LATEST HEADLINES

January 15, 2026
UK cyber plan tackles state threats & ransomware
Cybersecurity experts warn that organisations face a more volatile threat landscape in 2026, as geopolitical tensions drive state-linked attacks and enterprises revisit older storage technologies in response to ransomware.UK lawmakers have introduced the Government Cyber Action Plan, which sets out measures that aim to strengthen cyber defences across vital public services. Security specialists say the move reflects a broader shift in both the nature of cyber threats and the types of defensive tools that enterprises now consider.Vendors and analysts expect cyber warfare, critical infrastructure risk and long-tail ransomware recovery to dominate board agendas through 2026.Geopolitics shiftSecurity leaders describe a growing overlap between traditional cyber crime and state-aligned campaigns. They say this blurs the line between criminal extortion and geopolitical disruption and raises the likelihood that organisations become unintended victims."The introduction of the Government Cyber Action Plan is an acknowledgement that as geopolitical tensions heighten, elevated levels of cybersecurity vigilance are required from every organisation, especially those involved in the delivery of key public services. For example, geopolitics has long been a driver of DDoS attack activity, but threat actors are targeting more intelligently, moving on from targeting government websites directly to hitting supporting service enablers and digital supply chains."A big change we have seen in 2025 is the immediacy of the relationship between real-world tensions and cyber activity. Attacks are now launched to coincide with individual political speeches or specific military operations. Private and public sector organisations can easily become collateral damage in geopolitically motivated attack campaigns."More sophisticated attack tools and the emergence of next-generation 'DDoS-as-a-Service' capabilities have removed barriers to entry to sophisticated attack capabilities, giving threat actors the ability to easily orchestrate complex campaigns. For defenders, this makes real-time intelligence** and adaptive defences more critical than ever," said Darren Anstee, Chief Technology Officer for Security, NETSCOUT.Enterprises that run critical national infrastructure and essential services face heightened scrutiny from regulators. They also face growing exposure to spill-over attacks that target suppliers and online intermediaries rather than government assets directly.DDoS evolutionSecurity professionals report an increase in distributed denial-of-service activity linked to political flashpoints and regional conflicts. Adversaries now combine higher volumes of traffic with more complex techniques that aim to exhaust both network capacity and security controls.Specialists say that so-called DDoS-as-a-service offerings on criminal marketplaces give less skilled actors access to attack tools and rentable botnets. These services automate aspects of reconnaissance and attack orchestration. They also reduce the cost and expertise required to launch disruptive campaigns.Defenders respond by investing in real-time telemetry and automated mitigation tools that adjust to changing attack patterns. They also seek better visibility across their own environments and their external service providers.Supply chain riskThe growing focus on digital supply chains reflects a pattern in which attackers bypass primary targets. They do this by compromising upstream or downstream entities such as managed service providers, hosting platforms or specialist software vendors.Security teams now assess risk beyond their own networks. They review contractual obligations on security controls. They also push for clearer incident reporting and joint response planning with partners.Industry observers say this trend places additional weight on the Government Cyber Action Plan and similar frameworks. These initiatives encourage baseline security practices and information sharing across public and private sectors.Ransomware responseWhile geopolitical campaigns draw attention, ransomware remains a persistent threat to enterprises of all sizes. Breaches that destroy or encrypt backups are prompting some organisations to re-evaluate their storage strategies and recovery processes."Companies are realising they can't do ransomware with a point product. There is no magic wand or silver bullet to deploy against a threat that can come from anywhere. IT teams and their organisations will need a deep defence, including building layers of security and using different protocols, processes, platforms and tech, and this means relying on tape," said Andrew Dodd, HPE Storage Worldwide Marketing Communications Manager, the LTO Programme.Security architects now talk about layered defence models that combine network controls, endpoint protection, identity security and data resilience measures. They separate data storage decisions from threat detection tooling. They also revisit offline or air-gapped backup methods that reduce the risk of simultaneous compromise.Return of tapeTape storage features in many of these discussions. Technology teams argue that offline, removable media reduces the attack surface during a ransomware incident because it is not continuously accessible over the network.Organisations in regulated sectors, such as financial services and healthcare, have used tape for long-term archiving. Some of these enterprises now extend its role into cyber recovery plans. They implement tiered backup architectures with a mix of disk, cloud and tape. They also test restore procedures from each tier.Vendors in the Linear Tape-Open ecosystem report increased interest from customers that experienced ransomware incidents. They say these customers often reassess the balance between rapid restore times and isolation from online threats.Resilience focusThe combination of state-linked attacks, commodity criminal tools and long dwell times inside networks pushes organisations to treat cyber incidents as an operational risk rather than only an IT issue. Boards ask for clearer metrics on recovery times and data loss. They also demand evidence of scenario planning that includes both disruptive DDoS events and destructive malware.Security consultants expect this year to bring more regulatory attention on incident reporting and resilience testing. They say this will affect not only critical infrastructure operators but also suppliers that connect to those environments."More sophisticated attack tools and the emergence of next-generation 'DDoS-as-a-Service' capabilities have removed barriers to entry to sophisticated attack capabilities, giving threat actors the ability to easily orchestrate complex campaigns. For defenders, this makes real-time intelligence** and adaptive defences more critical than ever," said Anstee.
