[$] Modernizing swapping: the end of the swap map

Post Syndicated from corbet original https://lwn.net/Articles/1057102/

The first installment in this series
introduced several data structures in the kernel’s swap subsystem and
described work to replace some of those with a new “swap table” structure.
The work did not stop there, though; there is more modernization of the
swap subsystem queued for an upcoming development cycle, and even more for
multiple kernel releases after that. Once that work is done, the swap
subsystem will be both simpler and faster than it is now.

Chrysalis, Notepad++, and Supply Chain Risk: What it Means, and What to Do Next

Post Syndicated from Rapid7 original https://www.rapid7.com/blog/post/tr-chrysalis-notepad-supply-chain-risk-next-steps

When Rapid7 published its analysis of the Chrysalis backdoor linked to a compromise of Notepad++ update infrastructure, it raised understandable questions from customers and security teams. The investigation showed that attackers did not exploit a flaw in the application itself. Instead, they compromised the hosting infrastructure used to deliver updates, allowing a highly targeted group to selectively distribute a previously undocumented backdoor associated with the Lotus Blossom APT.

Subsequent reporting from outlets including BleepingComputer, The Register, SecurityWeek, and The Hacker News has helped clarify the scope of the incident. What’s clear is that this was a supply chain attack against distribution infrastructure, not source code. The attackers maintained access for months, redirected update traffic selectively, and limited delivery of the Chrysalis payload to specific targets, helping them stay hidden and focused on espionage rather than mass compromise.

What does the Notepad++ incident mean?

This incident highlights how modern supply chain attacks have evolved. Rather than targeting application code, attackers abused shared hosting infrastructure and weaknesses in update verification to quietly deliver malware. The broader takeaway is that supply chain risk now extends well beyond build systems and repositories. Update mechanisms, hosting providers, and distribution paths have become attractive targets, especially when they sit outside an organization’s direct control.

Was Notepad++ itself compromised?

Based on public statements from the Notepad++ maintainer and independent reporting, there is no evidence that the application’s source code or core development process was compromised. The risk stemmed from the update delivery infrastructure, reinforcing that even trusted software can become a delivery mechanism when upstream systems are abused.

Who was behind the Chrysalis backdoor & Notepad++ attack?

Rapid7 was the first to publish attribution linking this activity to Lotus Blossom, a Chinese state-aligned advanced persistent threat (APT) group. Based on our analysis, we assess with moderate confidence that this group is responsible for the Notepad++ infrastructure compromise and the deployment of the Chrysalis backdoor.

Lotus Blossom has been active since at least 2009 and is known for long-running espionage campaigns targeting government, telecommunications, aviation, critical infrastructure, and media organiations, primarily across Southeast Asia, and more recently, Latin America.

The tactics, tooling, and infrastructure used in this campaign – including the abuse of update infrastructure, the use of selective targeting, and the deployment of custom malware, are consistent with the group’s historical tradecraft. As with any attribution, this conclusion is based on observed behaviors and intelligence correlations, not a single, definitive indicator.

What should organizations do right now?

Based on what we know today, there are several immediate actions organizations should take:

  • Check and update Notepad++ installations. Ensure any instances are running the latest version, which includes improved certificate and signature verification.

  • Review historical telemetry. Even though attacker infrastructure has been taken down, organizations should scan logs and environments going back to October 2025 for indicators of compromise associated with this campaign.

  • Hunt, don’t just scan. This activity was selective and low‑volume. Absence of alerts does not guarantee absence of compromise.

  • Use available intelligence. Rapid7 Intelligence Hub customers have access to the Chrysalis campaign intelligence, along with follow‑up indicators provided by partners such as Kaspersky, to support targeted hunting across endpoints and network telemetry.

Why does this matter beyond Notepad++?

This incident is a case study in how trust is exploited in modern environments. The attackers didn’t rely on zero days or noisy malware. They abused update workflows, hosting relationships, and assumptions about trusted software. That same approach applies across countless tools and platforms used daily inside enterprise environments.

It also reinforces a broader trend we’ve seen over the last year: attackers are patient, selective, and focused on long‑term access rather than immediate impact. That has implications for detection strategies, incident response planning, and supply chain risk management.

What does this mean for software supply chain security?

For defenders, this incident reinforces several lessons:

  • Supply chain security must include distribution and hosting infrastructure, not just source code.

  • Update mechanisms should enforce strong signature and metadata validation by default.

  • Shared hosting environments represent an often overlooked risk, especially for widely deployed tools.

  • Trust in software must be continuously validated, not assumed.

The Chrysalis incident is not just about a single tool or a single campaign. It reflects a broader shift in how advanced threat actors think about access, persistence, and trust. Software supply chains are no longer just a development concern. They are an operational and security concern that extends into hosting providers, update mechanisms, and the assumptions organizations make about what is “safe.”

As attackers continue to favor selective targeting and long‑term access over noisy, large‑scale compromise, defenders need to adapt accordingly. That means moving beyond basic scanning, validating trust continuously, and treating update and distribution infrastructure as part of the attack surface.

Learn more: Watch the full Chrysalis debrief webinar

If you’d like to hear directly from the researchers behind this discovery, watch the full Chrysalis: Inside the Supply Chain Compromise of Notepad++ webinar, now available on BrightTALK. In this detailed session, Christian Beek (Senior Director, Threat Analytics) and Steve Edwards (Director, Threat Intel & Detection Engineering) walk through the full attack chain, from initial compromise to malware behavior, attribution to Lotus Blossom, and what organizations can do right now to assess exposure and strengthen supply chain security. [Watch Now]

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/1057381/

Security updates have been issued by AlmaLinux (brotli, curl, kernel, python-wheel, and python3.12), Debian (containerd), Fedora (gnupg2, pgadmin4, phpunit10, phpunit11, phpunit12, phpunit8, phpunit9, and yarnpkg), Mageia (expat), Oracle (qemu-kvm and util-linux), Red Hat (kernel, kernel-rt, opentelemetry-collector, and python3.12-wheel), SUSE (abseil-cpp, dpdk, freerdp, glib2, ImageMagick, java-11-openj9, java-17-openj9, java-1_8_0-ibm, java-1_8_0-openj9, java-1_8_0-openjdk, java-21-openj9, kernel, libsoup, libsoup-3_0-0, openssl-3, patch, python-Django, rekor, rizin, udisks2, and xrdp), and Ubuntu (gh, linux, linux-aws, linux-azure, linux-azure-5.15, linux-gcp, linux-gke,
linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iotg,
linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra,
linux-nvidia-tegra-5.15, linux-oracle, linux-raspi, linux, linux-aws, linux-azure, linux-gcp, linux-oem-6.17, linux-oracle,
linux-raspi, linux-realtime, linux, linux-gke, linux-gkeop, linux-hwe-6.8, linux-oracle,
linux-oracle-6.8, linux-raspi, linux-fips, linux-aws-fips, linux-azure-fips, linux-gcp-fips, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-realtime, linux-intel-iot-realtime, and linux-realtime, linux-realtime-6.8, linux-raspi-realtime).

2025 Q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults

Post Syndicated from Omer Yoachimik original https://blog.cloudflare.com/ddos-threat-report-2025-q4/

Welcome to the 24th edition of Cloudflare’s Quarterly DDoS Threat Report. In this report, Cloudforce One offers a comprehensive analysis of the evolving threat landscape of Distributed Denial of Service (DDoS) attacks based on data from the Cloudflare network. In this edition, we focus on the fourth quarter of 2025, as well as share overall 2025 data.

The fourth quarter of 2025 was characterized by an unprecedented bombardment launched by the Aisuru-Kimwolf botnet, dubbed “The Night Before Christmas” DDoS attack campaign. The campaign targeted Cloudflare customers as well as Cloudflare’s dashboard and infrastructure with hyper-volumetric HTTP DDoS attacks exceeding rates of 200 million requests per second (rps), just weeks after a record-breaking 31.4 Terabits per second (Tbps) attack.

Key insights

  1. DDoS attacks surged by 121% in 2025, reaching an average of 5,376 attacks automatically mitigated every hour.

  2. In the final quarter of 2025, Hong Kong jumped 12 places, making it the second most DDoS’d place on earth. The United Kingdom also leapt by an astonishing 36 places, making it the sixth most-attacked place.

