Query unstructured data in Amazon SageMaker Catalog using generative AI

Post Syndicated from Nishchai JM original https://aws.amazon.com/blogs/big-data/query-unstructured-data-in-amazon-sagemaker-catalog-using-generative-ai/

Each day, businesses generate massive amounts of unstructured data, such as PDFs, images, email, customer feedback, and medical reports. But knowing data exists isn’t enough. You need to find it, access it, and extract answers from it fast. In Part 1 of this series, you saw how to set up the producer side of the pipeline: using Amazon Textract and Anthropic Claude on Amazon Bedrock to extract and enrich metadata, and then publish those enriched assets to Amazon SageMaker Catalog so your organization can discover them.

In this post, you take the next step: the consumer side. You sign in as a data consumer, search for and subscribe to the enriched unstructured data assets, and then query them using two approaches. The first is a no-code chat agent for natural language queries. The second is Amazon Bedrock model inference for programmatic access. By the end of this post, you will know how to unlock the business knowledge inside your unstructured data and make it available to analysts and application engineers alike.

Solution overview

This post continues the two-part series architecture, where Amazon SageMaker Catalog acts as the central hub connecting data producers and consumers through a publish-subscribe model.

The consumer workflow picks up after the producer has enriched and published the unstructured data assets. As a consumer, you will:

  • Sign in to your SageMaker Unified Studio consumer project and search the catalog using keywords from the enriched metadata README.
  • Subscribe to the published Amazon Simple Storage Service (Amazon S3) asset and get the subscription approved by the producer.
  • Interact with the subscribed data through two options:
    • Option 1 – A no-code chat agent for natural language queries (NLQs), ideal for data analysts and business users.
    • Option 2 – Amazon Bedrock model inference for programmatic NLQ integration, suited for application engineers building data-driven applications.

The following diagram illustrates the consumer workflow in this solution. The consumer (1) signs in to SageMaker Unified Studio, (2) searches the Amazon SageMaker Catalog for enriched unstructured data assets using keywords from the AI-generated metadata, (3) subscribes to the S3 data asset and receives approval from the producer, and then (4) queries the data using either the Amazon Bedrock chat agent app (Option 1) or Amazon Bedrock model inference through a Jupyter notebook (Option 2).

With both a no-code and a programmatic path, consumers across different roles, from analysts to engineers, can query data in the way that fits their workflow, while the SageMaker Catalog approval workflow maintains governed access throughout.

Consumer workflow architecture: sign in to SageMaker Unified Studio, search the SageMaker Catalog, subscribe to the S3 asset with producer approval, then query with the Amazon Bedrock chat agent or model inference

Figure 1: Consumer workflow for the publish-subscribe solution

Prerequisites

Before you begin, make sure you have completed all steps in Part 1 of this series, including:

Consume published data from the consumer project

In this section, you sign in as a consumer user in the SageMaker Unified Studio consumer project. You then subscribe to the S3 bucket by searching for a keyword that is part of the README published in Part 1.

  1. Sign in to the consumer project and search for the keyword emergency, which was added to the README file during publishing. The search returns the enriched asset that the producer published in Part 1.

    SageMaker Unified Studio catalog search for the emergency keyword, returning the enriched asset published in Part 1

    Figure 2: Catalog search results for the emergency keyword

  2. Choose the asset from the results to view its details, including the AI-generated business metadata, glossary terms, and README content. Then choose Subscribe.

    Asset details page showing AI-generated business metadata, glossary terms, and README content, with the Subscribe button

    Figure 3: Asset details with AI-generated metadata and the Subscribe option

  3. Enter analysis as the Reason for request in the Comment section, then choose Request.

    Subscription request dialog with analysis entered as the reason for request in the Comment box

    Figure 4: Subscription request with the reason for request entered

  4. Sign back in to the producer project (unstructured-producer-project) to approve the subscription request.
  5. After approval, return to the consumer project and confirm that the subscribed asset now appears under Manage, Assets, Subscribed assets.

    Consumer project Subscribed assets list confirming the approved subscription

    Figure 5: Approved subscription under the Subscribed assets tab

With the subscription approved, you can now access the enriched unstructured data through two approaches.

Option 1: As a data or business analyst, you can use the Amazon Bedrock chat agent app for natural language queries.

Option 2: As an application engineer, you can use Amazon Bedrock model inference for programmatic natural language queries.

Let’s explore both options.

Option 1: Amazon Bedrock chat agent app

The Amazon Bedrock chat agent app gives you a no-code, conversational interface to query your enriched unstructured data using natural language. As a data analyst or business user, you can ask questions in plain English. You get answers grounded in the documents your organization has ingested, without writing any code. For production workloads, especially in sensitive domains such as healthcare, you can apply Amazon Bedrock Guardrails to add content filtering and grounding validation to your model responses.

Data scientists and application engineers can also extend these capabilities by integrating the chat agent app APIs into custom applications, so users can interact with unstructured Amazon S3 data programmatically.

To set up the Amazon Bedrock chat agent app on your subscribed dataset, complete the following steps.

Prerequisite: Add the S3 data location.

Before creating the chat agent app, you need to add the S3 location of your subscribed data as a registered location in your project.

  1. Choose the Data tab in Overview.
  2. Choose the S3 bucket, and then choose Add to add the S3 location.

    Data tab in the project Overview with the S3 bucket selected and the Add button to register the S3 location

    Figure 6: Adding the S3 location from the Data tab

  3. On the S3 location page, provide the following details:
    • Add a name: producerprojectdata.
    • Add the producer’s S3 path as a new S3 location: s3://amzn-sagemaker-bucket-<domain-id>-<project-id>/medical/.

    Note: You can get the S3 location details from the technical name of your subscribed asset.

    • Choose the AWS Region, and then choose Add data to add this as a new location.

    Note: Make sure the AWS Region you select supports the Amazon Bedrock foundation models used later in this post. For a list of available models by Region, see Supported Regions and models for Amazon Bedrock.

    S3 location page with the location name, producer S3 path, and AWS Region entered before choosing Add data

    Figure 7: S3 location details and AWS Region selection

    Note: Make sure to select only the PDF files within the S3 path for the data source.

