I had missed that AWS discussed how they use #eBPF to implement network policies, optimize TCP performance, and reduce Lambda function cold starts.
Recording: https://youtu.be/pVJHljuz1F0
Microsoft breaking a bunch of dual-boot systems by revoking insecure versions of grub during a standard Windows update is, uh, not great and was not supposed to happen, but it's worth mentioning that systems broken by this were running known insecure bootloaders and anyone running a distro that's actually on top of security updates was unaffected
(Edit to add: I wasn't terribly clear here. It's not the user's fault if their distro fails to deal with this, it's the distro's)