  3. Infected Android TVs — part of the Aisuru-Kimwolf botnet — bombarded Cloudflare’s network with hyper-volumetric HTTP DDoS attacks, while Telcos emerged as the most-attacked industry.

2025 saw a huge spike in DDoS attacks

In 2025, the total number of DDoS attacks more than doubled to an incredible 47.1 million. Such attacks have soared in recent years: The number of DDoS attacks spiked 236% between 2023 and 2025.


In 2025, Cloudflare mitigated an average of 5,376 DDoS attacks every hour — of these, 3,925 were network-layer DDoS attacks and 1,451 were HTTP DDoS attacks. 


Network-layer DDoS attacks more than tripled in 2025

The most substantial growth was in network-layer DDoS attacks, which more than tripled year over year. Cloudflare mitigated 34.4 million network-layer DDoS attacks in 2025, compared to 11.4 million in 2024.

A substantial portion of the network-layer attacks — approximately 13.5 million — targeted global Internet infrastructure protected by Cloudflare Magic Transit and Cloudflare’s infrastructure directly, as part of an 18-day DDoS campaign in the first quarter of 2025. Of these attacks, 6.9 million targeted Magic Transit customers while the remaining 6.6 million targeted Cloudflare directly. 


This assault was a multi-vector DDoS campaign comprising SYN flood attacks, Mirai-generated DDoS attacks, and SSDP amplification attacks to name a few. Our systems detected and mitigated these attacks automatically. In fact, we only discovered the campaign while preparing our DDoS threat report for 2025 Q1 — an example of how effective Cloudflare’s DDoS mitigation is!

In the final quarter of 2025, the number of DDoS attacks grew by 31% over the previous quarter and 58% over 2024. Network-layer DDoS attacks fueled that growth. In 2025 Q4, network-layer DDoS attacks accounted for 78% of all DDoS attacks. The amount of HTTP DDoS attacks remained the same, but surged in their size to rates that we haven’t seen since the HTTP/2 Rapid Reset DDoS campaign in 2023. These recent surges were launched by the Aisuru-Kimwolf botnet, which we will cover in the next section. 

“The Night Before Christmas” DDoS campaign

On Friday, December 19, 2025, the Aisuru-Kimwolf botnet began bombarding Cloudflare infrastructure and Cloudflare customers with hyper-volumetric DDoS attacks. What was new in this campaign was its size: The botnet used hyper-volumetric HTTP DDoS attacks exceeding rates of 20 million requests per second (Mrps).


The Aisuru-Kimwolf botnet is a massive collection of malware-infected devices, primarily Android TVs. The botnet comprises an estimated 1-4 million infected hosts. It is capable of launching DDoS attacks that can cripple critical infrastructure, crash most legacy cloud-based DDoS protection solutions, and even disrupt the connectivity of entire nations.

Throughout the campaign, Cloudflare’s autonomous DDoS defense systems detected and mitigated all of the attacks: 384 packet-intensive attacks, 329 bit-intensive attacks, and 189 request-intensive attacks, for a total of 902 hyper-volumetric DDoS attacks, averaging 53 attacks a day.


The average size of the hyper-volumetric DDoS attacks during the campaign were 3 Bpps, 4 Tbps, and 54 Mrps. The maximum rates recorded during the campaign were 9 Bpps, 24 Tbps, and 205 Mrps.

To put that in context, the scale of a 205 Mrps DDoS attack is comparable to the combined populations of the UK, Germany, and Spain all simultaneously typing a website address and then hitting ‘enter’ at the same second.


While highly dramatic, The Night Before Christmas campaign accounted for only a small portion of the hyper-volumetric DDoS attacks we saw throughout the year.

Hyper-volumetric DDoS attacks

Throughout 2025, Cloudflare observed a continuous increase in hyper-volumetric DDoS attacks. In 2025 Q4, hyper-volumetric attacks increased by 40% compared to the previous quarter.


As the number of attacks increased over the course of 2025, the size of the attacks increased as well, growing by over 700% compared to the large attacks seen in late 2024, with one reaching 31.4 Tbps in a DDoS attack that lasted just 35 seconds. The graph below portrays the rapid growth in DDoS attack sizes as seen and blocked by Cloudflare — each one a world record, i.e. the largest ever disclosed publicly by any company at the time.


Like all of the other attacks, the 31.4 Tbps DDoS attack was detected and mitigated automatically by Cloudflare’s autonomous DDoS defense, which was able to adapt and quickly lock on to botnets such as Aisuru-Kimwolf.


Most of the hyper-volumetric DDoS attacks targeted Cloudflare customers in the Telecommunications, Service Providers and Carriers industry. Cloudflare customers in the Gaming industry and customers providing Generative AI services were also heavily targeted. Lastly, Cloudflare’s own infrastructure itself was targeted by multiple attack vectors such as HTTP floods, DNS attacks and UDP flood.

Most-attacked industries

When analyzing DDoS attacks of all sizes, the Telecommunications, Service Providers and Carriers industry was also the most targeted. Previously, the Information Technology & Services industry held that unlucky title.

The Gambling & Casinos and Gaming industries ranked third and fourth, respectively. The quarter’s biggest changes in the top 10 were the Computer Software and Business Services industries, which both climbed several spots. 

The most-attacked industries are defined by their role as critical infrastructure, a central backbone for other businesses, or their immediate, high-stakes financial sensitivity to service interruption and latency.


Most-attacked locations

The DDoS landscape saw both predictable stability and dramatic shifts among the world’s most-attacked locations. Targets like China, Germany, Brazil, and the United States were the top five, demonstrating persistent appeal for attackers. 

Hong Kong made a significant move, jumping twelve spots to land at number two. However, the bigger story was the meteoric rise of the United Kingdom, which surged an astonishing 36 places this quarter, making it the sixth most-attacked location.  

Vietnam held its place as the seventh most-attacked location, followed by Azerbaijan in eighth, India in ninth, and Singapore as number ten.


Top attack sources

Bangladesh dethroned Indonesia as the largest source of DDoS attacks in the fourth quarter of 2025. Indonesia dropped to the third spot, after spending a year as the top source of DDoS attacks. Ecuador also jumped two spots, making it the second-largest source.

Notably, Argentina soared an incredible twenty places, making it the fourth-largest source of DDoS attacks. Hong Kong rose three places, taking fifth place. Ukraine came in sixth place, followed by Vietnam, Taiwan, Singapore, and Peru.


Top source networks

The top 10 list of attack source networks reads like a list of Internet giants, revealing a fascinating story about the anatomy of modern DDoS attacks. The common thread is clear: Threat actors are leveraging the world’s most accessible and powerful network infrastructure — primarily large, public-facing services. 

We see most DDoS attacks coming from IP addresses associated with Cloud Computing Platforms and Cloud Infrastructure Providers, including DigitalOcean (AS 14061), Microsoft (AS 8075), Tencent (AS 132203), Oracle (AS 31898), and Hetzner (AS 24940). This demonstrates the strong link between easily-provisioned virtual machines and high-volume attacks. These cloud sources, heavily concentrated in the United States, are closely followed by a significant presence of attacks coming from IP addresses associated with traditional Telecommunications Providers (Telcos). These Telcos, primarily from the Asia-Pacific region (including Vietnam, China, Malaysia, and Taiwan), round out the rest of the top 10.

This geographic and organizational diversity confirms a two-pronged attack reality: While the sheer scale of the highest-ranking sources often originates from global cloud hubs, the problem is truly worldwide, routed through the Internet’s most critical pathways from across the globe. In many DDoS attacks, we see thousands of various source ASNs, highlighting the truly global distribution of botnet nodes.


To help hosting providers, cloud computing platforms and Internet service providers identify and take down the abusive IP addresses/accounts that launch these attacks, we leverage Cloudflare’s unique vantage point on DDoS attacks to provide a free DDoS Botnet Threat Feed for Service Providers. 

Over 800 networks worldwide have signed up for this feed, and we’ve already seen great collaboration across the community to take down botnet nodes.

Helping defend the Internet

DDoS attacks are rapidly growing in sophistication and size, surpassing what was previously imaginable. This evolving threat landscape presents a significant challenge for many organizations to keep pace. Organizations currently relying on on-premise mitigation appliances or on-demand scrubbing centers may benefit from re-evaluating their defense strategy.

Cloudflare is dedicated to offering free, unmetered DDoS protection to all its customers, regardless of the size, duration, or volume of attacks, leveraging its vast global network and autonomous DDoS mitigation systems.

