down about 17% this year.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Seattle startup Gradial continued its hot funding streak, raising another $65 million for its agentic AI platform that automates enterprise marketing.
The Series C round was led by Insight Partners alongside existing investors VMG, Madrona, and PruVen Capital.
Gradial raised $35 million in December and said in a blog post this week that it’s raised over $110 million in the past 16 months, calling it “a testament to the rapid growth” Gradial has seen across its business.
Axios reported that the new round values Gradial at $675 million.
Gradial works by plugging agents into the marketing tools enterprises already use — Adobe, Salesforce, Sitecore — and handling the operational work of getting content live: authoring, QA, brand compliance and routing updates through existing approval chains.
The company also watches for gaps in AI-generated search results, with agents that can draft and publish fixes automatically — without a human queuing up an agency ticket.
Customers include AWS, Prudential, T-Mobile, Vanguard, Kaiser Permanente, and US Bank.
The company was launched in 2023 by four co-founders who met at Dartmouth College: CEO Doug Tallmadge previously worked at SpaceX as a software engineering manager; chief growth officer Anish Chadalavada is a former AI strategy manager at Microsoft and investor at Point72 Ventures; CTO Deip Kumar also worked at SpaceX and Microsoft; and COO Anup Chamrajnagar worked at Point72.
The funding will help Gradial grow its 100-person company across engineering, sales and marketing, according to Axios.
Just as last week was ending, the US government forced Anthropic to pull its two newest models, Fable 5 and Mythos 5, citing national security concerns after Amazon researchers allegedly found a way to bypass Fable 5’s guardrails.
Cybersecurity researchers have since signed an open letter calling the move dangerous, and Anthropic itself noted the same jailbreaks exist in other models. So is this a genuine security concern, or just the latest chapter in a messy relationship between Anthropic and the Trump administration?
On this episode of TechCrunch’s Equity podcast, hosts Anthony Ha, Sean O’Kane, and Rebecca Bellan unpack what the ban means for developers building on Anthropic’s platform and for anyone watching the IPO, why it might accidentally be good for the company, and more of the week’s headlines.
Subscribe to Equity on YouTube, Apple Podcasts, Overcast, Spotify and all the casts. You also can follow Equity on X and Threads, at @EquityPod.

Professional car thieves have leaned on a quiet radio trick for years to slip past keyless entry systems. Mark Rober, the former NASA engineer known for his glitter bomb videos and hands-on builds, wanted to see exactly how that trick works and whether regular people could defend against it. His latest experiment delivers a clear answer on both fronts.
Rober started by buying a customized relay attack device from a dark net seller accessed through Tor for $12,000 in Bitcoin. Rober believed the risk was worthwhile and put the expensive gadget through a series of preliminary tests after the source provided him with detailed instructions and a warning about self-destruct capabilities in case anyone became too inquisitive. This worked since it could unlock and even start a car, but it took some time and required periodic signal frequency modifications.
When you deconstruct the technology behind these devices, it becomes pretty straightforward. The majority of modern cars transmit a low-pitched radio signal every few seconds to determine whether the accompanying key fob is nearby. When the fob receives the signal and answers with the right code, the car recognizes that the owner is close enough to start the engine or unlock the doors. This is exploited by thieves who creep up on the vehicle and send a louder signal in the direction of the fob, which might be anywhere, such as inside a home or an office. The fob replies as if it is right next to the vehicle.

Rober was determined to make the same car-unlocking device faster and less expensive. He went to a local store, bought a cheap, basic baby monitor for only $12, and tore it up right away. The wireless components of the monitor are ideal for handling that kind of signal, so he tinkered with them to get them to pick up the car’s signal and then rebroadcast it at full blast just next to the fob. He spent less than $200 on his do-it-yourself version, which was a fraction of the price of a real one.

After that, Rober began testing his creation. He would move the antenna around and adjust the power levels in suburban areas until he could consistently unlock the car in ten seconds. After that, he advanced to real-world trials in a controlled setting. Additionally, he was able to obtain a CT scan of the original device without activating its self-destruct features, which greatly aided him in determining which components are truly essential and which may be replaced with less expensive baby monitor technology.

The clincher came when he took the device for a ride in a brand new 2026 Hyundai Sonata, courtesy of streamer JasonTheWeen. Rober got into the car and hotwired it during a Twitch live stream while Jason was busy gaming; since the entire process was being seen by a live audience, it was a slam dunk proof of concept. Later, as promised, Rober presented Jason with a spanking new Rivian.