    Data source selection showing only the PDF files within the S3 path selected

    Figure 8: Selecting the PDF files as the data source

After the location is added, it appears as a selectable S3 location when creating a knowledge base in AI Apps.

Complete the following steps to configure the chat agent app:

  1. In the left navigation pane, under Generative AI, choose AI Apps.
  2. In the Build section of the page, choose Chat agent.

    AI Apps Build section with Chat agent selected in the left navigation under Generative AI

    Figure 9: Choosing Chat agent in the AI Apps Build section

  3. Expand the Data tab to create a knowledge base with your S3 bucket. On the Create a new knowledge base page, enter the following:
    • Add a name: MedicalKB.
    • Add a description: Knowledge base built from subscribed medical S3 data assets. Contains medical documents used to provide grounded, context-aware responses to medical domain queries.
    • Choose the data source. You will see the S3 bucket that you added in the previous step.
    Create a new knowledge base page with the MedicalKB name, description, and the added S3 bucket as the data source

    Figure 10: Creating the MedicalKB knowledge base from the S3 data source

  4. Choose your embedding model. You can leave the default settings and choose Create. It might take 10–15 minutes to create the knowledge base, depending on file sizes.
  5. After the knowledge base is created, on the Chat agent page:
    • Choose your preferred model from the Model menu (you can switch between different large language models as needed).
    • Under Data, choose your published S3 bucket as the knowledge base.
    • Begin interacting with the agent by entering questions in the Enter prompt field.
    Chat agent page with a model selected and the MedicalKB knowledge base chosen, ready to enter a prompt

    Figure 11: Chat agent page with the model and knowledge base selected

For example, entering “Which age groups had the highest rates of emergency department visits for tooth disorders?” returns an answer grounded in the enriched dental dataset published in Part 1.

The chat agent uses the enriched README metadata along with the underlying documents to surface contextually relevant answers. Analysts can explore unstructured content without needing to know where the data lives or how it’s structured.

Option 2: Natural language queries using Amazon Bedrock model inference

This option demonstrates how to use Amazon Bedrock model inference to query subscribed data using natural language. You can integrate this capability with external chat applications so users can run natural language queries through Amazon Bedrock.

  1. In your consumer project, choose Manage, Assets from the bottom of the left navigation pane. On the Subscribed tab, choose your subscribed S3 asset. Under Actions, choose Open JupyterLab notebook.

    Subscribed S3 asset Actions menu with Open JupyterLab notebook selected in the consumer project

    Figure 12: Opening the JupyterLab notebook from the subscribed asset

  2. This opens the JupyterLab notebook environment. Upload the s3_document_consumer_v2.ipynb notebook and run all the cells. You can download the notebook from s3_document_consumer_v2.ipynb.Note: The project role requires permissions for Amazon S3, Amazon Textract, and Amazon Bedrock. If you followed Part 1, you might already have these policies attached. For details on the required policies and guidance, see the prerequisites in Part 1.
  3. Review the notebook cells.
    JupyterLab notebook cells with the final cell showing a sample question answered by Amazon Bedrock

    Figure 13: Sample question answered by Amazon Bedrock in the notebook

    In the final cell, you find a sample question that Amazon Bedrock answers: “Which primary payer types (Medicare, Medicaid, private insurance, and so on) account for the highest proportion of dental-related emergency department visits?”

    Amazon Bedrock processes the question against the enriched content in the S3 bucket and returns a grounded answer. You can replace this sample question with any query relevant to your documents.

The Amazon Bedrock model inference approach gives you programmatic control, making it possible to embed natural language query capabilities directly into your existing data applications and business intelligence tools.

Clean up

To avoid ongoing charges, make sure to delete the resources used in this solution immediately after completing the walkthrough. The primary cost drivers are SageMaker Unified Studio notebook instances, Amazon Bedrock model inference calls, and Amazon S3 storage.

  1. Stop SageMaker Unified Studio resources:
    • Close running notebooks.
    • Stop running notebook instances.
    • Shut down unused kernels.

    Note: Running notebook instances continue to incur charges even when not in use.

  2. Clean Amazon S3 storage:
    • Delete temporary files created during processing.
    • Remove uploaded test documents that are no longer needed.

    Note: Although Amazon S3 costs are minimal, large volumes of data can accumulate significant charges, so it’s best to remove unneeded data.

Conclusion

In this post, you saw how to consume and query the enriched unstructured data assets published in Part 1 of this series. By subscribing to assets through the Amazon SageMaker Catalog publish-subscribe model, you can discover, access, and interact with your organization’s unstructured data, whether through the no-code chat agent or Amazon Bedrock model inference.

Together, both parts of this series show you how to build a comprehensive pipeline that transforms raw unstructured documents into governed, queryable knowledge assets. The combination of Amazon Textract for extraction, Amazon Bedrock for intelligent summarization and NLQ, and Amazon SageMaker Catalog for governance and discoverability means your teams can focus on extracting business insights rather than managing infrastructure.

To continue your Amazon SageMaker journey, see the following resources:


About the authors

Nishchai JM

Nishchai JM

Nishchai is an Analytics and generative AI Specialist Solutions Architect at Amazon Web Services. He specializes in building larger scale distributed applications and helps customers modernize their workloads on AWS. He thinks Data is new oil and spends most of his time deriving insights from data.

KiKi Nwangwu

KiKi Nwangwu

KiKi is an Analytics and generative AI Specialist Solutions Architect at AWS. She specializes in helping customers architect, build, and modernize scalable data analytics and generative AI solutions. She enjoys traveling and exploring new cultures.

Narendra Gupta

Narendra Gupta

Narendra is a Sr. Specialist Solutions Architect for Data & AI (Analytics) at AWS. He works with customers to design data-driven solutions and has deep expertise in data governance and cataloging.

Aditya Edara

Aditya Edara

Aditya is a Support Engineer at AWS. He serves as a Subject Matter Expert in AWS Analytics services, specializing in Amazon EMR and AWS Glue. Aditya provides expert guidance and technical support to enterprise and strategic customers, helping them optimize data analytics solutions.