December 03, 2025
The State of Ransomware in Manufacturing and Production 2025 - Sophos News
Sophos’ latest annual study explores the real-world ransomware experiences of 332 manufacturing and production organizations hit by ransomware in the past year. The report examines how the causes and consequences of these attacks have evolved over time.This year’s edition also sheds new light on previously unexplored areas, including the organizational factors that left firms exposed and the human toll ransomware takes on IT and cybersecurity teams within the sector.Download the report to explore the full findings.Exploited vulnerabilities and expertise shortfalls fuel ransomware incidentsExploited vulnerabilities are the leading root cause of ransomware attacks on manufacturing and production organizations, responsible for 32% of incidents. Malicious emails ranked second, with their share declining from 29% in 2024 to 23% in 2025.Multiple organizational factors contribute to manufacturing and production organizations falling victim to ransomware, with the most common being a lack of expertise (i.e., insufficient skills or knowledge available to detect and stop the attack in time) named by 42.5% of victims. It is followed in very close succession by unknown security gaps (i.e., weaknesses in defenses that respondents were unaware of), which contributed to 41.6% of attacks.Organizational root cause of attacks in manufacturing and productionData encryption sharply declines but extortion rates soarData encryption in the sector has dropped to its lowest level in five years, with 40% of attacks resulting in data being encrypted — the third lowest percentage recorded in this year’s survey and close to half the 74% reported by manufacturing and production organizations in 2024. In line with this trend, the percentage of attacks stopped before encryption reached a five-year high, indicating that manufacturing and production organizations are strengthening their defenses.However, adversaries are adapting: The proportion of manufacturing and production organizations hit by extortion-only attacks (where data wasn’t encrypted but a ransom was still demanded) surged to 10% of attacks in 2025 from just 3% in 2024 — the second highest rate reported in this year’s survey. This is likely due to the high value of intellectual property, complex supply chains, and the operational impact of downtime in manufacturing environments.Data encryption in manufacturing and production | 2021 – 2025Ransom payments persist while reliance on backups hold steadyWhile the proportion of manufacturing and production organizations paying the ransom to recover data has declined in the last year, over half (51%) still paid — well above 2022 (33%) and 2023 (34%) levels. Meanwhile, backup use remains steady at 58% in 2025, reflecting strong confidence in this data recovery method.Recovery of encrypted data in manufacturing and production | 2021 – 2025Ransom demands, payments and attack recovery costs fallRansomware economics in manufacturing and production shifted in 2025, with average ransom demands falling 20% to $1.2M (from $1.5M in 2024) and payments dropping from $1.2M to $1.0M. The decline was largely driven by fewer mid-range ($1M–$5M) demands and payouts, while extreme cases ($5M+) saw a slight uptick.At the same time, the mean cost of recovery (excluding any ransoms paid) has dropped nearly a quarter (24%) over the past year to $1.3M, down from $1.7M in 2024 and below the $1.5M global average in this year’s report.Collectively, these findings indicate that the sector is becoming more resilient and efficient in its ransomware response but still faces high-value outliers that skew the overall risk landscape.Ransomware takes a human toll, driving stress and anxiety among IT/cybersecurity teams within the sectorThe survey reveals that ransomware incidents have profound repercussions for IT and cybersecurity teams in the manufacturing and production sector. Nearly half of respondents (47%) reported increased anxiety or stress about future attacks, underscoring the lasting psychological impact of such events.Other common consequences include a shift in team priorities or focus (45%), heightened pressure from senior leadership (44%), and a sustained increase in workload (41%). Notably, the proportion of manufacturing and production respondents reporting these effects was higher than the cross-sector average across nearly all areas, highlighting the exceptional strain faced by teams in this industry. Download the full report for more insights into the human and financial impacts of ransomware on the retail sector.What Sophos is seeing in the manufacturing sectorIn addition to the findings of the report, over the past twelve months, Sophos X-Ops has observed ransomware activity across leak sites and found that 99 distinct threat groups targeted manufacturing organizations. The most prominent groups targeting manufacturing organizations based on leak site observations are GOLD SAHARA (Akira), GOLD FEATHER (Qilin) and GOLD ENCORE (PLAY).  Reflecting the trends in the report, over half of the ransomware incidents handled by Sophos Emergency Incident Response involved both data theft and data encryption, underscoring the continued rise of double extortion tactics where stolen data is held to ransom and threatened with publication on a leak site.About the surveyThe report is based on the findings of an independent, vendor-agnostic survey commissioned by Sophos of 3,400 IT/cybersecurity leaders across 17 countries in the Americas, EMEA, and Asia Pacific, including 332 from the manufacturing and production sector. All respondents represent organizations with between 100 and 5,000 employees. The survey was conducted by research specialist Vanson Bourne between January and March 2025, and participants were asked to respond based on their experiences over the previous year.
November 14, 2025
LTO Program Releases 40 TB LTO Ultrium Cartridge Specs and New High-Density Roadmap
The LTO Program Technology Provider Companies (TPCs), Hewlett Packard Enterprise, International Business Machines Corporation and Quantum Corporation, today announced specifications for a new generation of LTO Ultrium data cartridges with 40 TB native capacity (up to 100 TB compressed, assuming 2.5:1 compression), extending the industry's most widely adopted open tape format for long-term, cyber-resilient, and energy-efficient data preservation. At the same time, the TPCs are optimizing the technology roadmap for future LTO products to better align with customer priorities regarding reliability, affordability and efficiency for managing colossal amounts of data.As organizations generate and retain unprecedented volumes of data to power AI, analytics, data insight, and compliance, the 40 TB LTO-10 cartridge offers enterprises and other large-capacity users superior storage density to efficiently archive greater amounts of information. This leap in capacity is made possible by innovations in the LTO-10 drive head design and a new, highly stable base film material, which together unlock the increased native media capacity of 40 TB. This new 40 TB cartridge is compatible with the same LTO-10 drive organizations are using for the 30 TB cartridge. "AI has turned archives into strategic assets," said Stephen Bacon, Vice President, Data Protection Solutions Product Management, HPE. "The new 40 TB LTO-10 cartridge will help enterprise-class organizations—across healthcare, financial services, media, research, manufacturing, the public sector and beyond—consolidate petabytes efficiently, strengthen cyber resiliency with true offline air-gapping, and keep long-term retention affordable and sustainable."Built for AI-Era Archives and Enterprise Scale The 40 TB LTO-10 cartridge achieves its breakthrough capacity by using an advanced base film technology known as Aramid. Aramid permits the manufacture of significantly thinner and smoother media, enabling longer tape lengths in a standard LTO Ultrium cartridge form factor. This material innovation provides an extra 10 TB of native capacity than the currently available 30 TB LTO-10 cartridge, which is manufactured using different materials.Built for AI-Era Archives and Enterprise ScaleOnce 40 TB LTO-10 cartridges are available, customers will be able to choose between the two different LTO-10 media types based upon their individual cost and capacity requirements, allowing for greater flexibility in media deployment. "Enterprises are moving from ad-hoc retention to intentional 'archive architectures' that serve AI, legal, and sustainability goals," said Jon Brown, Senior Analyst at Omdia. "This new 40 TB LTO-10 capacity point advances that architecture: fewer cartridges, fewer frames, lower energy and a stronger security posture."Roadmap OptimizationIn conjunction with the Aramid announcement, the TPCs are also optimizing the capacity roadmap for future generations of LTO technology, from Generation 11 through Generation 14. This will result in a new outlook for the projected capacities to be delivered in each generation, peaking with a 913 TB cartridge at Generation 14. The revised LTO roadmap is tightly aligned with anticipated storage requirements in the coming years and gives the technology space to grow should users require it. The new capacity points will prioritize reliability and compelling value in terms of cost per terabyte, and ensure everyday LTO Ultrium tape solutions will remain a practical and affordable storage choice for every type of business or workload. Meanwhile, the new maximum capacity of 913 TB for LTO-14 will reduce the time needed to store and recover data, while preserving exabyte-scale growth paths for tape libraries. The roadmap ensures LTO tape technology will remain the most reliable, affordable, and efficient way to archive AI-scale data for the next decade.40 TB Cartridge AvailabilityMedia qualification and interchange testing will begin directly after this announcement, with the expectation that 40 TB products will be available for shipment in the first calendar quarter of 2026. Buyers seeking LTO Ultrium format-compliant products should look for the LTO Ultrium format verification trademarks on both tape drives and data cartridges. Storage and media manufacturers interested in licensing LTO formats may obtain information by contacting the LTO Program at www.lto.org/contact-us/. Organizations can evaluate multi-year Total Cost of Ownership and sustainability impacts using the LTO Ultrium TCO Tool and by consulting their preferred solution providers.