About Cloudforce One

Driven by a mission to help defend the Internet, Cloudforce One leverages telemetry from Cloudflare’s global network — which protects approximately 20% of the web — to drive threat research and operational response, protecting critical systems for millions of organizations worldwide.

A day with young creators at Coolest Projects Mzansi 2025

Post Syndicated from Tanaka Dhliwayo original https://www.raspberrypi.org/blog/a-day-with-young-creators-at-coolest-projects-mzansi-2025/

Coolest Projects is the world’s leading technology showcase for young people, a space where creativity, curiosity, and problem-solving come together through code. Last November, Coolest Projects returned to South Africa, providing another exciting opportunity to celebrate and amplify the voices of young digital creators across Mzansi, a local name for South Africa.

A student working on their project.

Coolest Projects brings young people together to share what excites them the most about creating with technology, whether that’s making a game, a website, a robot, or a simple Scratch animation. What matters most is not perfection, but participation.

A showcase for young makers

Coolest Projects, an initiative of the Raspberry Pi Foundation, is brought to South Africa by our long-standing partner Coder:LevelUp, giving young people the space to share how they get creative with technology.

I spent the day surrounded by young people explaining their ideas with a mix of excitement, nerves, and confidence — the kind of emotions you get when you build something yourself and someone is finally asking you about it.

A group of people standing around a table.

The event brought together over 250 young people to share the projects they had been working on. Some had been preparing for months, while others had begun exploring their ideas more recently. All of them arrived ready to explain what they made, how it worked, and what they would do differently next time.

There wasn’t a single kind of project. There was a Scratch animation at one table, a game at the next, and a hardware project across the room. Some projects were polished, others rougher around the edges. But the event isn’t about perfection, it’s about learning and having the courage to show your work.

For a lot of participants, this was the first time they had presented their work to an audience, and you could see their confidence build as they spoke. By the end of the day, many were already talking about what they wanted to build next! From experience, we know that many of these young people will come back to Coolest Projects in the future, with our global impact data showing that over 1 in 10 participants in the Coolest Projects online showcase in 2025 had also taken part in Coolest Projects in 2024.

The coolest projects and the coolest people

One of my favourite things about Coolest Projects is that although you might come for the projects, what stays with you is often the people behind them. Coolest Projects celebrates both what young people build and who they are becoming.

The coolest projects

A project that really stood out to me was created by a group of girls who built a language app that translates words from isiZulu, one of South Africa’s official languages, into French and other languages — an ambitious and thoughtful idea.

A group of students looking at a computer screen.

What made this project especially meaningful to me was how well it reflected South Africa’s identity as a rainbow nation, with 12 official languages and countless cultures intersecting everyday. Their work wasn’t just technical, it was deeply relevant. It showed how young creators are already thinking about inclusion, communication, and using technology to bridge the gap between people in different parts of the country. Seeing these young girls confidently present such a culturally aware solution was incredibly inspiring.

And the coolest people

A group of boys arrived with a project that, honestly, fell apart on the day. Things didn’t work the way they had planned. But instead of shutting down or panicking, they laughed it off, explained what should have happened, and kept the energy positive. Their confidence, humour, and teamwork were great to see.

A group of students standing around a table.

They showed that Coolest Projects is not about having everything work perfectly. It’s about showing up, trying something ambitious, and being willing to talk about what went wrong.

Why does Coolest Projects matter?

Coolest Projects goes beyond showcasing technical skills. It helps young people:

  1. Build confidence in presenting ideas
  2. Develop problem-solving and communication skills
  3. See themselves as creators, not just consumers, of technology

For many young creators in South Africa, participating in Coolest Projects is a powerful way to gain recognition and see that their ideas matter and that they belong in the world of technology.

A project on a table.

We look forward to Coolest Projects South Africa returning in 2026 to once again showcase the incredible potential of young tech creators across the country.

Inspired to take part?

The Coolest Projects 2026 global online showcase is now open for entries. Find all the details on how to enter, as well as details of Coolest Projects in-person events you can look forward to throughout 2026, in our recent blog post.

To be the first to hear about events near you, sign up to the Coolest Projects newsletter.

The post A day with young creators at Coolest Projects Mzansi 2025 appeared first on Raspberry Pi Foundation.

Технологичната зависимост на Европа и гащите на Бриджит Джоунс

Post Syndicated from Светла Енчева original https://www.toest.bg/tehnologichnata-zavisimost-na-evropa-i-gashtite-na-bridzit-dzouns/

Технологичната зависимост на Европа и гащите на Бриджит Джоунс

Преди близо четири години, когато започна войната на Русия срещу Украйна, Европа преживя челен сблъсък с енергийната си зависимост от управляваната от Владимир Путин държава. Впоследствие тази зависимост беше отслабена (макар и не напълно премахната), ала това стана не без съдействието на някои недемократични режими – например този в Азербайджан.

Междувременно една от важните външнополитически теми стана зависимостта на Запада от Китай, където се произвеждат голяма част от нещата, които потребяваме. Това доведе до ограничения, особено отвъд океана, за някои китайски технологични компании.

България и киберсигурността: Готови ли сме за предизвикателствата на XXI век?
От януари насам са осъществени редица кибератаки срещу Украйна, като мишени са от държавни институции до банки. Много от тези атаки са приписвани на Русия. Вземайки предвид активната информационна…
Технологичната зависимост на Европа и гащите на Бриджит Джоунс

Откакто Доналд Тръмп стана президент за втори път, управлението му все повече превръща САЩ, които до този момент Европа е смятала за своя най-естествен съюзник, във враг на Стария континент. Тази трансформация от своя страна логично води до въпроса

колко е голяма европейската зависимост от Вашингтон.

Досега въпросната тема се разглежда най-вече във военен аспект – необходимостта Европа да се въоръжава, след като НАТО вече не е онзи сигурен щит, който беше до неотдавна. Но и в други отношения сме толкова несамостоятелни, че даже ни е страх да си го помислим.

Да вземем платежните системи. В България банковите карти са Visa или Mastercard, някои страни в ЕС издават и American Express. Общото между трите е, че са американски. И ако САЩ решат да наложат тежки санкции на ЕС, биха могли да поискат от собствениците на тези системи да „отрежат“ картите, издадени в държави от Съюза. На този етап Брюксел не изглежда да има план за решаване на такъв проблем. Дигиталното евро още не е въведено, но и да беше, щеше да е валидно само в ЕС.

Германия впрочем разполага със собствена система – т.нар. жирокарти, наричани още EC карти. Те са дебитни, но важат предимно на територията на страната, поради което германските банки все повече ги правят съвместими със системи като Maestro или направо издават Visa и Mastercard вместо жирокарти.

ЕС, компютрите и мобилните технологии

Ако се замислите какви по произход са компютрите и мобилните ви устройства, както и тези на познатите ви, вероятно ще изброите предимно американски, китайски, корейски или тайвански марки. Можете ли да се сетите за съвременен бранд от ЕС за такива продукти, без да се замисляте и да търсите информация?

В епохата на джиесемите някои от хитовите марки телефони бяха тъкмо европейски – като започнем с финландските Nokia, но също и германските Siemens, шведските Ericsson, нидерландските Phillips. Днес Nokia е китайска компания, поделението на Ericsson за мобилни телефони още през 2001 г. се обедини с японската Sony, а 11 години по-късно Sony напълно го погълна. Асоциираме Siemens с част от вагоните на софийското метро, а Phillips – с бяла и черна техника. Апропо моят първи и единствен джиесем беше от неособено престижната навремето френска марка Sagem, от която не се произвеждат телефони от 2008 г. насам.

В наши дни има компании от ЕС, правещи смартфони.

Може би най-известните (е, ако четете технологични новини и/или много искате да живеете екологично и социално отговорно) са нидерландските Fairphone, които са с акцент върху етичното производство и възможността потребителите сами да ремонтират устройствата си.

При германските смартфони Volla пък фокусът е върху независимостта и защитата на личния живот на ползвателите им. Устройствата се предлагат с избор между две операционни системи – едната е наречена също Volla и е на основата на Android, другата е мобилната дистрибуция на Линукс Ubuntu Touch. Макар обаче защитата на личния живот да е едно от най-важните неща за германците, тези смартфони не се радват на особена популярност в страната. Човек може да живее от десетилетия в Германия и така и да не разбере, че съществуват. Те не се предлагат в големите германски вериги за продажба на техника и електроника, но пък се продават в… сайта на „Кауфланд“. Не звучи особено престижно да си купите смартфон от хранителен супермаркет, нали?