[$] Ideas on modernizing the open-source desktop

Post Syndicated from jzb original https://lwn.net/Articles/1095425/

Scott Jenson has been working on user interfaces (UIs) and user experience (UX)
for many years at Apple, Google, and other companies. Now, he’s trying to convince
open-source projects to experiment more and drive the desktop beyond the age-old “windows, icons, menus,
pointer
” (WIMP) model. At Akademy 2026, KDE’s annual developer
conference, he shared his complaints and ideas in a talk aimed
at convincing those in attendance to take the lead on desktop design.

Systemd v262 released

Post Syndicated from jzb original https://lwn.net/Articles/1096204/

Systemd v262 has been released. Some of the notable new features include the
ability to build systemd as a single statically linked binary for small
containers, support for the kernel coredump socket protocol introduced with
Linux 6.17, addition of OpenSSL 4 support, and many other changes. See
the release
notes
for a full list of changes.

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever

Post Syndicated from Grace Zhang original https://aws.amazon.com/blogs/security/supporting-asds-multi-factor-authentication-campaign-why-mfa-matters-more-than-ever/

The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message.

As threat actors continue to target credentials through phishing, credential stuffing, and social engineering, passwords alone are no longer enough. MFA is one of the most effective security controls available. It’s a cornerstone of ASD’s Essential Eight maturity model and a recognized component of major cybersecurity frameworks worldwide. ASD’s campaign reinforces what the security community has long advocated: switching on MFA is one of the simplest and most impactful steps any organization or individual can take to protect themselves online, and we encourage all to heed ASD’s call.

How AWS enforces MFA across every account type

At AWS, we’ve put this principle into practice at scale. In June 2025, AWS Identity and Access Management (IAM) achieved comprehensive MFA enforcement for root users across all account types, a significant milestone and the first of its kind among major cloud providers. This was the culmination of a deliberate, phased security journey: beginning with requiring MFA for AWS Organizations management account root users in May 2024, expanding to standalone account root users in June 2024, introducing centralized root access management in November 2024, and completing enforcement across all account types including member accounts. MFA prevents over 99 percent of password-related attacks and is available to all AWS customers at no additional cost, with support for FIDO2 passkeys and FIDO-certified security keys for phishing-resistant authentication. This milestone reflects our ongoing commitment to secure-by-design principles, setting a high bar for our customers’ default security posture and demonstrating that organizations of any scale can, and should, make MFA the standard rather than the exception.

ASD’s Multi-factor authentication: Switch it on campaign banner

Extending MFA beyond your AWS environment

A compromised email account can be used to reset AWS passwords. A breached source control system can expose infrastructure-as-code secrets. Enable MFA on your email, collaboration tools, source control, and other services that support it. Visit the ASD Multi-factor authentication campaign page for broader guidance.

Getting started with MFA on AWS

AWS enforces MFA automatically for root users. To extend that same protection to your IAM users—the identities your team members and applications use daily—you can configure MFA individually through the AWS Management Console for IAM. To learn more, see Security best practices in IAM. For phishing-resistant authentication with FIDO2 passkeys, see Passkeys and security keys in IAM.

If you have questions or feedback about MFA on AWS, leave a comment below or reach out on AWS re:Post. If you haven’t already, heed ASD’s call and switch on MFA across every account you own.

This post was written in support of ASD’s Multi-factor authentication: Switch it on campaign. For more AWS security content, visit the AWS Security Blog.

If you have feedback about this post, submit comments in the Comments section below.


Grace Zhang

Grace Zhang

Grace is the Regulatory and Security Compliance Lead for Australia and New Zealand (ANZ), based in Sydney. She supports security assurance and compliance initiatives across the ANZ region, helping customers navigate regulatory requirements and build confidence in the security of the AWS Cloud.

Critical security vulnerabilities in the Radicle network protocol

Post Syndicated from jzb original https://lwn.net/Articles/1096200/

The Radicle peer-to-peer
code-collaboration project has disclosed
two critical vulnerabilities
in the network protocol used by Radicle
nodes. The first flaw is that the network protocol used by Radicle “does not
give the confidentiality it was expected to give
“, which allows anyone who
can observe the network between two nodes to read the data exchanged. The second
is that peer authentication is broken and allows impersonation, so an attacker
can spoof their Node ID and read private repositories they should not be able to
read.

In practice, the two flaws are most useful when they can be exploited
together: an attacker on the path sees the Node IDs at both ends of a
connection, and both are normally on the allow-list. That attacker can read
whatever is exchanged while they watch, and can then use a Node ID they saw to
fetch the whole repository on demand. The realistic threat is anyone on the path
between your node and node it syncs with, and no setting or allow-list protects
against them.

We are publishing this before the security update is available. You can act
on it today, and no fix we release later can undo an exposure that has already
happened.

See the post for workarounds that can be used today; a major update that will
be backward-incompatible is underway.

Critical WordPress RCE vulnerability announced

Post Syndicated from jzb original https://lwn.net/Articles/1096195/

A critical
vulnerability
has been discovered in WordPress‘s get_page_template()
function for page-template resolution that could allow remote-code execution
(RCE) by an unauthenticated attacker, in some limited circumstances. The project
has provided an update for the most recent branch of WordPress, as well as
backports of the fix for branches back to 4.7. See the
vulnerability report for the conditions required for an RCE attack to be successful.

The vulnerability also
affects
the ClassicPress fork of
WordPress, though a security update has not been provided for that project
yet. LWN covered ClassicPress in
2024. Users of either content-management system should update soon.

How dynamic application security testing validates risk at runtime

Post Syndicated from Rapid7 original https://www.rapid7.com/blog/post/em-dynamic-application-security-testing-dast-validates-risk-at-runtime-idc-marketscape

Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it?

Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment (Doc #US54119126, September 2026). The IDC MarketScape evaluated 16 vendors and named Rapid7 a Leader.

We believe the result reflects the strength of Rapid7’s DAST capabilities, but the IDC MarketScape also offers a useful view of where the category is heading. DAST has developed beyond traditional web scanning into a source of runtime evidence that can help organizations validate risk across the application layer.