November 15, 2025
Elon Musk tried to bury tape forever, yet LTO just fired back with a 40TB beast for the AI era
LTO’s 40TB cartridge pushes tape storage into the AI-driven futureAramid film gives magnetic tape the strength to expand its lifespanMagnetic tape storage remains the cheapest offline safeguard for critical enterprise dataLong dismissed as outdated technology, magnetic tape storage continues to defy predictions of extinction.The LTO Program, a collaboration between HPE, IBM, and Quantum, has unveiled a new generation of LTO Ultrium cartridges offering 40TB of native capacity.The development coincides with a renewed roadmap stretching to Generation 14, which targets a 913TB capacity milestone.A new approach to tape materialsThe 40TB LTO-10 cartridge’s capacity increase is largely driven by “Aramid,” a new base film material that enables thinner and smoother tape, allowing for longer tape lengths without expanding the cartridge’s size.Combined with refinements to drive head design, the new media achieves an additional 10TB over the 30TB model while remaining compatible with existing LTO-10 drives.“Enterprises are moving from ad-hoc retention to intentional ‘archive architectures’ that serve AI, legal, and sustainability goals,” said Jon Brown, Senior Analyst at Omdia.“This new 40TB LTO-10 capacity point advances that architecture: fewer cartridges, fewer frames, lower energy, and a stronger security posture.”Are you a pro? Subscribe to our newsletterSign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!The upgrade targets enterprises that need to store large datasets over decades, from scientific research to financial records, while keeping power and maintenance costs low.Alongside the 40TB announcement, the Technology Provider Companies have adjusted their roadmap for upcoming LTO generations, spanning from LTO-11 to LTO-14.The roadmap now peaks at an ambitious 913TB per cartridge, aligning with projected increases in storage demand from AI and data-intensive applications.“AI has turned archives into strategic assets,” said Stephen Bacon, Vice President, Data Protection Solutions Product Management, HPE.“The new 40TB LTO-10 cartridge will help enterprise-class organisations—across healthcare, financial services, media, research, manufacturing, the public sector and beyond—consolidate petabytes efficiently, strengthen cyber resiliency with true offline air-gapping, and keep long-term retention affordable and sustainable.”By prioritizing cost per terabyte, reliability, and long-term scalability, the revised plan aims to keep tape competitive in a landscape increasingly dominated by solid-state performance.The roadmap also accounts for faster storage and retrieval processes, supporting exabyte-scale infrastructure growth across industries.Testing for the new 40TB cartridges will begin shortly, with availability expected in early 2026.Despite Elon Musk’s public dismissal of older storage formats, tape continues to serve a specific function that neither flash drives nor SSD systems can replace.Its offline nature provides a defence against cyberattacks and data loss from hardware failure.This new roadmap suggests that tape will not only survive the AI era but continue adapting to it.Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
November 15, 2025
LTO Program Unveils LTO-10 40TB Ultrium Cartridge, Updates Roadmap Toward 913TB ...
LTO Program Unveils LTO-10 40TB Ultrium Cartridge, Updates Roadmap Toward 913TB Archival Tapeby Lyle Smithon November 15, 2025Hewlett Packard Enterprise, IBM, and Quantum, collectively known as the LTO Technology Provider Companies, have officially announced the specifications for a new LTO-10 data cartridge featuring 40TB of native storage capacity. This update to the LTO Ultrium format delivers a substantial capacity increase and a retooled technology roadmap that aligns with current trends in AI-driven data use, long-term archiving needs, and sustainability concerns.LTO-10 Data CartridgeThe new LTO-10 media can store up to 100TB of compressed data at a 2.5:1 compression ratio, making it particularly useful for enterprises handling massive volumes of information. As organizations increasingly rely on data for AI model training, analytics, compliance, and long-term preservation, demand for higher-density, offline air‑gapping continues to grow. The 40TB capacity represents a 33% increase over the existing 30TB LTO-10 cartridges, which will continue to be available and coexist with the new model.The capacity boost is the result of engineering refinements to both the drive head and the tape material. Central to this upgrade is the use of an Aramid-based base film, a shift from the composition used in the earlier version. This material enables thinner, smoother tape, allowing longer tape to be housed in a standard cartridge shell. Importantly, no new drive is needed. The 40TB cartridges are compatible with existing LTO-10 drives, offering users an immediate upgrade path without requiring hardware replacement.LTO Program Roadmap UpdatedIn parallel with the 40 TB announcement, the LTO Program has adjusted its roadmap for future generations of the Ultrium format. Generations 11 through 14 will feature revised capacity targets, with the final milestone now set at 913 TB for LTO-14.These new goals reflect projected storage needs across industries and are designed to deliver better long-term value at a lower cost per TB. The roadmap also keeps future development aligned with reliability expectations and the growing need for scalable solutions.At the same time, the offline nature of LTO tape remains a strong option for organizations seeking to enhance their resilience against cyber threats.AvailabilityThe 40 TB LTO-10 cartridge is expected to be available in the first quarter of 2026. Qualification and interchange testing will begin immediately. Buyers are encouraged to look for LTO Ultrium verification marks on both drives and cartridges to ensure format compliance. Organizations evaluating whether this new media fits into their long-term planning can use the LTO TCO tool or work with their preferred solution providers to assess cost and environmental impact.LTO UltriumLyle SmithLyle is a long-time staff writer for StorageReview, covering a broad set of end user and enterprise IT topics.