Във Финландия някогашната Nokia също произвежда смартфони, вече под марката HMD. Както Fairphone и Volla, и те притежават характеристики, които ги нареждат между ниския и средния клас устройства; и цените им са съответни. Финландски са и телефоните Jolla.

Съществуват дори европейски марки компютри.

Ако не сте чували за тях, не се срамувайте – преди да започна да работя по тази статия, и аз не бях, но има специална страница за европейски продукти, от която се информирах.

Но ето, Tuxedo Computers например е германска марка, чиито устройства са оптимизирани за работа под Линукс. Тя предлага както лаптопи, така и персонални компютри. Германски са и CSL Computer, Schenker Technologies и Terra, произвеждани от Wortmann. Продуктите на последните две компании са подходящи за работа под Windows.

Slimbook пък е испанска марка за лаптопи, оптимизирани за различни дистрибуции на Линукс.

За разлика от европейските смартфони, компютрите, произведени в ЕС, са в по-висок ценови клас.

А софтуерната зависимост?

Ако компютрите, смартфоните и другите електронни джаджи, които си купуваме, все пак са от различни държави, по отношение на софтуера – по-специално на потребителския софтуер и социалните медии – зависимостта на гражданите на ЕС от САЩ е огромна.

От местопрестъплението: Facebook
Според Йовко Ламбрев настроенията против ваксините срещу COVID-19 имат благодатна почва не само заради специфики от родния контекст, но и заради стар и познат глобален проблем – съсредоточаването на…
Технологичната зависимост на Европа и гащите на Бриджит Джоунс

Моя германска позната е повела лична борба срещу тази зависимост. Затова преминава на европейски алтернативи. Вместо Messenger и Facebook на Meta предпочита да използва германската социална мрежа Mastodon. Офис пакетът ѝ е също германски, безплатен и с отворен код – LibreOffice. Браузърът ѝ е норвежко-исландският Vivaldi – от страни от Европейското икономическо пространство (ЕИП). Продължава да ползва обаче Windows като операционна система.

Съществува специална страница за европейски алтернативи на (основно) американски софтуерни услуги. Статии по темата с актуалност към 2025 г. може да се прочетат и на други места (например тук и тук).

Съществуват и европейски операционни системи.

ЕС впрочем обмисля създаването на собствена операционна система, която да е на основата на Линукс и да се използва в работата на публичната администрация. Засега обаче разработването ѝ е на ниво концепция. Нещо като реформата на Тръмп на здравното осигуряване, за която той на предизборния дебат с Камала Харис каза, че имал „концепции за план“ – нещо, за което тя после многократно го подиграваше.

Същевременно съществуват операционни системи, създадени в страни от ЕС, като тези за компютри са варианти на Линукс. Най-популярната от тях е openSuse (Германия и Люксембург), сравнително известна е и Linux Mint (Ирландия). Освен това има например Tuxedo OS (Германия, предназначена за компютрите от едноименната марка, за които стана дума по-горе), Manjaro (Германия, Франция и Австрия) и Zorin OS (Ирландия). Франция пък разполага с операционна система, която се използва в работата на жандармерията.

Има и европейски операционни системи за мобилни телефони: вече споменатата Volla на едноименните германски смартфони, Sailfish – Линукс дистрибуция, разработена от финландските производители на телефоните Jolla, френската /e/OS.

Щом има европейски алтернативи, защо не ги ползваме?

Този въпрос всъщност е подвеждащо генерализиращ. Преди да бъде купено от Microsoft, а впоследствие затрито, създаденото от естонци приложение Skype се радваше на огромна популярност в целия свят. Джиесемите Nokia също имаха култов статус далеч извън Европа. И това са само два примера за европейско лидерство в софтуера и мобилните технологии, а може да се намерят и други. Дори и днес – например една най-използваните в глобален план музикална платформа – Spotify, е шведска по произход.

Не може да се отрече обаче, че в наши дни произведените в ЕС и ЕИП компютри, мобилни устройства и потребителски софтуер (с малки изключения, като Spotify) са най-вече за ентусиасти и не могат да преборят конкуренцията. Въпреки че някои от тях може да притежават много добри качества, те почти не се рекламират. Масовият европеец не е и чувал за повечето от тях, не познава хора, които ги ползват, съответно не ги и търси. А

наличието на критична маса потребители е важно.

То означава не само по-добра поддръжка, а и общности, които имат свойството да привличат още повече потребители. Представете си например да преминете към социална мрежа, но приятелите ви да не са в нея. Ако не успеете да ги „придърпате“, вероятно в някакъв момент ще се върнете към популярните канали за общуване, колкото и да искате да се освободите от тях.

В случай че не познавате никой, който си е купил телефон или компютър от определена марка, е по-вероятно да заложите на сигурното, особено ако устройството е и с операционна система, с която нямате опит. Освен ако експериментаторството и неконформизмът не са водещите принципи в живота ви.

Повечето потребители предпочитат да им е удобно и да нямат проблеми.

Тук трябва да призная, че преди години съм експериментирала с различни дистрибуции на Линукс. Всичко беше много вдъхновяващо… до момента, в който все нещо не сработваше – я връзката с принтера или със скенера, я мишката, я някаква важна настройка, я програма, от която имам нужда. И трябваше да се премине към писане на код. Пък аз не съм програмистка и опитите да реша проблема бяха много мъчителни за мен. Понякога прибягвах към чужда помощ, но се случваше и проблемът да се окаже нерешим.

В сравнение с онези години днес има много повече периферни устройства и джаджи, с които потенциално да възникне проблем – като почнем от смартчасовниците и безжичните слушалки и стигнем до цели умни домове. Някои устройства работят с точно определен софтуер и минаването към такъв с отворен код, ако изобщо е възможно, ще ги направи неизползваеми. На този етап европейските алтернативи не предоставят цялостни „екосистеми“, с каквито технологичните и софтуерните гиганти разполагат.

Била съм и с офис пакет с отворен код. Всичко вървеше гладко до момента, когато започнах работа, на която трябваше да се пишат проекти, а поради сроковете за кандидатстване редовно се налагаше да доработвам вкъщи. Текстообработващата ми програма „омазваше“ форматирането на бланките на проектните предложения, поради което ми се наложи да се върна към Microsoft Office.

Да не забравяме, че технологиите са въпрос и на статус.

Дори едно устройство да е с добри характеристики и да работи безпроблемно, а софтуерът да е удобен и полезен, дори и да са създадени с важна кауза, ако тези неща не се смятат за кул, хората няма да искат да ги ползват. Опитайте се да убедите един лоялен потребител на Apple, че заради сигурността на Европа е по-добре да премине на европейски устройства и операционни системи, и само вижте как ще ви изгледа.

За голяма част от европейците идеята да преминат на алтернативи от ЕС и ЕИП в името на сигурността и независимостта изглежда като гащите на Бриджит Джоунс – може да скриват сланинките на корема, може дори да са удобни, но за повечето хора (с малки изключения, като например героя на Хю Грант от филма) изобщо не са секси.

Отвъд принципите и интересите

Ако изобщо се осъществи, „концепцията за план“ за операционна система за администрацията в Европа може и да сработи добре. За служителите в публичния сектор софтуерната платформа в работата им не е статусен символ. Тя може и да е като гащите на Бриджит Джоунс – достатъчно е да е удобна и да върши работа, не е задължително да е секси. Ако има и един основен европейски офис пакет с отворен код за служителите, той може да започне да се използва и от частни потребители, защото ще гарантира съответствие при електронната им комуникация с институциите.

Дотук добре. Ала независимо дали ни харесва, или не, живеем в потребителско общество. Включително в Европа. По-важно от продуктите и услугите, както и от принципите, ценностите и интересите е как се „опаковат“ те, как хората ги възприемат. Когато са за лична употреба, не могат да се наложат със сила, освен в диктатура, каквато ЕС не иска да бъде. Няма как и критично мнозинство от европейците да решат да ги използват само въз основа на принципи и лозунги.