From possible weakness to validated application risk

Code analysis and dependency scanning help teams identify weaknesses before an application is deployed. DAST provides a different view by interacting with the assembled application while it is running. It can show what happens when a particular request reaches the application, how the application responds, and whether a suspected weakness can be reproduced.

This is especially valuable for APIs and AI-backed applications, where risk may emerge through interactions among models, prompts, data, tools, and permissions. Some of these behaviors cannot be fully understood from source code or a dependency manifest. They become visible when the application is exercised under runtime conditions.

DAST therefore has a direct role in continuous threat exposure management (CTEM). Discovery gives teams a view of their assets and possible weaknesses, but that view alone does not tell them where to focus. Validation helps narrow the field by showing which exposures can be reached or exploited and providing evidence that teams can use to take action.

For Rapid7, DAST is exposure management applied to the application layer. Web applications, APIs, and AI-backed endpoints are all part of the attack surface, so they need to be discovered, tested, prioritized, and managed alongside infrastructure, cloud, and other exposures.

Why we believe Rapid7 was named a Leader by IDC

Rapid7’s DAST solution is delivered as part of the Exposure Command portfolio. Its scan engine maps an application, executes attacks against the discovered paths, and validates confirmed findings. Security teams can map a broad area of an application while limiting active attacks to an appropriate set of paths, giving them control over how testing is performed.

Findings are checked against Rapid7 telemetry to help determine which issues warrant closer attention. When a finding needs action, browser-based replay reproduces the original request, the attack request, and the triggering response. Developers receive evidence they can work with, rather than a finding they must first spend time proving.

Authenticated scanning can be difficult to maintain across a changing application portfolio, and a broken login sequence can leave important areas untested. Rapid7’s solution can identify the affected step and support a targeted update without requiring the entire sequence to be recorded again.

The connection with Surface Command adds another useful layer. Newly discovered external assets can be surfaced for application testing, helping teams close the gap between finding an application and understanding the risk it presents

DAST plays a core role within Exposure Command: providing the application-layer validation teams need to prioritize risk and move from findings to remediation.

Learn more about Rapid7 Exposure Command.

Security updates for Wednesday

Post Syndicated from jzb original https://lwn.net/Articles/1096191/

Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10.0, dotnet8.0, dotnet9.0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5.15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7.0, linux-azure-fde-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-oracle, linux-oracle-6.8, linux-raspi, openssh, and sudo).

Research on Models Engaging in Genie-Like Behavior

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html

New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”

Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be associated with the benign intent of “a security professional trying to test defense,” despite no such benign context being provided as input. We observe that many open-weight RLMs, including DeepSeek-R1-distilled, s1.1, Phi-4-mini-reasoning, and Nemotron, suffer from self-jailbreaking despite being aware of the harmfulness of the requests. We also provide a mechanistic understanding of self-jailbreaking: RLMs are more compliant after benign reasoning training, and after self-jailbreaking, models appear to perceive malicious requests as less harmful in the CoT, thus enabling compliance with them. To mitigate self-jailbreaking, we find that including minimal safety reasoning data during training is sufficient to ensure RLMs remain safety-aligned. Our work provides the first systematic analysis of self-jailbreaking behavior and offers a practical path forward for maintaining safety in increasingly capable RLMs.

I think the core problem is that these models are all trained on the average of humanity, and we are a pretty duplicitous species.

6 раздувки за варненското лято 2026

Post Syndicated from Веселин Златков original https://www.toest.bg/6-razduvki-za-varnenskoto-lyato-2026/

6 раздувки за варненското лято 2026

През лятото край морето има много надуваеми елементи – пояси, дюшеци, топки, лодки и т.н. Затова си позволявам да определя жанра на наблюденията и разсъжденията си за отминалия туристически сезон във Варна като „раздувка“. Думата беше популярна едно време, преди всички да заговорят за наратива. Раздувките ми нямат претенции да са прецизен анализ, а и така се случи, че това не беше най-активното ми лято, но все пак някои детайли от този ключов сезон за варненския живот си заслужава да бъдат изтъкнати. 

1. Нямаше туристи 

Е как да има?! Вече всеки си е купил апартамент във Варна, нормално е хотелите да останат празни. Нормално е и ресторантите да останат празни, защото е по-лесно и по-евтино, като имаш кухня, да си сготвиш нещо лятно и свежо там, вместо да рискуваш с непроверени откъм обслужване и меню заведения. 

Разбира се, този довод е по-скоро шега, но в нея има доза истина, особено ако говорим за родните туристи, както и за чужденците, които са инвестирали в имот край морето ни. А последните не са никак малко.

Истината е, че в началото на лятото Варна изглеждаше поразително пуста, каквато не сме я виждали от много време. В края на сезона министърът на туризма, т.нар. представители на бранша и всички, чиято задача е да внасят спокойствие в обстановката, заявяват, че първоначалният кошмарен спад е компенсиран и резултатите са в крайна сметка като през миналата година. 

Спирането на чартърните полети от Германия, за което така и не стана ясно как е допуснато и по чия вина се е стигнало до него, лиши курортите ни от около 120 000 германци, които винаги са били гръбнакът на сезона.

Отсега се водят преговори за възстановяване и гарантиране на тази ключова транспортна връзка за следващото лято. Проблемът обаче трябва да отвори дебат за алтернативни варианти на системата, по която работи туризмът ни вече десетилетия. Големите групи от германски пенсионери, които прииждаха край Варна още от май, преди дори да се е стоплило морето, вече са минало. Туризмът ни трябва да се модернизира, но това, изглежда, не става твърде бързо.

6 раздувки за варненското лято 2026
© Веселин Златков

2. Храната

Последното издание на кулинарното риалити MasterChef преди две години беше спечелено от варненката Марианна Александрова. Както се оказа, тя не искаше просто телевизионна слава, а си беше поставила по-амбициозна цел – да изгражда специфична варненска кулинарна идентичност. Александрова е преподавателка в Колежа по туризъм, изследва стари готварски традиции и намира рецепта за паста с миди във вестник от 1896 г. Според нея тъкмо това ястие може да стане хит на оригиналната „варненска“ кухня.

В колко варненски ресторанти се предлага паста с миди ала XIX век, признавам си, не знам. Но едва ли са много. На теория цялата идея да има варненско ястие, което да е като запазена марка за града, е супер.