November 17, 2025
Why LTO Tape Storage Thrives in the AI Era Despite Tech Titans' Push - Ian Khan
Opening: The Unlikely Resilience of Legacy StorageIn an age dominated by flashy cloud solutions and AI-driven innovations, it’s easy to dismiss technologies like Linear Tape-Open (LTO) storage as relics of the past. Yet, as Elon Musk’s ventures, such as Tesla and SpaceX, push for all-digital, tape-free environments, LTO tape storage isn’t just surviving—it’s thriving. Why does this matter now? With data volumes exploding due to AI, IoT, and regulatory demands, businesses face a critical juncture: balancing cost, security, and sustainability in their data strategies. This isn’t about nostalgia; it’s about future readiness in a world where data is both an asset and a liability.Current State: LTO’s Steady Climb in a Digital WorldDespite predictions of its demise, LTO tape storage continues to see robust enterprise adoption. Recent developments, like the LTO-9 specification offering up to 45 TB of compressed capacity per cartridge, highlight its evolution. Companies in sectors like healthcare, finance, and media rely on LTO for long-term archiving, with the Global LTO Tape Storage Market projected to grow at a CAGR of around 7% through 2028, according to industry reports. For instance, major cloud providers, including AWS and Google, integrate tape into their cold storage tiers, recognizing its cost-effectiveness for infrequently accessed data. Meanwhile, Elon Musk’s efforts to eliminate tape—such as Tesla’s push for fully digital manufacturing records—underscore a broader trend toward real-time, high-performance storage. However, this hasn’t wiped out LTO; instead, it has clarified its niche: where low cost, high durability, and energy efficiency trump speed.Key Drivers and ChallengesThe persistence of LTO stems from tangible benefits. Cost efficiency is paramount—tape storage can be up to 80% cheaper per terabyte than disk or cloud alternatives for archival purposes. Security is another forte; with air-gapping capabilities, LTO tapes are immune to cyberattacks like ransomware, a growing concern as data breaches cost businesses an average of $4.45 million globally in 2023. Sustainability adds to its appeal, as tapes consume minimal power when not in use, aligning with corporate ESG goals. Yet, challenges abound. Implementation hurdles include slower access times, which can delay data retrieval in urgent scenarios, and the need for specialized hardware and expertise. Moreover, the perception of tape as outdated can deter innovation-focused leaders, risking missed opportunities in hybrid storage models.Analysis: Implications for Business and TechnologyThe endurance of LTO tape storage reveals deeper implications for digital transformation. On one hand, it highlights the fallacy of a one-size-fits-all approach to data management. As AI and big data analytics demand vast historical datasets, LTO provides a scalable, low-cost repository that complements high-performance systems. This duality fosters a hybrid storage ecosystem, where hot data resides on flash or cloud for instant access, while cold data rests securely on tape. Opportunities include enhanced data governance—for example, in regulated industries like finance, where compliance requires decades-long retention. However, the reliance on tape also poses risks, such as vendor lock-in with proprietary formats or skills gaps in maintaining tape libraries. From a broader trend perspective, this mirrors the rise of edge computing, where distributed data storage solutions gain prominence over centralized models. The key takeaway: businesses must evaluate storage not just on technological prowess but on total cost of ownership, risk mitigation, and alignment with long-term strategies.Ian’s Perspective: Why Tape Isn’t Going Anywhere SoonAs a technology futurist, I see LTO tape storage as a testament to the principle of “right tool for the job.” Elon Musk’s vision of a tape-free world is admirable for its innovation drive, but it overlooks the pragmatic realities of enterprise economics. My analysis suggests that tape’s resilience isn’t a failure of progress but a smart adaptation. In an era of AI-generated data deluge, the cost of storing every byte in high-performance systems is unsustainable. Predictions? I foresee LTO evolving with smarter integrations, such as AI-driven indexing for faster retrievals, and partnerships with blockchain for immutable audit trails. However, businesses that ignore tape’s strengths risk bloated IT budgets and vulnerabilities in their data lifecycle. The future isn’t about choosing between old and new; it’s about orchestrating a symphony of technologies that ensure readiness for whatever comes next.Future Outlook: Short-Term Gains and Long-Term ShiftsIn the next 1-3 years, expect LTO to solidify its role in cold data management, with advancements in capacity and automation reducing manual interventions. Hybrid cloud-tape solutions will become mainstream, driven by cost pressures and data sovereignty laws. By 5-10 years, quantum storage and DNA-based alternatives might emerge, but LTO could adapt through enhanced durability and eco-friendly materials, potentially capturing niche markets in space exploration or deep archives. The key trend will be interoperability—tape systems that seamlessly integrate with AI platforms for predictive analytics. Nonetheless, if innovation stalls, LTO could face decline in favor of more agile, software-defined storage. For leaders, this means staying agile: investing in tape where it makes sense, but remaining open to disruptive technologies that could redefine storage paradigms.Takeaways: Actionable Insights for Business LeadersAssess Your Data Lifecycle: Conduct a thorough audit to identify cold data suitable for LTO, balancing access needs with cost savings. This can reduce storage expenses by up to 60% in archival scenarios.Embrace Hybrid Models: Integrate LTO with cloud and on-premise systems for a resilient data strategy. For example, use tape for compliance archives and cloud for active analytics, ensuring both security and agility.Invest in Skills and Security: Train teams in tape management and leverage its air-gapped nature to fortify against cyber threats. In a ransomware-prone world, this could be your data’s insurance policy.Monitor Innovation Trends: Keep an eye on advancements in LTO and alternatives; pilot new integrations like AI-enhanced tape libraries to future-proof your investments.Prioritize Sustainability: Leverage LTO’s low energy footprint to support ESG goals, potentially cutting carbon emissions associated with data centers.Ian Khan is a globally recognized technology futurist, voted Top 25 Futurist and a Thinkers50 Future Readiness Award Finalist. He specializes in AI, digital transformation, and Future Readiness™, helping organizations navigate technological shifts.For more information on Ian’s specialties, The Future Readiness Score, media work, and bookings please visit www.IanKhan.comIan KhanThe FuturistIan Khan is a Theoretical Futurist and researcher specializing in emerging technologies. His new book Undisrupted will help you learn more about the next decade of technology development and how to be part of it to gain personal and professional advantage. Pre-Order a copy https://amzn.to/4g5gjH9