Вашият живот може да бъде записан с цел подобряване на обслужването
Софтуерно приложение за лицево разпознаване надмина като възможности всичко, направено до момента. Clearview позволява разкриването на самоличността на даден човек чрез една-единствена снимка…
Технологичната зависимост на Европа и гащите на Бриджит Джоунс

За да възжелаят гражданите на ЕС европейски компютри, мобилни устройства, софтуер, социални медии и например изкуствен интелект, необходимо е те не само да разберат, че такива неща съществуват и че могат да са им полезни. Хората трябва да ги намерят и за вдъхновяващи. Включително извън Европа. Така както се възприемат германските автомобили, френската кухня, италианската мода или скандинавският дизайн. Или европейските телефони допреди двайсетина години. Или Spotify днес.

Разбира се, има и друг вариант – да бъдем притиснати от необходимостта да преминем към европейски алтернативи. Защото например глобалните вериги на доставки са станали невъзможни, а САЩ използват зависимостта ни от американския софтуер, който на практика знае всичко за нас, за да ни следят с политическа, а не с маркетингова цел, и да ни извиват ръцете. А може и изобщо ни отрежат достъпа до него. Нали не искаме да стигаме дотам?

Backdoor in Notepad++

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2026/02/backdoor-in-notepad.html

Hackers associated with the Chinese government used a Trojaned version of Notepad++ to deliver malware to selected users.

Notepad++ said that officials with the unnamed provider hosting the update infrastructure consulted with incident responders and found that it remained compromised until September 2. Even then, the attackers maintained credentials to the internal services until December 2, a capability that allowed them to continue redirecting selected update traffic to malicious servers. The threat actor “specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++.” Event logs indicate that the hackers tried to re-exploit one of the weaknesses after it was fixed but that the attempt failed.

Make sure you’re running at least version 8.9.1.

Олга Минева. Силна и свободна

Post Syndicated from Надежда Радулова original https://www.toest.bg/olga-mineva-silna-i-svobodna/

Олга Минева. Силна и свободна

В мозъка ни има четири вериги, които отговарят за щастието, и една от тях е да помагаш на другите – има чисто неврологично обяснение за радостта, която носи работата с кауза. Честа практика е организации да обединяват усилията на различни специалисти, а също и на доброволци, за да се борят с реални проблеми, от които държавата е абдикирала. Навярно именно заради смисъла, чиято добавена стойност носи освен ползи за обществото и удовлетвореност за ангажираните с нея.

Днес ви срещаме с Олга Минева, жената, която стои зад Фондация Emprove – с опита си като организационен психолог и с усилието си да променя средата. Emprove осигурява общност и менторски програми за момичета и жени, преживели насилие. Придружава ги по пътя им да поемат живота в собствените си ръце, работи за овластяването и окриляването им тогава, когато са забравили колко са силни.

Ако трябва да опиша ролята ми, то аз може би съм събирачът на хора в Emprove – човекът, който намира начин да се случват страхотните идеи на общностите ни.

Първите знаци за токсична връзка са свързани с ограничаване на личната свобода и неприкосновеност, с психическия контрол, с ограничаване на правата да работиш и да се срещаш с приятели. При цялата им съвкупност обикновено е въпрос на време да се стигне до домашно насилие, ето защо е изключително важно жените да могат да разпознават първите признаци. Има спешни канали – организации, които успяват да помогнат на жени в непосредствен риск (например Националната телефонна спешна линия за борба с насилието). Emprove се грижи за дългия път преди разпознаването на насилието или след измъкването от неговата клопка – период на подкрепа, осъзнаване и справяне с преживяната травма, за да започнат жените живота си отново. Неслучайно някои от тях, постигнали своите важни победи, наричат себе си жените сървайвъри.

Именно създадената от Олга организация е инициатор на общността на жените сървайвъри – тези, които са излезли (и оцелели) от връзки с насилие и се превръщат в ментори и ролеви модели за цялото ни общество.

Завършила психология в Хайделбергския университет и впоследствие магистратура по управление на промяната в Лондонския университет, Олга работи и до ден днешен като организационен психолог с ръководители на екипи и компании – тези, които задават визията, тона, атмосферата на работа за много други хора. Лидерски консултант е за служители не само в корпоративния свят, а и за ръководители на големи неправителствени организации:

Нерядко те трябва да си спомнят какво е да си говорят и да са свързани с другите. Виждам колко е важна работата ми, възприемам я като призвание, затова и до ден днешен я работя с душа и сърце, а Emprove е привилегия за мен, допълнителен, избран смисъл. Имам чувството, че за целия екип на фондацията – и терапевти, и ментори – е важно, че не работим това фултайм, защото то щеше да се превърне в рутина и да ни претопи. Emprove е истинското ни богатство, допълващо работните ни мисии.

Всичко започва преди около десет години, когато Олга работи в австрийска компания като организационен консултант, и там има възможност да върши и социална дейност. Тогава написва и основите на платформа, която впоследствие ще се превърне в мрежа за помощ и взаимопомощ. До този момент тя е виждала много програми, ориентирани към подкрепа на жени, които винаги завършват с наръчници. Предлага нещо различно – експериментален проект, в който да си партнират шест европейски държави и който да се грижи за процеса на справяне на жените.

Една кризисна грижа обикновено покрива 6 до 12 месеца. Какво обаче става след това? Ние създадохме онлайн платформа, в която менторите и участничките са анонимни. После, при обратната връзка, се оказа, че потребителките ни в тестовата фаза, които бяха около 400 жени, нямат нужда да са инкогнито. Това беше моят „аха! момент“. Жената сървайвър има тотално различен профил, тя е на друг етап от живота си, осъзнава силата си и е готова да я покаже на света. Така стигнахме и до темата за ранната превенция, защото жените сървайвъри вече искат и могат да помагат.

Не можех да предвидя такъв мащаб – над 100 жени са вече част от общността, годишно обучаваме хиляди и организираме десетки събития из цялата страна! Сега имаме за оперативен директор жена сървайвър, която се грижи за тази система от общности и същевременно е невероятен ролеви модел. Изнасяме наши изложби в чужбина, а също така сме официални представители на глобалната кампания на Ив Сен Лоран Abuse is not Love.

Голямата цел и смисъл е плащ, твърди Олга Минева който ти намяташ и той ти дава сили, но има опасност да прелетиш през живота си. И тук идва недвусмисленият проблем с усещането за неотложност, с което с променлив успех се борим всички ние. Наблюденията на Олга са, че в сектора на организациите, ангажирани с каузи, често работят хора, които – осветени от искрицата на смисъла – рискуват да позволят работата да ги погълне или да прегорят.

Тя самата открито заявява убедеността си, че всички трябва да ходим на терапия и да не се страхуваме да надникнем в себе си.

Един дълъг процес на себеизследване е – но поне разбираме къде ни отиват силите. Също така, когато мога, бягам от града и отивам да живея на морето – там хоризонтът буквално се разширява пред очите. Дистанцията ме спасява от чувството на вменена спешност. И едни от най-хубавите ми идеи за Emprove са дошли, когато съм далече от София и от офиса. Другият ми начин са йогата, медитацията и ходенето пеша. Притихването. Имам чувството, че никой не ни е учил да стоим на тихо като малки. Страхуваме се от скуката, а какви неща излизат от теб, когато притихнеш! Имам също така един смартпръстен, който ми казва, когато стресът ми е много – през него открих колко харесвам работата си като психолог, където потъвам като в медитация в историята на хората, в процеса, в който ги напътствам. Там няма място за адреналин, там ти си част от нечий свят. В Emprove е много по-интензивно и динамично.

Фондацията е разпознаваема и с множество кампании, които свързват жените с хора на изкуството: изложбата „Пробуждане между редовете“, арт инсталацията Розов облак, кампанията за мъжко психично здраве Чуй Гласа Ми, поетичния спектакъл Виж ме – силна и свободна и др.

С Олга Минева разговарям в планината, докато тя е на резиденция, вдъхновена от жени сървайвъри и събрала музиканти, фотографи, видеооператор, майсторка на бродерия, скулпторка, художници, терапевт – всички те обменят търсения.

Затова и идеята за свързването е основополагаща за начина, по който Олга мисли света. Тя твърди, че се налага да ребрандираме понятия като граници например: „Не границите, които ни разделят от нещата, а границите като мост към правилните неща“ е сред максимите, от които се ръководи.