На практика обаче храната започва да се превръща в ахилесовата пета на преживяването „почивка във Варна“.

 Доста хора се възмутиха от цените на един обяд или на една вечеря край морето, но според мен това не е основният проблем. Проблемът е в качеството както на продуктите, така и на приготвянето им. И дори не е необходимо да опитвате – достатъчно е да помиришете.

Над пристанището и покрай Морските бани във Варна и това лято доминираше една миризма – не на море и водорасли, а на прегоряло олио и непочистени скари. Това е положението, това е реалната кулинарна варненска идентичност, колкото и да не ни се иска.

6 раздувки за варненското лято 2026
© Веселин Златков

3. Боклукът

Варна никога не е била толкова мръсна, колкото това лято. Вярно е, че всяка година, когато градът се напълни с туристи, контейнерите започват да преливат. Този път обаче не беше само това. Метачките изчезнаха от улиците на града през юни и се появиха пак едва в края на август, без ясна причина за липсата им. За миене на улиците изобщо не говорим – такава дейност нямаше. Между плочките на тротоарите и покрай бордюрите поникнаха всякакви бурени, които никой не се погрижи поне веднъж да бъдат разчистени. Изобщо, да ходиш с джапанки или със сандали по варненските улици това лято си беше предизвикателство, защото не знаеш какво ще настъпиш.

Имаше обаче и друго явление, доста гнусно и срамно – празни контейнери и разпилени около тях отпадъци.

Видео, публикувано в социалните мрежи, показа причината за това безобразие. На него се вижда как мъж с жълта жилетка, който не просто оставя торба с отпадъци до контейнера вместо в него, а изсипва отпадъците на улицата. Напълно съзнателно. А при въпрос защо го прави, той обяснява, че така му е наредено от някой си „Мишо от „Хепи“. Всичко това – в самия център на града, до емблематичния хотел „Черно море“.

Привърженици на кмета Благомир Коцев твърдят, че подобни саботажи се правят най-редовно, буквално от първия ден на мандата му. Честно казано, не вярвах да е вярно, докато не видях въпросните кадри. Колко трябва да мразиш кмета, за да замърсяваш съзнателно града си с цел да злепоставиш Коцев? Нямам отговор на този въпрос. И не вярвам, че някой може да има разумен довод за тази свинщина. По-лошото е, че не личи по нищо органите на реда да им пука за това, да не говорим да установят и накажат виновните.

4. Фестивалите

Когато слизате към морето по централното стълбище към Морските бани, попадате на тераса, на която е написано „1926“. Това е годината, в които баните са завършени и Варна по същество става истински курорт – пет години след официалното обявяване. В същата година започват и Народните летни музикални тържества – първият български фестивал, днес познат като Международния музикален фестивал „Варненско лято“. Почитателите на класическата музика коментират, че тази година изданието му е било подобаващо за 100-годишнината. Но колко привлекателна е класическата музика за един съвременен турист?

Въпреки че през лятото във Варна постоянно има някакви събития с фестивален характер, мнозина твърдят, че културният календар на града е твърде рехав. Това може да звучи парадоксално, но всъщност показва една очевидна липса – на голям поп или рок фестивал като тези в Пловдив.

6 раздувки за варненското лято 2026
© Веселин Златков

Варна остана и това лято без световни звезди, което навява усещане за провинциалност. 

На този фон неуспешната кандидатура на града за домакин на „Евровизия“ не трябва да изненадва никого. От самото начало се знаеше, че Варна няма зала за 10 000 души – основно изискване за прословутия конкурс. Какво решение ще получи този проблем, е въпрос, на който трябва да отговори държавата – подобен обект не може да бъде изграден само с местни усилия.

5. Нож за украинците

Да се върнем към надуваемите летни предмети, с които започнах тези „раздувки“. Малко неочаквано това лято в морето на Офицерския плаж се появи аквапарк. Казвам „неочаквано“, защото да разположиш съоръжение за деца точно на мястото, където пробите за чистотата на водата са все на ръба на допустимото, не е много логично. Но след като концесионери, наематели, контролни органи и в крайна сметка клиентите на атракциона не виждат проблем в това, няма какво да коментираме. 

Големият проблем с надуваемия аквапарк се оказа друг – че се управлява от украинци.

Антиукраинските настроения във Варна са дълга и сложна тема, но този път грозните изстъпления в социалните мрежи бяха надминати от нещо още по-грозно. В средата на август елементи от аквапарка бяха срязани и се наложи да бъде затворен, за да се отстранят щетите от вандалския акт. 

Екипът на аквапарка съобщи това във Facebook със съжаление и откровено учудване от случилото се. Вместо някакво съчувствие и нормално осъждане на вандализма, съобщението беше последвано от масов хейт и откровена ксенофобия. Коментари от типа „Махайте се, отивайте си в Украйна“, „Вземете си аквапарка и си го закарайте в Одеса“ бяха най-меките. 

Честно казано, като варненец изпитах истински срам от тази реакция. Почти толкова, колкото от кадрите със съзнателното изсипване на боклук до контейнерите. И този път органите на реда не показаха някаква амбиция да разследват, да установят извършителя и евентуалния поръчител на безобразието и да го накажат.

6 раздувки за варненското лято 2026
© Веселин Златков

6. Син кит

В самия край на лятото, в топлото начало на септември (най-хубавото време да си варненец или да посетиш града), на входа на Морската градина се появи огромен син кит в реални размери – 28 метра дължина. Надуваемото животно стана сензация буквално за часове. Оказа се, че поставянето му е част от форум на морски експерти, чиято тема беше избягването на инциденти между големите морски бозайници и корабите. 

Децата подскачаха и се радваха, възрастните снимаха, та снимаха с телефоните, а в социалните мрежи… Е, там пак беше касапница! „Това ли измислихте?! От това ли има нужда Варна? Позор!“ – такъв беше основният тон на коментарите, буквално стотици, може би хиляди. 

6 раздувки за варненското лято 2026
© Веселин Златков

И тук вече престанах да се срамувам и възмущавам от масовия хейт и просто се натъжих. Какво се случва с варненци, моите мили съграждани? Наистина ли такова е масовото им мнение, или става въпрос за някаква целенасочена тролска атака? 