November 19, 2025
Tape keeps kicking, 'breakthrough' 40TB native spec announced - LTO-10 tapes claim up to 100TB compressed data capacity, hold 2.2X more data than previous spec
There’s a revamped, more capacious magnetic tape format in town. The Linear Tape-Open (LTO) Ultrium Format companies, composed of industry leaders HPE, IBM Corporation, and Quantum Corporation, announced the LTO-10 40TB cartridge standard a few hours ago. In an email to Tom’s Hardware, the organization heralded the new tape cart’s 40TB native capacity, which they say can deliver up to 100TB, compressed, assuming a 2.5:1 compression ratio.(Image credit: The Linear Tape-Open (LTO) Ultrium Format companies)According to the LTO, its “breakthrough” new format was driven by “data preservation demands as data collection skyrockets in today’s AI era.” Even tape makers are now talking about artificial intelligence. Indeed, a 2.2X increase in native tape storage capacity over LTO-9, and a 33% increase vs LTO-10 30TB native carts, is a significant increase. Moreover, the LTO Program insists that its tapes remain as reliable, affordable, and efficient as ever.Two major innovationsTwo major innovations were behind the native capacity increases available with LTO-10. Firstly, a new head design is claimed to facilitate reliable reads/writes at the significantly increased density. Secondly, the new advanced base film technology, dubbed Aramid, is said to “permit the manufacture of significantly thinner and smoother media.”Specifically, Aramid is behind the 10TB native capacity uplift seen between LTO-10 30TB and 40TB cartridges. The thinner, more stable Aramid basically allows longer lengths of tape to be used in the same cartridge form factor.As this is merely a change to the magnetic media in the carts, the LTO Program says customers currently using LTO-10 30TB media will be able to pick and choose between the two media types, according to their cost and capacity requirements. However, the larger capacity benefits are clear, delivering “fewer cartridges, fewer frames, lower energy and a stronger security posture,” notes an analyst quoted in the official press release.(Image credit: The Linear Tape-Open (LTO) Ultrium Format companies)Tape lives on, and has an ambitious 913TB cart capacity roadmapWe commented on this in 2024, and it is probably worth repeating: Tape shipments are on the up, even though it just seems so archaic, and there are some notable (more glamorous) challengers intending to eat its lunch.In its latest press release, announcing LTO-10 40TB, the LTO Program reiterated its outlook, mentioning tapes with a maximum capacity of 913TB (LTO-14). It is expected to be another seven years before LTO-14 is a thing. But, in the meantime, LTO-10 40TB cartridges are scheduled to ship in Q1 2026.Stay On the Cutting Edge: Get the Tom's Hardware NewsletterGet Tom's Hardware's best news and in-depth reviews, straight to your inbox.Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.
October 20, 2025
If You Can Hold On To It • Disaster Recovery Journal
"yes"Turning Existing Infrastructure into a Future-Ready StrategyOver the past five years, artificial intelligence (AI) and the promise of new data insight pipelines have been the most exciting drivers of digital transformation, reshaping the way organizations operate and innovate as they think about how to use the new technology. However, as AI accelerates and amplifies business capabilities, it also drives unprecedented data usage needs. Current estimates suggest around 403 terabytes of data are generated globally every single day, with the annual projection soaring to 181 zettabytes in 2025. This volume alone is staggering, but it’s not the only shift reshaping how enterprises think about storage.The lifespan of data is evolving, too. In the past, businesses stored information for as long as regulations or internal policies required, then commonly discarded it to save money and free up infrastructure. Now, in an AI-powered world, the game has changed. Proprietary data has emerged as one of the most valuable assets for enterprises—and increasingly, the expectation is that data must be stored indefinitely, ready to fuel future models, insights, and innovations as the technology continues to evolve. There are, of course, concerns about this level of storage, ranging from cost to cyber threats, and it seems the rules are shifting alongside the evolution of AI.AI’s New Rules for DataAI’s insatiable appetite for data explains this shift in the general mindset of data preservation. Large language models (LLMs) and machine learning (ML) systems don’t just rely on a steady influx of new data—they thrive when organizations have deep historical datasets to train on, and to continue to refer back to with each new incarnation or model. That means the value of data extends beyond today’s use cases. What may not be useful now could prove indispensable for model training, methods, benchmarking, or compliance tomorrow.This reality represents a brave new world of storage. Before the AI boom, the guiding principle was efficiency: keep what you must, discard what you can, and keep costs low. Now, that strategy risks leaving organizations unprepared for the next wave of innovation, introducing a tricky balancing act that’s new to the world of enterprise data.Enterprises becoming thoroughly digitized have resulted in a lot of strides being made more quickly than ever before, but this level of digitization also introduces hazards. In addition to skyrocketing volumes and extended storage timelines, cybercriminals have also adapted, enabling even novice coders to utilize AI-powered tools to launch waves of increasingly sophisticated attacks. Organizations find themselves facing a formidable equation: More data than ever before, stored longer than ever before, and exposed to more cyberattacks than ever before.Meeting this challenge requires more than simply spending money on new solutions. It calls for rethinking storage strategies to balance cost, security, and accessibility while keeping every scrap of data for the long term.Turning Existing Infrastructure into a Future-Ready StrategyFor many organizations, the instinct might be to chase the “next big thing” in storage, which, while flashy, is impractical and costly. The reality is that most enterprises already have the building blocks for a strong, future-ready system, and are trying to apply a single storage technology across an entire data lifecycle, leaving critical hardware or cost advantages behind. The key lies in tailoring those resources into a hybrid storage strategy which can address today’s demands for the ideal mix of performance, scale, economics, and, especially, intrinsic