Ако нямаме моста, все едно газим в блато от възможности, идеи, норми, вменени очаквания: ти си майка, жена, учен – каквото и да е. Нужна ни е посока: да открием кои са за нас правилните хора, идеи, процеси (неслучайно арт резиденцията се казва „Посока: СИЛНА“).

Изкуството по естествен начин се вписва в концепцията на екосистемата Emprove – като медиатор не само между артистите и жените сървайвъри, а и като възможност човек да опознае себе си през различни ключове, включващи несъзнаваното.

И понеже всеки от нас може да бъде част от промяната на нечий живот, неизбежно стигаме до артисти, срещата с които е повлияла върху Олга Минева. А срещите по Пътя са колкото търсени, толкова и случайни. Така тя кръстосва погледа си с този на Марина Абрамович.

Сравнително прясно преживяване е и повлия върху отношението ми към изкуството и връзката му с Emprove – отивайки на изложбата на Марина Абрамович в Royal Academy в Лондон, я срещнах случайно с група будистки монаси. Тя е първата жена, която е получила възможност за самостоятелна изложба там. И тази експозиция проследяваше процеса на нейното търсене на връзка със самата себе си: от дивото до притихването и силата. Това много силно ми импонира. Аз винаги съм носила в себе си каузата за женската сила и грижата за жената. Когато потънах в темата за насилието над жени, бях много ядосана, а гневът е опасна емоция. И това личи силно и в изкуството на Марина Абрамович, която в началото е дялкала пентаграми върху корема си, самонаранявала се е, подлагала се е на жестокости в изкуството си – може би и заради гнева си към един свят, който не е честен с жените.

Когато се движиш през изложбата и гледаш пърформансите, виждаш как става все по-тихо, по-медитативно. И се стига до нежния ѝ образ от настоящето. Бях разтърсена от преживяването, а когато излязохме с майка ми във вътрешния двор на Royal Academy of Arts, видях самата Марина, обляна от слънцето, озарена, в мир със себе си. На живо. Беше богато преживяване – краят на историята, който е добър.

Тази ситуация по странен начин кореспондира с тениската с надпис Not hysteric, historical, която Олга Минева притежава от мърча към филма „Жените наистина плачат“.

Ние имаме тонове години зад гърба си, в които жените са били невидими в историята, правата им са били потъпквани, гласовете им – заглушавани. И ако още си в ядосаната фаза, може да изглежда истерично. В женското движение трябва да има и гневни хора. Но има и тих начин да правиш революции и промени. Да се успокоиш не означава да се примириш и да угаснеш, това е нещото, което пропускаме в гневната фаза. Когато притихнеш, разбираш, че няма проблеми да си бос, а не с танк.

Днес Олга Минева успява да съвмести ангажираността си в Emprove с работата си като психолог, но това, което ѝ дава личен смисъл и обич, е общуването с дъщеря ѝ. Именно с нея, все още бебе в слинг, тя регистрира фондацията преди почти седем години. През годините е опитвала да си води дневник с добрите моменти през деня.

Осъзнах, че в абсолютно всеки ден хайлайтите ми са онези малки моменти с дъщеря ми – дребни наши традиции, да я взема от училище, да се смеем, да ядем нещо вредно. Така започнах да търся начин, когато пътувам в чужбина по международните ни проекти, моето семейство да идва с мен.

С нея пътуват и идеите ѝ – и готовността да опита нещо ново, невиждано, да зарази и други хора, за да придвижат заедно живота на непозната жена в по-добра посока.


Хората, които тихо и кротко променят средата, формират общности и задават посоки, в които има смисъл да тръгнем заедно. Тук ви срещаме с тях. Това са „Тези хора“.

AWS Transform custom: AI-driven Java modernization to reduce tech debt

Post Syndicated from Dinesh Prabakaran original https://aws.amazon.com/blogs/devops/aws-transform-custom-ai-driven-java-modernization-to-reduce-tech-debt/

In today’s rapidly evolving software landscape, maintaining and modernizing Java applications is a critical challenge for many organizations. As new Java versions are released and best practices evolve, the need for efficient code transformation becomes increasingly important. Organizations today face significant challenges when modernizing their Java applications. Legacy codebases often contain outdated patterns, deprecated APIs, and inefficient implementations that hinder performance and maintainability. Traditional manual refactoring approaches are time-consuming, error-prone, and difficult to scale across large codebases. In addition, as developers spend more time on new development and deployment, the volume of technical debt continues to rise, requiring transformation of legacy code at-scale.

AWS Transform custom addresses these challenges through intelligent automation, providing AWS-managed transformations – standardized transformation packages for common scenarios like Java version upgrades. These transformations enable teams to achieve quick wins through standardized, tested transformation patterns that can be executed at scale, bringing significant time and cost savings to customers. In addition, customers can create custom user defined transformations to address technical debt with code transformations across languages, frameworks, and more.

This post explores how to leverage AWS Transform custom’s out-of-the-box transformation for Java upgrades. By the end of this post, you’ll understand how to use these standardized transformations to modernize your Java applications efficiently while maintaining full control over the transformation process.

Introduction to AWS Transform custom

AWS Transform custom uses agentic AI to automate large-scale code modernization, handling language version upgrades, API migrations, framework updates, and organization-specific transformations. Through continual learning, the agent improves from every execution and developer feedback, delivering high-quality, repeatable transformations without requiring specialized automation expertise.

Prerequisites

Before starting your Java modernization journey with AWS Transform custom, ensure you have the necessary development environment, build tools, and AWS Transform custom command line interface (CLI) installed. For detailed prerequisites and setup instructions, refer to the AWS Transform custom Prerequisites Guide.

Understanding the Modernization Scenario

We’ll demonstrate AWS Transform custom using a Movie Service application – a Spring Boot REST API built on Java 8 with Gradle. This represents a typical enterprise modernization challenge with legacy dependencies, outdated patterns, and technical debt.

Leveraging AWS-Managed Transformations

AWS Transform custom focuses on leveraging AWS-managed transformations designed for common modernization tasks like Java version upgrades.

AWS-managed transformations are pre-built, AWS-vetted transformations for common use cases that are ready to use without any additional setup. These transformations provide immediate value with minimal configuration, making them ideal for standard upgrade scenarios.

Understanding AWS Transform custom CLI Capabilities

AWS Transform custom provides a comprehensive command-line interface that enables both interactive and automated transformation workflows:

atx --version                    # Display ATX version
atx --help                       # Display general help
atx custom def list              # List transformation packages
atx                              # Start interactive conversation

For detailed information on all available commands, refer to the AWS Transform custom command reference.

Screenshot of AWS Transform custom interactive mode.
Figure 1:AWS Transform custom interactive mode

Discovering Available Transformations

Use atx custom def list to view all available transformations, including AWS-managed transformations and custom-defined (user-defined) transformations created by your organization. Key AWS-managed transformations include Java/Python/Node.js version upgrades and AWS SDK migrations.

Screenshot of AWS Transform interface displaying categorized lists of AWS Managed transformations and user-defined custom
transformations.
Figure 2: AWS Transform custom lists available AWS Managed and custom-defined (user-defined) transformations

Applying AWS-Managed Transformations

Before applying any transformations, ensure your project is initialized with Git and that all build and test cases are working correctly with Java 8 (Test cases can be skipped when necessary by using the appropriate build command option and instructions to the agent). For Gradle projects, verify that ./gradlew build executes successfully.

The transformation process follows a structured approach:

  1. Ensure Clean Git State:
git status
git add .
git commit -m "Baseline before Java 21 transformation"
  1. Apply Transformation: You can apply transformations using either interactive or direct command modes. In this blog, we will use the interactive mode to walk through the process step-by-step:

Interactive Mode (used in this blog):

First, create a config.json file with your transformation configuration:

{
  "codeRepositoryPath": "/path/to/your/aws-appconfig-java-sample-gradle",
  "transformationName": "AWS/java-version-upgrade",
  "buildCommand": "./gradlew clean build",
  "validationCommands": "build and validate using \"./gradlew clean build\" after transformation to test with java 21",
  "additionalPlanContext": "This is a Java 8 to 21 transformation of a gradle app , also include all dependency migration as well. Use java path /path/to/your/java-8/bin/java and /path/to/your/java-21/bin/java when building before and after transformation. We are using gradle wrapper gradlew, update it if needed for java 21 upgrade. Check for deprecated methods and dependencies and update them."
}

Update the codeRepositoryPath in your config.json to point to your local project directory and update the Java path in additionalPlanContext to match your Java 8 and 21 installation. For more details about configuration files and their parameters, refer to Using Configuration Files.