Then Rober became a little more mischevious, stashing a Sonata with a dozen GPS trackers buried inside in a dangerous neighborhood with a reputation of snatch-and-grab auto thefts. He left it there for five days to see what would happen if someone decided to try their luck – and sure enough, they did. The tracker data revealed that after receiving a parking penalty, the automobile wound up in an impound yard, where a high-definition camera filmed a youngster driving it away.

Rober was first interested in seeing the hack in action, but he soon began to consider how to prevent it from happening again. He discovered that you can effectively stop a relay by simply placing the fob in a metal tin or wrapping it in aluminum foil; bam, the signal is blocked. Problem fixed. Although Rober discovered a few additional solutions to the problem, he also learned that some car manufacturers, such as Kia, are willing to send out free software updates to close the gap.
Why you can trust TechRadar
We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.
The Dreo Smart Misting Fan 516S is a device that came to me when I needed it most. It was a sweltering day in the UK — a nation with little in the way of air conditioning, but lots of humidity. But as I sat there at my desk sweating profusely, my editor handed Dreo’s new misting fan to me, and I have to say, it’s been a lifesaver.
But what exactly is the Dreo Smart Misting Fan 516S? Well, it’s a device designed to deliver “mess-free cooling,” and is best-suited for desks and tables. I’ve spent the last three weeks with Dreo’s fan, and have used it at my desk, at the kitchen table, and even in a controlled testing space at Future Labs. And for the most part, it’s proved to be quite an impressive performer — though it’s not totally without its flaws. So, here’s how I’d rate my experience overall.
First of all, let’s talk about who this fan is for. In my view, this is best suited for someone who’s sat at their desk and wants a personal fan, but one they can also set on a bedside table on hotter evenings too. I’d not necessarily recommend it to keep the whole family cool on the sofa, though — it’s still pretty compact, and the fan head is relatively small, meaning you don’t get the huge amount of coverage that some of the best fans can provide.
So, how does the 516S fare when used at a desk? In my case, it was great. I found the mist setting to work exceptionally well, and it added a nice degree of coolness without making any mess or feeling too intense. There were 12 speeds to select, and it was easy to switch between the three mist levels depending on how hot I felt. What’s more, it can oscillate 150 degrees horizontally, up to 20 degrees up, and 10 degrees down, making it easy to tailor coverage to your specific space. Dreo states that the 516S can cool a room by 3C / 5.4F at a max speed of 8m/s.
Setting up misting is pretty straightforward too. Simply fill up the detachable 1.3L water tank, slot it into the fan, and you’re good to go. You have to flip the tank upside down before inserting it, and this can lead to a bit of minor leakage, but I never found this to be a big issue. The tank is also large enough to keep misting for hours on end — 12 hours, according to Dreo — and I never felt that I had to refill it too regularly. And if you’re not in a misty mood, then fear not — it’s easy to switch over to a fan only mode, which works nicely too.
Even when using the mist mode, I found the fan to run pretty quietly, which was especially useful when trying it out at night. I didn’t find it difficult to drift off to sleep with the fan at a middling speed, and it certainly couldn’t cut past my Sony WH-1000XM6 headphones when trying it during the workday. One caveat, however, is that the Turbo mode — for those who want maximum power — can get fairly noisy. This could frustrate some when trying to watch TV or listen to music, but the mode did still work well when I needed a thorough blast of cold.