technology advantage, while remaining adaptable for tomorrow’s needs.Consider tape storage, for instance. Most organizations are either familiar with tape, or already have it implemented. As technologies evolve, tape does as well – tape remains one of the most reliable and cost-effective ways to store large amounts of data for long periods of time. In fact, when combined with other storage options such as object storage, tape can play a critical role in creating a holistic solution.Take exponential data growth, for example. Theoretically, enterprises could choose to store their mountains of new information, as well as all their archives and backups of critical systems and data stores, entirely in the cloud. However, doing so would come with astronomical costs, especially when factoring in networking speed limitations or even egress fees paid to retrieve colder cloud storage tiers in a hurry. So, while the “someone else’s infrastructure” appeal of cloud storage is often tapped for short-lived data needs, it’s usually far too expensive to serve as the warehouse for everything.That’s where tape can really shine. Data that must be preserved but isn’t immediately needed in the hot performance tier can be shifted to tape systems, reducing cloud costs and freeing up network space without sacrificing the ability to retrieve it whenever needed. Tape effectively becomes the long-term memory of the enterprise, while cloud object storage functions as the short-term working brain.Tape’s cybersecurity capability adds another layer of advantage. Storing all data on a cloud platform or on-premises server connected to the network exposes it to the ever-present threat of ransomware, data breaches, or insider misuse. The more data you have, the more enticing a target you become to the ever-present cyber threat actors. Data sets, archives, and backups stored on tape, however, can provide air-gapped and even fully offline advantage options that place critical data literally “out of reach” of online attacks, offering a crucial layer of protection in an era where digital adversaries are more numerous than ever.Of course, no solution is perfect on its own – that’s why a hybrid approach blending the best technology at each workflow step is the key to building the ideal workflow. By blending cloud, on-premises, and tape storage into a cohesive strategy, enterprises can strike a balance between cost, security, and accessibility. The hybrid model ensures organizations can move quickly when needed, keep data secure, and scale sustainably as data volumes continue to grow.Preserving Data Today Secures Tomorrow’s AdvantageGlobally, data architects, managers, and protectors are in uncharted territory. The arrival of generative AI has proven just how unpredictable and fast-moving technological leaps can be – and if there’s one thing the past few years have taught us, it’s that we can’t know what comes next.The only way to prepare is to ensure proprietary data is not just stored but preserved indefinitely. Tomorrow’s breakthroughs – whether in AI, analytics, or some other yet-unimagined technology – will depend on the depth and quality of the data you have today, and how well you can utilize the storage technologies of your choice to serve your data usage and workflow needs. Organizations that hold onto their data have already gained an edge in training proprietary models. The best of these organizations are actively using every technology choice at their disposal to ensure their data is not only protected, but in a cost-effective manner. Those that didn’t are playing catch-up, often at great cost.The lesson is clear: don’t get left behind, because your competitors are learning these lessons as well. The enterprises that thrive in this next era of digital innovation will be those that recognize the enduring value of their data. That means keeping it all and planning to keep it forever. By embracing hybrid storage strategies that combine the strengths of tape, cloud, and on-premises systems, organizations can rise to the challenge of exponential growth, protect themselves from evolving threats, and ensure they are ready for whatever comes next.In the age of AI, your competitive advantage won’t just come from your technology stack. It will come from the data you’ve preserved, ready to pull into new, agile data insight workflows as your team grows. When the next big shift arrives, the organizations with the foresight to keep everything will be the ones leading the way.ABOUT THE AUTHORSkip LevensSkip Levens is a product leader and AI strategist at Quantum, a leader in solutions for AI and unstructured data. He is currently responsible for driving engagement, awareness and growth for Quantum's end-to-end solutions. Throughout his career – which has included stops at organizations like Apple, Backblaze, Symply and Active Storage – he has successfully led marketing and business development, evangelism, launched new products, built relationships with key stakeholders and driven revenue growth.
September 29, 2025
Attackers Use AI to Build Ransomware at Rapid Scale - GovInfoSecurity
AI-Based Attacks,Fraud Management & Cybercrime,Identity & Access ManagementAttackers Use AI to Build Ransomware at Rapid ScaleZeki Turedi of CrowdStrike Discusses Enterprising Adversaries' AI TacticsAnna Delaney (annamadeline) •September 29, 2025     Zeki Turedi, field CTO, CrowdStrikeAdversaries are using artificial intelligence to develop ransomware and malware at rapid scale, with voice-based social engineering schemes increasing to more than 400% and cloud intrusions rising by 136%. Criminal groups have transformed the way they operate with more sophisticated attacks targeting organizations worldwide, said Zeki Turedi, field CTO for Europe at CrowdStrike.See Also: Preparing for the Next Attack"On one spectrum, we're seeing artificial intelligence, large language models, being used for things like developing phishing emails. I'm sure a lot of organizations are using themselves to build their own emails for their own talk to their customers - the adversaries do the exact same thing," Turedi said. "On the more extreme side of things, we're seeing adversaries who use AI to help them, enable them to build ransomware, malware, technical payloads on a rapid scale as well."In this video interview with Information Security Media Group at Gartner Security & Risk Management Summit London, Turedi also discussed:Why vishing attacks succeed through persistent research and sophisticated impersonation tactics;How identity security gaps enable stealthy nation-state groups to operate undetected for extended periods;The critical need to wrap security around AI investments to avoid repeating cloud security mistakes.Turedi has more than a decade of cybersecurity experience. He guides European enterprise and government clients on threat detection and incident response strategy, and previously built forensics teams across EMEA and Asia for global law enforcement and commercial sectors.