Then execute the transformation in interactive mode (used for this blog walkthrough):

For Java version upgrade with Gradle using config.json (Interactive Mode):
atx custom def exec -t --configuration file://config.json

Screenshot of AWS Transform interface displaying categorized lists of AWS Managed transformations and user-defined custom transformations.
Figure 3: AWS Transform custom execute a gradle transformation in interactive mode with transformation configuration supplied from config.json

Direct Command Mode (alternative approach): Use this mode for automated CI/CD pipelines or when you want to execute transformations without interactive prompts.

atx custom def exec -x -t --configuration “file://config.json”

Parameter explanation: –

--configuration: Specifies the configuration file for interactive mode

– -x: Executes the transformation automatically without interactive prompts (direct mode)

– -t: Enables test mode for validation during execution (direct mode)

--configuration: Specifies the configuration file path with file://prefix (direct mode)

ATX Execution Command Executing AWS managed Java version upgrade transformation for Gradle project using ATX CLI

  1. Review Transformation Plan: AWS Transform custom analyzes your project based on the configuration provided in config.json and generates a comprehensive transformation plan. This plan details all proposed changes, including:
  • Java version updates: Migration from Java 8 to Java 21 configurations
  • API migration patterns: Automatic updates for deprecated APIs and modern alternatives
  • Framework modernization: Spring Boot version upgrades and compatibility updates
  • Dependency modifications: Updated library versions compatible with Java 21
  • Build system updates: Gradle configuration and plugin changes for Java 21 compatibility
  • Code pattern improvements: Implementation of modern Java features and best practices

We recommend doing a thorough review of the transformation plan to ensure it encompasses all expected updates. The additionalPlanContext in your config.json helps guide the transformation to include dependency migrations and Gradle wrapper updates. If adjustments are needed, provide feedback through the CLI interface.

Additionally, if you want to customize the transformation to target additional changes, for example upgrading additional legacy dependencies contained in the project, you can provide this as feedback when reviewing the transformation plan. AWS Transform custom incorporates all feedback provided to refine the transformation plan before proceeding.

  1. Apply the Transformation: After confirming the transformation plan meets your requirements, type proceed and press Enter. AWS Transform custom executes the transformation according to the approved plan.

The transformation process automatically:

– Creates a new branch and commits the transformed changes in there

– Updates Gradle configuration for Java 21

– Migrates Java EE to Jakarta EE packages (if applicable)

– Updates framework dependencies for Java 21 compatibility

– Applies all necessary code changes

– Updates test cases and testing frameworks for Java 21 compatibility

– Runs comprehensive validation builds

Results of AWS-Managed Transformations

After applying the Java version upgrade transformation, below changes are observed:

Configuration Updates: – Java version: 1.8 → 21 – Spring Boot version upgrades – Gradle plugin and configuration updates – Dependency version modernization

To validate the changes, switch to Java 21 and run ./gradlew build to ensure the transformation was successful, then test the application functionality.

Figure 4: displaying Updated Gradle Configuration Gradle build.gradle showing updated Java 21 configuration and modernized
dependencies
Figure 4: Updated Gradle Configuration Gradle build.gradle showing updated Java 21 configuration and modernized dependencies

Figure 5: Updated code where legacy pattern of raw types usage is transformed to generics
Figure 5: Updated code where legacy pattern of raw types usage is transformed to generics
Figure 6: Second example of updated code where legacy pattern of raw types usage is transformed to generics
Figure 6: Second example of updated code where legacy pattern of raw types usage is transformed to generics
Figure 7: Updated dependency from javax.security to java.security and uses CertificateFactory to get X509Certificate
Figure 7: Updated dependency from javax.security to java.security and uses CertificateFactory to get X509Certificate
Figure 8: Updated Test cases from junit 4 to junit5
Figure 8: Updated Test cases from junit 4 to junit5

Beyond AWS-Managed Transformations: Custom-Defined Transformations

While AWS-managed transformations provide excellent coverage for standard Java modernization scenarios, there are cases where the available AWS-managed transformations may not address your specific transformation requirements. In such situations, AWS Transform custom enables users to create and test their own organization specific, custom-defined transformation definitions.

When to Create Custom-Defined Transformations

Custom-defined transformations become necessary when AWS-managed transformations don’t cover your specific needs, such as proprietary frameworks, organization-specific coding standards, or complex multi-step migration scenarios.

Creating Custom-Defined Transformations

AWS Transform custom enables teams to develop custom transformations using transformation rules and configuration files. This allows organizations to define transformation logic specific to their requirements, test on sample code, and share validated transformations across teams.

AWS Transform custom’s interactive mode (atx) is particularly beneficial for creating Custom-defined transformations, enabling conversational interaction to iteratively refine requirements and get real-time feedback. Custom-defined transformations provide flexibility to extend AWS Transform custom’s capabilities when AWS-managed transformations don’t meet specific modernization needs.

Continual Learning and Knowledge Items

AWS Transform custom automatically learns from each transformation execution to improve future results. For Java upgrades specifically, the service captures patterns like successful refactoring strategies, common dependency conflicts, and framework compatibility matrices across Java versions. This knowledge feeds back into future transformations, making them more accurate at predicting successful upgrade paths and reducing manual intervention.

Knowledge items are account-specific and remain within your AWS account boundaries. Users can enable or disable continual learning, providing full control over this preference.

Conclusion

In this blog, we demonstrated how AWS Transform custom enables efficient Java application modernization using AWS managed transformations. Starting with a legacy Movie Service application running Java 8 and Spring Boot 2.x, we successfully transformed it to Java 21 with modern dependencies and patterns.

The step-by-step process showed how to establish a baseline, discover available transformations using atx custom def list, and apply transformations through AWS Transform custom’s CLI. The result was a fully modernized application with updated Java versions, Spring Boot upgrades, and modern Java features like enhanced switch expressions and local variable type inference – all achieved in minutes rather than weeks of manual refactoring.

Beyond Java Modernization

Beyond Java modernization, AWS Transform custom’s transformation capabilities extend to other programming languages and frameworks, making it a versatile solution for comprehensive application portfolio modernization across diverse technology stacks. The agent supports diverse transformation use cases including:

  • Version upgrades for Java, Python, and Node.js
  • Runtime and API migrations (AWS SDK v1→v2, Boto2→Boto3)
  • Framework transitions and upgrades
  • Language translations and architectural changes
  • Organization-specific, custom-defined transformations

Through its define once, transform everywhere approach, AWS Transform custom enables organizations to capture and amplify transformation knowledge by defining transformations once and executing repeatable tasks across the entire organization. This reduces knowledge silos and ensures consistent quality regardless of team or project scope.

Getting Started

Ready to modernize your Java applications with AWS Transform custom? Here’s how to begin:

  1. Install AWS Transform custom CLI (atx) using the installation script and verify your environment
  2. Configure AWS credentials with transform-custom:* permissions
  3. Explore available AWS-managed transformations using atx custom def list
  4. Apply transformations to your Java applications using direct execution mode (atx custom def exec) or interactive mode (atx)
  5. Validate results through comprehensive testing with ./gradlew build for Gradle projects
  6. Scale across your application portfolio for consistent modernization

Additional Resources

For detailed setup instructions and documentation, visit:

Start your modernization journey today and experience the power of AI-driven code transformation at scale.

About the authors

Profile image for Venugopalan Vasudevan

Venugopalan Vasudevan

Venugopalan Vasudevan (Venu) is a Senior Specialist Solutions Architect at AWS, where he leads Generative AI initiatives focused on Amazon Q Developer, Kiro, and AWS Transform. He helps customers adopt and scale AI-powered developer and modernization solutions to accelerate innovation and business outcomes.

Profile image for Dinesh Balaaji Prabakaran

Dinesh Balaaji Prabakaran

Dinesh is a Enterprise Support Lead at AWS who specializes in supporting Independent Software Vendors (ISVs) on their cloud journey. With expertise in AWS Generative AI Services, he helps customers leverage Amazon Q Developer, Kiro, and AWS Transform to accelerate application development and modernization through AI-powered assistance.