Ако китът беше червен, розов или кафяв, щяха ли да му се зарадват? Или щяха да го нарежат, ако някой беше пуснал слуха, че китът е украински? 

Варна преминава през период на криза, която няма да завърши с края на този летен сезон – това е очевидно. Ясно е също, че без отговорността и съзнателните усилия на гражданите си т.нар. Морска перла няма да стане по-приветливо и приятно място. Но изглежда, варненци напоследък са ангажирани предимно с това да не харесват. Да не харесват и да не правят нищо, бих добавил. 

CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

Post Syndicated from Rapid7 original https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm

Overview

On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.

BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML. CVE-2026-94127 is not exposed in a default configuration: exploitation requires a BIG-IP virtual server with both an APM access policy and an OAuth profile configured. Because affected BIG-IP systems may process traffic at an organization’s network edge, organizations using this configuration should prioritize remediation.

The vulnerability affects the data plane and does not expose the BIG-IP control plane. BIG-IP systems operating in Appliance mode are also affected.

F5 lists the following affected release trains and corresponding fixed hotfixes:

  • BIG-IP 21.1.0: versions prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG

  • BIG-IP 17.5.0: versions prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG

  • BIG-IP 17.1.0: versions prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG

As of September 22, 2026, CVE-2026-94127 has been added to the CISA KEV while a publicly available proof of concept was not confirmed.

Mitigation guidance

Organizations running affected F5 BIG-IP deployments should apply the appropriate F5 hotfix as soon as operationally feasible, particularly where a vulnerable APM and OAuth configuration is reachable from untrusted networks.

F5 lists the following remediation versions:

  • BIG-IP 21.1.0: update to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG or later.

  • BIG-IP 17.5.0: update to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG or later.

  • BIG-IP 17.1.0: update to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG or later.

Administrators should first determine whether a BIG-IP APM access policy and an OAuth profile are configured together on a virtual server, since this configuration is required for exposure.

For organizations that cannot immediately apply the applicable update, F5 provides an iRule workaround through F5 Support. Customers should open a support case with F5 to obtain the vendor-provided workaround and follow F5’s implementation guidance.

Rapid7 customers

Exposure Command, Vulnerability Management, and Nexpose

Exposure Command, Vulnerability Management, Nexpose customers can assess exposure to CVE-2026-94127 using vulnerability checks expected to be available in today’s (September 23) content release.

Updates

  • September 22, 2026: Initial publication.

“We can figure it out”: How one Minnesota teacher uses Experience CS to set the tone for her whole year

Post Syndicated from Sofia Mohammed original https://www.raspberrypi.org/blog/we-can-figure-it-out-how-one-minnesota-teacher-uses-experience-cs-to-set-the-tone-for-her-whole-year/

Walk into Allison Knoph’s fifth grade classroom in Edina, Minnesota in October and the creative writing station will be the loudest place in the room.

That is by design. “I use it at my creative writing station,” she says of Experience CS, which she has run each fall for the past couple of years. Kids use the station computers to be creative as they work on their programming projects, building characters and testing jokes they have written. Some laugh hard enough that a visitor might wonder if anyone is working.

“Giggling,” Allison says, “is a good problem to have.”

Placement matters

Experience CS is a standards-aligned computer science curriculum for grades 3 to 8 (ages 8 to 14) that integrates computing into core subjects like math, science, and art. Allison has completed two units with her students, The me project, designed for fourth grade (ages 9 to 10), and Ecosystems, designed for seventh grade (ages 12 to 13).

2 units: How to program a mystery, designed for fifth grade (ages 10 to 11), and Ecosystems, designed for seventh grade (ages 12 to 13).

Of the two units, the storywriting-themed The me project was the stronger fit. It mapped cleanly onto language arts work her students were already doing. Students hit the signposts the unit lays out, but what they did inside that structure was theirs. One wrote the minimum and moved on. Another built a multi-scene story with custom sound effects, spending three weeks developing their project and making improvements.

The Ecosystems unit was more challenging for her students, and the students who finished “were the ones who were kind of the more gung-ho ones that were really into it.” She is not dismissing it, but she is clear that placement matters.

Helping each other

Allison highlighted that some of the students who were thriving in the Experience CS lessons were students who were experiencing difficulties in other areas of the curriculum. “The kids who don’t normally shine often do here,” she says. Describing one experience from her classroom, she shared that a student who had difficulties with reading quickly understood how a program should be sequenced. Within a week, classmates were walking to that desk for help. The peer support model is not something she engineers. It builds itself.

Running the lessons in October sets a tone she draws on all year. Something breaks, a student gets stuck, and the answer in her room becomes “We can figure it out.” That carries into math, into writing, into everything after.

Why now

Allison is not arguing that every student will grow up to write code. Her argument is that computational thinking transfers, and that it looks a lot like the writing instruction she is already doing: syntax, structure, sequence. Debugging a story and debugging a program are closer cousins than most people think.

Young people with a teacher in the classroom

In the age of AI, computational thinking and coding skills are especially important. Access to AI tools makes it easier for more people to generate code. Fewer people can read it, judge whether it is any good, and change it. Allison saw this on her son’s robotics team: the students who understood their code could adapt it when the robot did something unexpected. The ones who had generated code and dropped it in could not. Same tools, different outcomes, and the difference was comprehension.

The context in Minnesota

Minnesota ranks near the bottom nationally for computer science access. In the most recent state-by-state accounting, 34 percent of its public high schools offered a foundational CS course, against a national average of 60 percent.

As a fifth grade teacher, Allison believes that if students may not have opportunities to learn CS in high school, the introduction has to happen earlier, in a classroom not labeled computer science.

She is candid that the barrier for elementary teachers is not interest. It is time, cost, and the fear of being asked a question they cannot answer. She sums up the Experience CS offering to her colleagues in a few words: free, little direct instruction, fits standards she is already teaching, and the kids like it enough to be loud about it.

“We can figure it out” is a good thing for a teacher to say out loud. It is a better thing for a room of ten-year-olds to start saying back.