September 29, 2025
25 Recent Cyber Attacks That Serve as a Wake-Up Call for Businesses - Security Boulevard
1. National Defense Corporation (NDC) Ransomware AttackIn March 2025, NDC and its subsidiary AMTEC were targeted by the Interlock Ransomware Group, resulting in the theft of approximately 4.2 TB of sensitive data. While classified materials were not confirmed as exposed, procurement and logistics information were compromised, demonstrating that even defense contractors are vulnerable to cyber threats.2. Microsoft Zero-Day Exploit (CLFS / Storm-2460)In April 2025, a zero-day vulnerability in Windows Common Log File System (CLFS), identified as CVE-2025-29824, was exploited by the Storm-2460 group using malware dubbed “PipeMagic.” This exploit allowed attackers to escalate privileges and deploy ransomware across various sectors, highlighting the risks associated with unpatched system vulnerabilities.3. WestJet CyberattackIn June 2025, Canadian airline WestJet experienced a cybersecurity incident that disrupted its website and mobile app. Operations largely continued, but internal systems were compromised. The incident is believed to have been caused by social engineering tactics, emphasizing the need for robust defenses against such attacks.4. Bybit Cryptocurrency Exchange HeistIn February 2025, over $1.46 billion in Ethereum was stolen from Bybit’s cold wallets, attributed to North Korea’s Lazarus group. This incident underscores the importance of securing cryptocurrency infrastructure against sophisticated cyber threats.5. St. Paul, Minnesota Municipal CyberattackA cyberattack disrupted city services in St. Paul, Minnesota, affecting online payments, internal networks, and public WiFi. The attack was significant enough to warrant a state of emergency, highlighting the vulnerability of municipal systems to cyber threats.6. Jaguar Land Rover (JLR) Supply Chain DisruptionIn late August to September 2025, a cyberattack forced JLR to halt production in multiple plants outside China for weeks, affecting thousands of suppliers. This incident demonstrates how attacks on one company can have cascading effects across the supply chain.7. Collins Aerospace / MUSE Software AttackOn September 19, 2025, an attack on the MUSE check-in/boarding software used by airports caused widespread flight delays and cancellations across Europe. This incident illustrates how vulnerabilities in third-party software can disrupt critical infrastructure.8. Allianz Life Data BreachAllianz Life experienced a breach impacting approximately 1.1 million U.S. customers, exposing names, addresses, phone numbers, and emails. While financial data was not compromised, the breach underscores the importance of safeguarding personal information.9. New York Blood Center (NYBC) Data BreachNearly 194,000 individuals’ data were exposed, including names, Social Security numbers, driver’s licenses, bank information, and medical test results. This breach highlights the critical need for securing health and identity data.10. Bank Sepah BreachIn March 2025, hacker group Codebreakers claimed to have infiltrated Bank Sepah, extracting over 12 TB of data belonging to more than 42 million individuals, including military personnel information and account numbers. The bank initially denied the breach, but the claim raised significant concerns about the security of financial institutions.11. Supply Chain Breach at a Major RetailerRecent breaches arise from weak links in vendors or software supply chains. Attackers often bypass the main target by compromising a trusted third party.12. Zero-Day Exploits Against Enterprise PlatformsMany 2024–2025 attacks used previously undocumented vulnerabilities (zero days) in widely used enterprise software, enabling stealthy access before patches are issued.13. Ransomware on Healthcare ProviderSeveral hospital systems and health networks faced ransomware attacks, crippling operations and demanding payment for data recovery. These reinforce that healthcare remains a prime target.14. Phishing / Credential Stuffing Leading to ExfiltrationA recurring motif in analysis: attackers steal or guess credentials and move laterally in corporate networks, exfiltrating data quietly before detection.15. Attack on Financial Services FirmFinancial institutions continue to be targeted for customer data, trading data, or proprietary models. Recent cases show threat actors probing APIs, internal tools, or cloud misconfigurations.16. Intrusion of a TelecomA telecom operator was breached, exposing customer account data and network logs. This kind of attack hits many downstream users.17. Attack on a GovernmentMunicipal systems (e.g. payment portals, utility management) are under attack. The 2025 St. Paul, MN case is one example.18. Critical Infrastructure / Utility Disruption AttackAttackers are increasingly seeking to impact energy grids, water treatment, or transport systems, aiming for disruption more than just data theft.19. Cloud Misconfiguration Leading to Open Buckets / Data ExposureA common vector in cloud storage was left open or misconfigured, exposing large troves of documents, logs, and secrets.20. Third-Party Analytics / Marketing Platform BreachAttackers compromised a marketing analytics vendor, then used that access to reach customer databases in many downstream client firms.21. Board / Executive Targeting via Spear PhishingIn some 2025 cases, top executives were targeted via highly tailored phishing or voice deepfake attacks, giving attackers privileged access.22. LogisticsA global shipping or logistics firm was hit by ransomware, halting deliveries and operations across multiple countries.23. Software Vendor (SaaS) Internal CompromiseA SaaS provider’s internal development or admin system was breached, giving attackers access to customer instances or data.24. Large-Scale Credential LeaksMassive dumps of usernames, emails, hashed passwords have been pushed publicly, often gleaned from aggregated past breaches, then reused in replay attacks.25. Attack On a Major MediaMedia houses have been breached, leading to leaks of editorial, subscriber, or internal email data.
September 30, 2025
Why burnout is a growing problem in cybersecurity - BBC News
Why burnout is a growing problem in cybersecurityImage source, Getty ImagesImage caption, UK retailers have been severely disrupted by cyber attacks this yearAuthor, Joe FayRole, Technology Reporter2 hours agoWhen Tony was signed off for burnout from his cybersecurity awareness role at a major UK ecommerce company last year, it had been a long time coming."Many of us in cyber, we put our hearts into our job. There's a lot of passion involved."He had found it progressively harder to sleep, and to go into the office.The security team got on a call that evening and the decision was taken to remove every single device from the network."And it was Sunday afternoon that I came offline," he says.The firm hadn't been hit by the bug, he says. "It was all preparatory work."Tony said this pattern is currently being repeated across organizations trying to protect themselves against the Scattered Spider attacks that hit retailers and other businesses this year.And, he says, "I can't even imagine what the folks at Co-op and M&S have gone through."Image source, Andrew TillmanImage caption, Cyber security can be "the best job in the world" says Andrew Tillman"If you think you might be burning out, you're already on your way there," says Andrew Tillman, former head of cyber risk and assurance for the UK's Health Security Agency.He says cyber security can, at times, be "the best job in the world". But when things get bad "it can be a bit of a dangerous place to be".Mr Tillman has suffered bouts of "burnout" himself through his four years at the agency.That stress is revealing itself in data collected by ISC2, the membership organisation for cybersecurity professionals.Its annual Workforce Study showed a 66% favourable job satisfaction rate in 2024, down four percentage points from the previous year.Burnout is a "major issue" for the sector, ISC2's chief information security officer Jon France says.He says professionals in the industry are increasingly being asked "to do more with less" which only increases stress and job dissatisfaction."Cyber professionals rarely work nine to five", he adds, "Even if they do, they remain on call because threat actors don't adhere to office hours."Part of the issue is that hackers have become more aggressive, prepared to target critical national infrastructure, or cripple health organizations with ransomware.Also, hackers backed by nation states are also accounting for more attacks, whether to carry out espionage, steal IP, spread misinformation, or cause disruption, or even seek financial gain on their own account.Earlier this year hackers, thought to be working for the North Korean regime, stole $1.5bn (£1.1bn) worth of digital tokens from crypto exchange ByBit.Image source, Getty ImagesImage caption, Crypto exchange ByBit lost $1.5bn of digital tokens in a hack this yearAs private and public sector organizations have digitized more of their operations, the ramifications of a cyber attack or data breach are more severe.Mr Tillman says: "There's always that conscious thought about 'if it goes wrong, how could this impact the individuals on the street? How could it affect their jobs, their livelihoods?'