Profile image for Sureshkumar Natarajan

Sureshkumar Natarajan

Sureshkumar Natarajan is a Senior Technical Account Manager at AWS, where he supports Enterprise customers in their cloud journey with a focus on Generative AI initiatives. He guides organizations in leveraging Amazon Q Developer, Kiro, and AWS Transform to unlock new capabilities, streamline development workflows, and achieve transformative business results.

Profile image for Anjan Dave

Anjan Dave

Anjan Dave is a Principal Solutions Architect at AWS with over 25 years of IT experience. He specializes in generative AI application modernization, infrastructure scalability, and developer productivity initiatives.
Anjan leads GenAI and modernization strategies across global projects, influencing technology roadmaps for HCM providers through event-driven and microservices architectures. He advocates for integrating Generative AI into the software development lifecycle to automate routine tasks, enabling engineering teams to focus on high-value architectural work.

On the Importance of “Hello” and “Thanks”

Post Syndicated from Let's Encrypt original https://letsencrypt.org/2026/02/05/fosdem2026.html

The ISRG team at FOSDEM 2026

In a recent conversation with a Let’s Encrypt subscriber, we asked them to guess how many people work at ISRG, the nonprofit behind Let’s Encrypt (and Prossimo and Divvi Up). Their guess was about 100; they’d overestimated by 72.5 people. We’re a pretty small team, and we get a lot done, but most of that work is entirely remote, distributed, and automated. 

That is a big part of what makes FOSDEM special. For the last few years, we’ve had a stand at this annual conference in Belgium, where a few folks from our team have the opportunity to speak directly with thousands of conference-goers. We continue to learn so much from these conversations! 

That’s where the “Hello” part of this blog post comes in. At this year’s FOSDEM, we met so many Let’s Encrypt subscribers, and each of them has a unique relationship to Let’s Encrypt. We were pleasantly surprised by how many people told us they were using IP-address certificates, a new option we just made generally available in December. We had a lot of conversations about our plans to shorten certificate lifetimes. There were a few folks who asked about S/MIME (still no plans to do that). We invited people to continue to stay in touch by signing up for our newsletter. 

The most meaningful part of FOSDEM is being able to say “thank you”. Our goal in starting Let’s Encrypt was to improve security and privacy for people using the internet, but that could not be achieved without the now millions of folks who decided to get a certificate. Our impact is predicated on this symbiotic exchange. While we were only able to directly express our gratitude to a few thousand people at FOSDEM, it was a reminder of how important the community is.

Amazon EC2 C8id, M8id, and R8id instances with up to 22.8 TB local NVMe storage are generally available

Post Syndicated from Channy Yun (윤석찬) original https://aws.amazon.com/blogs/aws/amazon-ec2-c8id-m8id-and-r8id-instances-with-up-to-22-8-tb-local-nvme-storage-are-generally-available/

Last year, we launched the Amazon Elastic Compute Cloud (Amazon EC2) C8i instances, M8i instances, and R8i instances powered by custom Intel Xeon 6 processors available only on AWS with sustained all-core 3.9 GHz turbo frequency. They deliver the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud.

Today we’re announcing new Amazon EC2 C8id, M8id, and R8id instances backed by up to 22.8TB of NVMe-based SSD block-level instance storage physically connected to the host server. These instances offer 3 times more vCPUs, memory and local storage compared to previous sixth-generation instances.

These instances deliver up to 43% higher compute performance and 3.3 times more memory bandwidth compared to previous sixth-generation instances. They also deliver up to 46% higher performance for I/O intensive database workloads, and up to 30% faster query results for I/O intensive real-time data analytics compared to previous sixth generation instances.

  • C8id instances are ideal for compute-intensive workloads, including those that need access to high-speed, low-latency local storage like video encoding, image manipulation, and other forms of media processing.
  • M8id instances are best for workloads that require a balance of compute and memory resources along with high-speed, low-latency local block storage, including data logging, media processing, and medium-sized data stores.
  • R8id instances are designed for memory-intensive workloads such as large-scale SQL and NoSQL databases, in-memory databases, large-scale data analytics, and AI inference.

C8id, M8id, and R8id instances now scale up to 96xlarge (versus 32xlarge sizes in the sixth generation) with up to 384 vCPUs, 3TiB of memory, and 22.8TB of local storage that make it easier to scale up applications and drive greater efficiencies. These instances also offer two bare metal sizes (metal-48xl and metal-96xl), allowing you to right size your instances and deploy your most performance sensitive workloads that benefit from direct access to physical resources.

The instances are available in 11 sizes per family, as well as two bare metal configurations each:

Instance Name vCPUs Memory (GiB) (C/M/R) Local NVMe storage (GB) Network bandwidth (Gbps) EBS bandwidth (Gbps)
large 2 4/8/16* 1 x 118 Up to 12.5 Up to 10
xlarge 4 8/16/32* 1 x 237 Up to 12.5 Up to 10
2xlarge 8 16/32/64* 1 x 474 Up to 15 Up to 10
4xlarge 16 32/64/128* 1 x 950 Up to 15 Up to 10
8xlarge 32 64/128/256* 1 x 1,900 15 10
12xlarge 48 96/192/384* 1 x 2,850 22.5 15
16xlarge 64 128/256/512* 1 x 3,800 30 20
24xlarge 96 192/384/768* 2 x 2,850 40 30
32xlarge 128 256/512/1024* 2 x 3,800 50 40
48xlarge 192 384/768/1536* 3 x 3,800 75 60
96xlarge 384 768/1536/3072* 6 x 3,800 100 80
metal-48xl 192 384/768/1536* 3 x 3,800 75 60
metal-96xl 384 768/1536/3072* 6 x 3,800 100 80

*Memory values are for C8id/M8id/R8id respectively.

These instances support the Instance Bandwidth Configuration (IBC) feature like other eighth-generation instance types, offering flexibility to allocate resources between network and Amazon Elastic Block Store (Amazon EBS) bandwidth. You can scale network or EBS bandwidth by 25%, allocating resources optimally for each workload. These instances also use sixth-generation AWS Nitro cards offloading CPU virtualization, storage, and networking functions to dedicated hardware and software, enhancing performance and security for your workloads.

You can use any Amazon Machine Images (AMIs) that include drivers for the Elastic Network Adapter (ENA) and NVMe to fully utilize the performance and capabilities. All current generation AWS Windows and Linux AMIs come with the AWS NVMe driver installed by default. If you use an AMI that does not have the AWS NVMe driver, you can manually install AWS NVMe drivers.

As I noted in my previous blog post, here are a couple of things to remind you about the local NVMe storage on these instances:

  • You don’t have to specify a block device mapping in your AMI or during the instance launch; the local storage will show up as one or more devices (/dev/nvme[0-26]n1 on Linux) after the guest operating system has booted.
  • Each local NVMe device is hardware encrypted using the XTS-AES-256 block cipher and a unique key. Each key is destroyed when the instance is stopped or terminated.
  • Local NVMe devices have the same lifetime as the instance they are attached to and do not persist after the instance has been stopped or terminated.

To learn more, visit Amazon EBS volumes and NVMe in the Amazon EBS User Guide.

Now available
Amazon EC2 C8id, M8id and R8id instances are available in US East (N. Virginia), US East (Ohio), and US West (Oregon) AWS Regions. R8id instances are additionally available in Europe (Frankfurt) Region. For Regional availability and a future roadmap, search the instance type in the CloudFormation resources tab of AWS Capabilities by Region.

You can purchase these instances as On-Demand Instances, Savings Plans, and Spot Instances. These instances are also available as Dedicated Instances and Dedicated Hosts. To learn more, visit the Amazon EC2 Pricing page.

Give C8id, M8id, and R8id instances a try in the Amazon EC2 console. To learn more, visit the EC2 C8i instances, M8i instances, and R8i instances page and send feedback to AWS re:Post for EC2 or through your usual AWS Support contacts.

— Channy

[$] API changes for the futex robust list

Post Syndicated from jake original https://lwn.net/Articles/1056387/

The robust
futex kernel API
is a way for a user-space program to ensure that the
locks it holds are properly cleaned up when it exits. But the API suffers
from a number of different problems, as André Almeida described in a session in the
“Gaming on
Linux” microconference
at the 2025 Linux Plumbers Conference in Tokyo.
He had some ideas for a new API that would solve many of those problems,
which he wanted to discuss with attendees; there is a
difficult-to-trigger race condition that he wanted to talk about too.

The collective thoughts of the interwebz