There are a number of other ways to customize your experience, though, such as a timer, a humidity preference setting, and a child lock system. Such options can be accessed through a number of control methods: touch controls, a remote, voice commands, or a companion app. This level of versatility is always welcome, and the inclusion of Alexa and Google voice assistants is pretty neat, especially given the 516S’s modest price — more on that later.
I will say, however, that the physical touch controls are… a little temperamental. Sometimes I found myself pressing a button over and over again trying to get it to function properly. That’s pretty frustrating, and often pushed me to reach for the remote instead. It’s no dealbreaker, especially with the various alternative control methods, but it’s worth noting all the same.
Before we sum up, let’s talk about design. This fan is decent-looking, with an easy-to-clean plastic exterior, attractive lighting on the control panel, and a transparent water tank, so you always know when it’s time for a refill. There’s also a practical carry handle, and you can easily dismantle the fan if you need to make a fix. The power cable is integrated, and you won’t be able to use this fan wirelessly, but for the cost, that’s understandable.
Speaking of cost, the 516S will typically set you back $99.99 / £99.99 (about AU$140), which in my view, is a very fair price. Sure, there are cheaper options available in this size-class, but you get mess-free and effective misting, a wide range of speeds, and a wide number of control methods, all without having to break the bank. So if you’re looking for a fan to use at your desk, or a personal cooling solution while watching TV for instance, I think the Dreo Smart Misting Fan 516S is well-worth considering.
The Dreo Smart Misting Fan 516S has a fairly modest price tag for all of the tech it crams in. It’s typically available for $99.99 / £99.99 (about AU$140), although I have seen it discounted with some online retailers. The fan released in April 2026 as part of Dreo’s 2026 summer lineup.
|
Speeds |
12 |
|
Oscillation |
150 degrees horizontal, 30 degrees vertical |
|
Weight |
5lbs / 2.3kg |
|
Dimensions |
7.9 x 8.6 x 15.7 inches / 201 x 219 x 400mm |
|
Control |
Touch, remote, app, voice |
|
Timer |
Yes |
|
Additional modes |
Fan only, Turbo |
|
Attribute |
Notes |
Score |
|---|---|---|
|
Features |
Wide control options, plenty of modes and speeds, mist and fan only options, wired power only. |
4.5 / 5 |
|
Performance |
Mess-free misting works well, decent coverage, usually quiet unless using Turbo mode. |
4 / 5 |
|
Design |
Decent looking, easily detachable water tank, touch controls could be better. |
4 / 5 |
|
Value |
Cheaper options exist, but a good performer at a relatively modest price. |
4 / 5 |
I spent three weeks testing the Dreo Smart Misting Fan 516S, using it at home on my desk and the kitchen table, and even trying it in a controlled environment at Future Labs.
During this time, I tested out all of the various features, sifted through the multiple connectivity and control options, and made sure to try the fan both with and without misting activated. During the majority of the testing period, I was using the fan on high temperature days with high humidity, making for a natural and authentic testing process.
More generally, I’ve tested tons of gadgets here at TechRadar across the course of multiple years. I’ve covered home and lifestyle products, audio gear, video games, and more as part of our dedicated reviews team.
Microsoft has released a new Insider Preview update for the modern Windows 11 Media Player. However, the app is facing criticism after tests revealed it uses more memory and opens local video files more slowly than the classic 17-year-old Windows Media Player.
The update adds some useful fixes, including better captions, clearer codec errors, and improved file recognition. But the biggest complaints remain higher RAM usage and paid codec support for some common video formats. The update is not available to everyone yet. Media Player version 11.2605.14.0 has only arrived on Experimental Insider builds as part of Microsoft’s June 12 Insider Preview releases.