."Staff turnover is particularly pronounced in entry level roles, says Lisa Ackerman, former deputy chief information security officer (CISO) at GSK, and CISO Council strategic lead at Cybermindz, a non-profit targeting burnout in cyber security.Constant alerts from warning systems might compound the problem, presenting professionals with a barrage of data they have to make sense of.This could be a particular issue for the younger professionals in frontline roles and security operations centres.But non-frontline roles are not immune, says Mr Tillman.Managing risk and ensuring organisations meet compliance and regulatory obligations can be a challenge when other teams are desperate to get new applications or services live without considering all the security angles.Image caption, Lisa Ackerman says burnout is particularly common in entry level rolesCybermindz founder Peter Coroneos says cybersecurity workers can be caught in a "blame culture" where their successes are "low visibility".This leaves them carrying "a low level of dread", he explains.For younger workers this can be damaging, as the human brain is still developing well into the 20s, Mr Coroneos says."So, if you are recruiting people whose brains are not fully formed and putting them in high-stress roles, then you are potentially setting them up for long-term problems in terms of their own cognitive and emotional wellbeing."Cybermindz offers a "structured neural training regime" which aims to get subjects back to a sense of psychological safety."If someone's having a panic attack, telling them to just calm down isn't actually going to work. You need to address neurochemistry," says Mr Coroneos. Ultimately, says Mrs Ackerman, "We want to get to some kind of legislation for cyber teams like we have for air traffic controllers and doctors and pilots and people who are first responders. Which, in reality, cyber defenders are."In the meantime, it's down to organizations and workers to watch out for the signs of stress before they turn into something more ominous.Mr Tillman says he is now far more aware of the warning signs of impending burnout, which for him include changing sleep patterns or eating habits, taking less exercise or not walking the dog."It's almost like a cyber breach," he explains. "You should assume it's on its way and work towards not allowing it to happen."
September 30, 2025
BBC reveals conversation of its Insider Threat with Medusa Ransomware gang
The Medusa Ransomware group, a notorious malware-as-a-service organization, appears to have made a significant blunder by attempting to manipulate an employee from the BBC into divulging login credentials. In a bizarre turn of events, the group offered the employee a 15% cut of the ransom demand, but only if paid in Bitcoin cryptocurrency, in exchange for insider access to the BBC’s network. This seemingly well-laid plan has backfired, revealing much more than the hackers likely intended.The hacker behind this misstep, who goes by the alias Syndicate, is reportedly the only English speaker in the entire Medusa Ransomware gang. Medusa, notorious for targeting global organizations, thrives on exploiting insider threats—individuals with legitimate access to internal networks, but with malicious intent. Syndicate aka SYN who appeared to believe they were orchestrating a seamless con, reached out to the BBC employee with an offer to reduce the ransom demand if the insider would provide access credentials.The Inside Threat: Fake Credentials and a Slip-UpIn an unexpected turn of events, the BBC employee, likely acting with permission from senior staff, engaged in the conversation and agreed to share fake login credentials with the hacker. What followed was a revealing exchange. After providing false information, the employee turned the tables by asking Syn how successful their hacking operations had been to date.Syndicate’s response was both alarming and revealing. In an unguarded moment, the hacker disclosed details of recent successful attacks, including one on a Brazilian IT company. The breach had resulted in the extraction of approximately $100 million from the victimized business, and Medusa had pocketed a $15,000 payment for the individual who facilitated the attack.Syn also admitted that earlier this year, Medusa had carried out similar attacks on a UK-based healthcare provider and a U.S. emergency services organization, highlighting the group’s international reach and ability to penetrate critical industries.Medusa’s Motivation: Exploiting Insiders for ProfitThis interaction starkly illuminates the core of Medusa Ransomware’s modus operandi: exploiting insiders for financial gain. The group’s business model revolves around luring individuals within organizations—whether through coercion or bribery—to facilitate their entry into highly sensitive systems. By offering a share of the ransom demands, they effectively turn trusted employees into unwitting (or willing) accomplices. The fact that the hackers disclosed their methods openly further underscores their confidence in their tactics and their ability to evade detection.Medusa, along with other cybercriminal syndicates, is increasingly turning to this approach, which allows them to bypass traditional cybersecurity defenses by targeting the people within an organization, rather than the technology alone. These attacks not only cause direct financial damage but can lead to significant reputational harm for organizations in sectors like healthcare, emergency services, and IT.Medusa’s Alleged Allegiances: A Pro-Russian GangAccording to a report compiled by CheckPoint, Medusa is believed to have ties to pro-Russian criminal groups. Notably, Medusa avoids targeting organizations based in Russia or its allied nations, such as the Commonwealth of Independent States (CIS). This selective targeting hints at geopolitical motivations behind their activities, with an apparent attempt to avoid triggering the wrath of the Russian state or its law enforcement agencies.Best Practices for Organizations: Safeguarding Against Insider ThreatsThis incident highlights the importance of a robust cybersecurity strategy, particularly in the face of increasingly sophisticated attacks that leverage insider threats. Organizations—whether large or small—must be vigilant when it comes to managing network access. Access should be granted only to those with a legitimate need, and such accounts should be limited to privileged users only.Furthermore, organizations should automate their monitoring processes to track logins and identify suspicious behavior quickly. This includes setting up systems to flag unusual access patterns or actions that could indicate insider malfeasance. In cases where suspicious activity is detected, quick and decisive action should be taken to block access and initiate an investigation.Ultimately, the Medusa Ransomware case serves as a stark reminder of the vulnerabilities inherent in insider access, and underscores the importance of proactive security measures to prevent cybercriminals from exploiting these weaknesses. Join our LinkedIn group Information Security Community!

NewsBytes Archive