Connect with us

Technology

Netskope Threat Labs: Phishing Clicks Nearly Tripled in 2024, Ubiquitous Use of Personal Cloud Apps and GenAI Tools Require Modern Workplace Security to Mitigate Risk

Published

on

New research details rising enterprise cloud security risks, successful strategies adopted to manage genAI risks in 2024

SANTA CLARA, Calif., Jan. 7, 2025 /PRNewswire/ — Netskope, a global leader in Secure Access Service Edge (SASE), today shared new research showing that, as a result of the growing prevalence and sophistication of phishing attacks, enterprise employees click on phishing lures nearly three times more in 2024 compared to the prior year. The findings, based on data gathered by Netskope from enterprises worldwide, and published as part of Netskope’s annual Cloud & Threat Report, reveal growing security risks related to the persistent use of personal cloud apps and continued adoption of genAI tools in the workplace, underscoring the need to adopt modern data security to proactively manage that risk.

Phishing lures triple in success rate

Despite organizations’ repeated attempts at security awareness training, with a particular emphasis on how employees can avoid being phished, in 2024 enterprise users clicked on phishing lures at a rate nearly three times higher than in 2023. More than eight out of every 1,000 users clicked on a phishing link each month – up 190% from last year when fewer than three per thousand enterprise users fell prey to phishing attempts.

Where attackers host their malicious payloads is also an element of social engineering. Attackers want to host malicious content on platforms where victims place some implicit trust, including popular cloud apps such as GitHub, Microsoft OneDrive, and Google Drive. In 2024, downloads of malicious content from popular cloud apps occurred in 88% of organizations at least once per month.

The top target for phishing campaigns that users clicked on in 2024 were cloud applications, representing more than a quarter of all phishing clicks at 27%. Among the cloud apps, Microsoft was by far the most targeted brand at a rate of 42% where attackers targeted Microsoft Live and Microsoft 365 credentials.

Personal apps blurring the lines

The ubiquity of personal cloud apps in the enterprise has created an environment where employees are knowingly or unknowingly using these apps to process or store sensitive information, leading to loss of organizational control over data and potential data breaches. Among the top personal apps that users send data to are cloud storage, webmail, genAI, social media, and personal calendar apps.

In 2024, 88% of all employees used personal cloud apps each month, with more than one out of every four users (26%) uploading, posting, or otherwise sending data to personal apps. Sensitive data being leaked through personal apps is top of mind for most organizations, with the most common type of data policy violation being for regulated data (60%), which included personal, financial, or healthcare data being uploaded to personal apps. The other types of data involved in policy violations include intellectual property (16%), source code (13%), passwords and keys (11%), and encrypted data (1%).

GenAI growth trends continue

In 2023, genAI came roaring into the workplace, and growing adoption of genAI apps by both organizations and users—as well as the overall volume of genAI apps in use— continued through 2024. Specifically:

Organizational use grew from 81% of companies using genAI apps in 2023 to 94% in 2024. ChatGPT continues to be the most popular genAI app, being used in 84% of organizations.Employee use rate of genAI apps tripled from 2.6% of all people in organizations to 7.8%. Retail and technology organizations lead all industries with an average of more than 13% of all employees using genAI apps monthly.Organizations now use an average of 9.6 genAI apps, up from 7.6 a year ago. The top 25% of organizations now use at least 24 genAI apps, whereas the bottom 25% are using 4 genAI apps at most.

Managing the genAI data risk

As genAI apps continued to solidify their standing as an enterprise mainstay (94% of organizations now use them) in 2024, organizations have shown they are still in the early stages of putting controls in place for the safe enablement of genAI and to help mitigate the data risks posed by genAI apps:

45% of organizations use DLP to control the flow of data into genAI apps. Industry adoption of DLP for genAI varies widely with telecommunications the highest at 64%.34% of organizations use real-time interactive user coaching to empower individuals to make appropriate and informed decisions.73% of the time, when prompted with warnings of a potential company violation, users opt to not proceed based on coaching information provided.73% of organizations block at least one genAI app, with a steady rate of 2.4 genAI apps blocked on average year over year.The number of apps blocked by the top 25% of all organizations blocking genAI apps has more than doubled from 6.3 apps to 14.6 over the past year.

Key takeaways for organizations

Netskope recommends organizations take the following steps to protect their environments:

Users are being bombarded with phishing links from all directions: email, social media, ads in search engine results, and all over the web. Furthermore, genAI is making it easier for attackers to craft convincing phishes. All of this underscores that relying on education alone to help users detect a phishing attempt is insufficient and must be coupled with investments in modern data protection.

Employees will continue to accidentally (or intentionally) share files via their personal accounts, include proprietary information in their personal backups, and use personal app instances to take data when leaving the organization. Regardless of intent, organizations must limit access to only those apps that serve a legitimate business purpose, create a review and approval process for new apps and implement a continuous monitoring process that will alert security operators when apps are being misused or have been compromised.

The trajectory of more organizations and more employees using genAI will continue into 2025 as genAI becomes more entrenched in the workplace. At the same time, the number of genAI apps will continue to grow, necessitating controls to ensure that only approved apps are used, and only for approved use cases. Organizations should use modern data security to control data movement into approved apps, leverage real-time user coaching to empower people to make informed decisions when using genAI apps, and implement controls that block unapproved apps.