Find out more about introducing Experience CS in your classroom: head to experience-cs.org today.

The post “We can figure it out”: How one Minnesota teacher uses Experience CS to set the tone for her whole year appeared first on Raspberry Pi Foundation.

„Господът на световете“. Извънземни и ислям (продължение)

Post Syndicated from Атанас Шиников original https://www.toest.bg/gospodut-na-svetovete-izvunzemni-i-islyam-produlzhenie/

<< Към първа част

„Господът на световете“. Извънземни и ислям (продължение)

Средновековните извори, особено от външни нам култури, имат особена динамика. На пръв поглед изглеждат непроницаеми, езикът е тежък, сух, често са сложни, витиевати, с множество скрити препратки, особено към текстове, които читателите следва да знаят по подразбиране. Няма бележки под линия, няма обяснения. Но с това се свиква и носи особено удоволствие, почти като да чоплиш тиквени или слънчогледови семки. За непосветените изглежда скучна повторяема дейност. Ала за нейните адепти носи огромно удовлетворение както веднага, така и с натрупването в дългосрочен план. И често пъти, особено когато става въпрос за Корана и Сунната, изворите осмислят събития от съвремието. Тъй де, откъде иначе човек може да разбере защо вече споменатата в предишната част ИДИЛ нарича списанието си „Дабик“?

Съвременните възгледи също не са еднозначни. Ето този любопитен читател отправя запитване към портала за фетви на катарското Министерство на религиозните дарения и работи: „Искам да Ви запитам относно въпроса за извънземните.“ Има ли ги споменати в Корана и Сунната? Ако не, откъде идвал тоя израз „извънземни същества“, което на арабски тук е буквално „космически същества“ (ка’инат фада’ийа). Запитването става още по-интересно: какво мислят религиозните авторитети за твърденията, че извънземните са създали човека подобен на тях чрез ДНК технологии, че те са помагали на фараоните да построят пирамидите, че те са силата, довела до съществуването на човека, и в крайна сметка как изглеждат? Дали изображенията, които намираме по мрежата, са истински, или са изфантазирани, за да убедят хората, че извънземни съществуват?

Мисля, че питането е достойно за едновремешния вестник „Психо“ или сходния му днес „Феномен“, който често си купувам, за да си сверя конспиративно-окултния часовник. Но както обичам да казвам, в мюсюлманското право и богословие срамен въпрос няма. Все пак става дума за съвършения Свещен закон на Всевишния. Там трябва да има отговор на всичко.

Отговорът е изненадващо разкрепостен, още повече че това е катарското министерство. Онзи, който е създал човека, и го е изваял че после му е и вдъхнал живот – тоест самият Аллах, – е способен да създаде и извънземни. Свещеният Коран е посочил, че има същества, които не са били известни на човечеството по времето на Пророка, ролята на научните открития, както и че за всяко нещо има определено време, което ще настъпи. Аргументът е вече цитираният от мен текст в Коран 16:8: „[Сътвори] и конете, и мулетата, и магаретата – за да ги яздите и за украса. И сътвори Той каквото не знаете“; „Всяка вест си има определено време и ще узнаете“ (6:67), и вече известното ни знамение за „небесните добичета“ (42:29), където, пояснява богословът, терминът дабба според някои религиозни учени обозначава създания, различни от ангелите, тъй като Всевишният прави разлика между онова, което е дабба, тук „твар“, и ангелите в самия Коран: „На Аллах се покланя в суджуд всичко на небесата и всяка твар по земята, и ангелите – без да се големеят“ (16:49).

Ако трябва да бъда донякъде критичен, тук нашият превод ми се вижда излишно рестриктивен и прокарва определено тълкувание. Защото арабският оригинал не ни казва точно „всичко на небесата и всяка твар на земята“, а по-скоро „всяка твар на небесата и земята“ (ма фи с-самауат уа-ма фи л-ард мин дабба). А пък суджуд, както е известно в мюсюлманската ритуална практика, е покланянето с чело до пода и ако бях един средновековен богослов като Ибн Таймия от XIII век например, щях да разсъждавам върху това как небесните твари, които не са ангели, а очевидно са нещо друго, свеждат чело до земята, какво тяло имат, колко и какви крайници, стави, имат ли глава, дали е повече от една, въобще как се извършва този жест на ритуално поклонение от чисто механична гледна точка.

Но да оставим тази спекулация за друг път и да продължим с катарската фетва на Министерството. Нали е важно какво казва религиозният истаблишмънт. На базата на тези текстове, твърди богословът, „хората на знанието“, тоест религиозните учени, или поне някои от тях, твърдят, че няма пречки да съществуват други „вселени“ или „светове“, без да е напълно сигурно, доколкото свещените текстове подлежат на тълкуване. Ала не си мислете, че това разкрепостено тълкуване се простира благосклонно върху окултно-конспиративните теории за сътворението на човека от извънземен разум чрез ДНК манипулация. Това допускане е откровена безсмислица. Та не е ли самият Аллах създател на човека според писаното „Сътворихме Ние човека от подбрана глина“ и т.н. (Коран 23:12)? За фараоните и извънземните позицията е по-мека, била тя и скептична – няма категорично доказателство за подобно, хм, строително сътрудничество (по мое четене), та и е правилно мюсюлманите да не се вдават много-много в разсъждения в тая посока.

Подобни позиции, с много сходна коранична основа, се застъпват и от други популярни богослови, ето например един Ясир Кади, богослов от САЩ, в онлайн канала му. Той преповтаря почти буквално старите аргументи, че и се опира на вече споменатия Ибн Таймия, който пък разсъждава върху възможностите за безкрайни творчески актове на Аллах, които, разбира се, включват и други светове. А ако това е така, логично е мюсюлманите да се вълнуват от съвременни дискусии, свързани с доказателства за извънземни, мислени през феномена на неидентифицираните летящи обекти.