The update brings several small but practical changes. Caption styling now follows Windows system caption settings, so users can adjust font size, color, and background from the operating system. Media Player also shows an indexing banner when it is scanning a fresh media library, which should make it clearer why some songs or videos are not showing up yet.
Microsoft has also improved file recognition to reduce playback errors, added clearer missing codec messages, blocked unnamed playlists, fixed a crash linked to play queue editing, and cleaned up some visual issues. These are useful fixes, especially for an app that ships as the default media player on Windows 11.
The problem is that these fixes do not address the biggest complaints. According to Windows Latest, the modern Media Player used around 377MB of RAM while idle, compared with about 103.4MB for the legacy Windows Media Player. The newer app also took longer to open a local video file in testing.

For a modern piece of software, this is a bad look. Opening and playing a local video should be one of the easiest things a media player does. If Microsoft’s newer app is slower at that than the version that shipped with Windows 7 nearly 17 years ago, something has clearly gone wrong.
The codec situation is another frustration. HEVC, also known as H.265, is now common on phones, including iPhones and many Android devices. But Windows users may need Microsoft’s paid HEVC Video Extensions app from the Store to play those files in Media Player. The extension costs $0.99.
There is some context here. HEVC is tied to patent licensing, and Microsoft has to account for royalties. Even so, the user experience is not great. Someone can shoot a video on a modern phone, move it to a Windows machine, and then be asked to pay extra just to play it in Microsoft’s own media app. Fortunately, Windows users are not stuck with that setup. Free alternatives like VLC Media Player and MPV can play HEVC videos without requiring Microsoft’s paid codec extension.
Windows 11 version 24H2 has also removed built-in AC-3 support, which can affect Dolby Digital audio playback. For now, the update shows Microsoft is improving Media Player, but the app needs to be faster, lighter, and less dependent on paid codec add-ons to win users over.
Like every piece of gear you wear on your body day in and day out, fitness trackers are incredibly personal. The right tracker for you should be comfortable, accurate, and tailored to your lifestyle, including your preferred workouts and health goals. Do you bike, row, or strength train? Do you run on trails for hours at a time, or do you just want a reminder to stand up every hour? Do you want to wear it on your wrist or your finger, or tuck it into your sports bra?
No matter what your needs are, there’s never been a better time to find a powerful, sophisticated tool to help optimize your workouts or jump-start your routine. We test dozens of fitness trackers every year while running, climbing, hiking, or just doing workout videos on our iPads at night, to bring you these picks.
Our top choice for most people is the Garmin Vivoactive 6 ($300), which works well with Android and iOS, but we also vouch for the latest Oura Ring 5 ($399) and the budget-friendly Google Fitbit Air ($100). For more wearables, check out our guides to the Best Smartwatches, Best Smart Rings, and Best Sleep Trackers.
Jump To
Garmin makes some of the most accurate fitness trackers on the market, and the Vivoactive 6 is the best midrange option for most people. It strikes a solid balance between smartwatch features and fitness tracking, with support for both iPhone and Android users.
Why WIRED recommends: The Vivoactive 6 is accurate, comfortable, and packed with useful wellness features without feeling overwhelming. It uses Garmin’s proprietary algorithms to power features like Morning Report and Body Battery, which provide daily insights into your sleep, recovery, and readiness. It also has built-in satellite connectivity and GPS, so you can track outdoor workouts without bringing your phone along. There’s also incident detection, which alerts emergency contacts if it detects a serious fall.
Garmin’s biggest advantage remains its free Connect platform, which enables health and fitness tracking without requiring a subscription. The company also continues to add new software features through regular updates without putting them behind a paywall.
The trade-offs: Garmin launched Connect+, a $70-per-year subscription with extras like live tracking and access to Garmin’s AI-powered Active Intelligence. Former editor Adrienne So doesn’t think most people need it, but it’s worth noting if you’re looking for a completely subscription-free experience. The Vivoactive 6 may also feel like overkill for casual users who only want basic activity and sleep tracking.
The gaming news site Aftermath reports:
Four gamers are suing Sony Interactive Entertainment for allegedly breaking a California law that requires digital storefronts selling games to make it clear people are buying licenses, not actually owning the games.
Sony Interactive Entertainment’s PlayStation store uses language like “Buy Now” and “Confirm Purchase,” lawyers wrote in a complaint filed on Thursday… “In reality, consumers who ‘purchase’ digital games through PlayStation do not obtain ownership of those products,” lawyers wrote. “Instead, PlayStation grants only a limited, revocable license to access the software, subject to multiple restrictions contained in a separate Software Product License Agreement”….
[T]he PlayStation store does have a disclosure. Above the “Confirm Purchase” button, there’s a note: “By selecting [Confirm Purchase], you agree to complete the purchase in accordance with the PlayStation Terms of Service before using this content. You further acknowledge that your purchase of this digital product amounts to a license subject to the Software Product License Agreement.” These four gamers aren’t satisfied with that; they said in the complaint that it’s too small, and that “a reasonable customer completing a purchase would not necessarily notice this disclosure.”
“It’s a proposed class action complaint, meaning the group of four gamers is asking a judge to grant them class action status.”
No Jackpot Winner as $257 Million Prize Rolls Over to $269 Million Monday Draw
Weekend Open Thread: Miami – Corporette.com
Zimbabwe Requires Crypto Businesses to Register Annually Under New FIU Regulations
Wall Street Week Ahead: Investors see Micron earnings as pulse check of AI rally momentum
Matt Damon’s Viral Sci-Fi Thriller Has Taken Over HBO Max
As AI companies race to go public, who else is along for the ride?
Anthropic staff to meet White House officials next week, Axios reports
Bitcoin could crash to $48,000, if this historical pattern is triggered
HIVE shares jump as $220M AI deal speeds Bitcoin mining pivot
what doctors are seeing in ebike crashes
Warning of disruption as Cardiff Crossrail works to start
Tributes to former deputy head teacher at Cambridge school among death and funeral notices
Kate Middleton Glare Goes Viral After Kids Booed At Royal Event
“Israel’s” ban on ICRC visits ruled illegal, but Knesset moves to stop them permanently
Financial Accounting | Last Day Revision Strategy and Booster | CMA Inter – June 2026
XRP ETFs Outperform As Bitcoin And Ethereum Funds Extend Outflow Trend
Over 400 Arch Linux packages compromised to push rootkit, infostealer
Singer Oliver Tree dies aged 32 in helicopter crash in Brazil
Invesco Quality Income Fund Q1 2026 Commentary
Market Preview: SpaceX (SPCX) IPO Record, Federal Reserve Meeting, and Iran Nuclear Agreement
You must be logged in to post a comment Login