И тук се натъкваме на една от пресечните точки между американската администрация и религиозните мюсюлмани. Защото, както видяхме, няма религиозно противоречие ходжата или всеки един религиозен мюсюлманин да допускат, че в произшествието в Розуел, САЩ, от 1947 г. например има зрънце истина. Сигурно и от гледна точка на вярата „няма лошо“, както се казва на арабски (ла ба’с), да се мисли и за нашенската Царичина дупка от 1990 г., когато български военни копаят в търсене на извънземни край София по указанията на екстрасенси. Не съм попадал обаче на тукашно мюсюлманско размишление по въпроса. Търсенето ми онлайн на комбинация от „извънземни“ и „Главно мюфтийство“ ме препраща към Отдел „Външни отношения“ на Мюсюлманското вероизповедание. Но не външни на Земята, или поне засега. Сигурно някой ден може да е другояче, ако тълкувателите на Корана в полза на космическите пришълци се окажат прави.

През 2017 г. излязоха данни, че Пентагонът използва десетки милиони долари „черни пари“ от военния бюджет за проучване на свидетелства за НЛО в рамките на програма за идентифициране на заплахи за въздушното пространство. Както отбелязва и Sapience, американски мюсюлмански институт за проучване на връзката между религията и науката, тези разкрития наливат наново вода в мелницата на интереса към извънземните. Според института

може да се прокара връзка между наблюдаваните прояви на НЛО и споменатите в ислямската традиция джинове.

Тези паралели вървят по няколко линии. На първо място, характеристиките при описанията на двата феномена – странни същества, които променят формата си, летящи, неестествено движещи се обекти. Второ, измамата като основна тема и в двата случая. И в разказите за НЛО, и в старите истории за джинове имаме елемент на заблуда и оптически илюзии. Трето, разказите за отвличания. И накрая, сходствата при случаи, свързани с обладаване, т.нар. стопаджийски ефект (hitchhiker effect) – след отвличане и посещение на извънземни човек носи остатъчни ефекти от него. След като веднъж срещнеш съществата от друг пласт на реалността, те оставят следа върху теб. Не се ли загатва и същото в текста на Корана: „Които изяждат лихвата, не ще се изправят, освен както се изправя някой, когото сатаната поваля от лудост“ (2:275), където се допуска възможността дяволът да доведе някого до безумие?

Тук трябва да направим и важно терминологично уточнение. Вместо „извънземен“ (extraterrestrial) някои учени използват термина „криптоземен“ или „скритоземен“ (cryptoterrestrial), доколкото той обозначава не живот, придошъл от пространства извън Земята, а по-скоро феномен, наличен на Земята, но със скрит произход. И това, твърди авторът на статията, веднага напомня за света на джиновете. Защото едно от значенията на арабския корен дж-н-н, от който идва думата, е свързано със скриване, укриване, покриване. Честно казано, ако бях мюсюлманин, и аз веднага щях да припозная джиновете като основни виновници за НЛО феномените. Не ми трябват „зелени човечета“. Е, ако може, да не изхвърляме и „небесните добичета“ с неясни атрибути от небесата.

Арабският онлайн инфлуенсър Manetho The Writer посвещава почти четиричасово предаване на „черните пари“ на Пентагона, обсъжданията на НЛО в американската администрация и връзката с възможни срещи с извънземни. Епизодът се нарича „От Конгреса до джамията: мюсюлманското право за извънземните“ и представлява подкаст с различни участници и материали. Има всичко – от протоколи на изтеклите документи от Пентагона и записки на Конгреса в САЩ, през детайлни описания на наблюдавани НЛО, споменаване на Розуел и други подобни събития, та чак до богословски обяснения по някоя от по-горните линии на разсъждение, текстове от Корана и Сунната и пространни разсъждения относно приложимостта на ислямското право относно възможните извънземни.

Докато слушам смесицата от арабски диалекти и книжовен кораничен език, от чисто любопитство се питам друго. Свързано е с визуалното възприятие на извънземните. Клишираният образ на извънземното на Запад е известен – голяма, удължена, яйцевидна глава, големи очи, тънко тяло, високо или ниско, фини крайници, нещо като известните „сиви същества“. Но историческите изображения на джинове в старите мюсюлмански ръкописи нямат нищо общо с това. Обикновено ги изобразяват мускулести, с човешка или животинска глава, често пъти с рога, зъбати, понякога имат крила. Това не са падналите ангели от християнството. В исляма такива няма. Даже архизлодеят на Корана – Иблис, е джин, пише го в Коран 18:50: „И когато рекохме на ангелите: „Сведете чела пред Адам!“, те се поклониха, освен Иблис. Той бе от джиновете…“ Вижте ги например тук в стари ръкописи… Та, чудя се, дали има истории за среща на съвременни мюсюлмани с извънземни, които да пресичат културните граници. Например да ги отвличат не зъбати и крилати джинове, а хуманоиди с яйцевидни глави. Е, да не насилваме историческите и културните особености. Пък и да не забравяме, че ако има „небесни твари“, които са разумни и от време на време избират да се явят на хората, те могат или да приемат различна форма, или съответните култури да ги възприемат според собствените им понятийни условности.

Но докато дослушвам подкаста, един от участниците изплюва камъчето. Колкото и да се спекулира около възможните обязаности на обитателите на Космоса – например как се женят, как извършват ритуално умиване и прочее (покрай всичко зачудвам се и как ли се обрязват), – се стига до признание. Мюсюлманската ритуалност в Свещения закон е изградена около идеята за централна роля на човечеството. Няма мърдане. И Коранът, и Сунната, и мюсюлманското право важат най-вече за него. Тоест продължавам същата нишка на разсъждение. Ако си нарушил „границите на Аллах“ (Коран 4:13) и ти се полага наказание свише, което никой не може да промени – като отрязването на ръката на крадеца, пребиване с камъни за прелюбодейство, камшици за алкохол например, – няма голямо значение дали другите разумни същества във вселените на „Господа на световете“ подлежат на същото. Свещеният закон може да е всеобхватен, но не е безогледен. В него си има приоритети. И извършеното от хора в сферата на човешкото безспорно е един от тях.


В рубриката „Ориент кафе“ Атанас Шиников поднася любопитни теми, свързани не толкова с горещата политика, колкото с историята и културата на Близкия изток. А той, древен и днешен, е по-близко до нас и съвремието ни, отколкото си представяме.

The collective thoughts of the interwebz