“The common thread for organizations working to safely enable the use of apps in the enterprise, and mitigate the challenges across the threat landscape, is the need for modern data security,” said Ray Canzanese, Director of Netskope Threat Labs. “Gone are the days when data security was an afterthought. It must be seamlessly integrated into every aspect of an organization’s operations. From defending against phishing to safeguarding personal apps and managing genAI, data security is no longer just a perimeter defense. It is a dynamic, proactive framework with real-time user coaching, DLP, and app-specific controls to stay ahead of an ever-changing threat landscape.”

Read the full Cloud and Threat Report: 2025 here. For more information on cloud-enabled threats and the latest findings from Netskope Threat Labs, visit Netskope’s Threat Research Hub.

About Netskope
Netskope, a global SASE leader, helps organizations apply zero trust principles and AI/ML innovations to protect data and defend against cyber threats. Fast and easy to use, the Netskope One platform and its patented Zero Trust Engine provide optimized access and real-time security for people, devices, and data anywhere they go. Thousands of customers trust Netskope and its powerful NewEdge network to reduce risk and gain unrivaled visibility into any cloud, SaaS, web, and private application activity—providing security and accelerating performance without compromise.

Learn more at netskope.com, on the Netskope blog, on LinkedIn, and Instagram.

Media Contacts:
press@netskope.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/netskope-threat-labs-phishing-clicks-nearly-tripled-in-2024-ubiquitous-use-of-personal-cloud-apps-and-genai-tools-require-modern-workplace-security-to-mitigate-risk-302343700.html

SOURCE Netskope

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

MARIANA MINERALS RESTARTS UTAH COPPER MINE AS THE WORLD’S ONLY AUTONOMOUS-FIRST MINE AND REFINERY

Published

on

By

Software-first minerals company integrates autonomous haulage, drilling, and robotic sensing across mining and refining under a single AI operating platform

SAN JUAN COUNTY, Utah, April 27, 2026 /PRNewswire/ — Mariana Minerals, the world’s only software-first, vertically integrated minerals company, today announced the restart of mining operations at Copper One in southeastern Utah. The restart marks a milestone in mining history: Copper One becomes the world’s first mine to deploy autonomous tools across all three operational domains (mining, refining, and capital project execution) unified under a single operating system.

Mariana acquired Lisbon Valley Mining Company in Q4 2025, gaining control of a roughly 10,000-acre permitted land package that has produced high-purity copper cathode since 2009. While refinery operations continued uninterrupted, mining was paused in late 2024. Mining operations resume this month with autonomous systems and autonomous orchestration active from day one.

“Copper One will be the first mine where delivering end-to-end autonomy is the priority, where it’s being rapidly deployed across mining and refining operations and coordinated by our internal software stack. That’s what MarianaOS makes possible. We chose to prove it here because the stakes are real: the U.S. has a structural copper deficit, and the window to close it is narrowing. We’re producing now and ramping output aggressively, with the primary goal of achieving fully-autonomous mining operations,” said Turner Caldwell, Co-Founder & CEO, Mariana Minerals.

MarianaOS: An Autonomy-First Mining Operating System
What makes Copper One unprecedented is not any single piece of autonomous equipment, but the intelligence layer coordinating them. MarianaOS integrates three core subsystems, MineOS, PlantOS, and CapitalProjectOS, into a unified platform spanning project execution through copper production.

On the mining side, Copper One will begin with integrating three best-in-class autonomous equipment platforms. Pronto’s turnkey Autonomous Haulage System (AHS) uses camera-based machine learning and Global Navigation Satellite Systems (GNSS) to enable fully driverless haul truck operation, with OEM-agnostic retrofit capability across mixed fleets. Sandvik’s AutoMine® platform enables autonomous production drilling, allowing operators to simultaneously monitor multiple surface machine operations from a remote-operations control center. And Boston Dynamics’ Spot quadruped robots autonomously patrol the open pit, heap leach pad, and solvent extraction-electrowinning (SX-EW) refinery infrastructure. All of these data feed directly into MineOS, enabling fleet-wide optimization and continuous improvement.

PlantOS extends autonomous operations into refining by integrating real-time sensor data across the entire refining process (solution chemistry, flow rates, temperature, and electrowinning cell performance) into a unified control system. Machine learning models predict process drift, automatically adjust reagent dosing, and flags maintenance needs before they impact output. The result is a continuously optimized refinery that operates with minimal human intervention.

CapitalProjectOS redefines how capital-intensive infrastructure projects are planned and executed. Traditional projects often take a decade or more and frequently suffer from chronic cost overruns. CapitalProjectOS integrates process development, engineering, procurement, construction, and commissioning data into a single platform that enables real-time progress tracking, predictive risk modeling, and automated schedule optimization. At Copper One, CapitalProjectOS is managing the expansion roadmap to scale output to 50,000 metric tons per year, coordinating heap leach pad expansions, refinery upgrades, and autonomous equipment deployment in parallel.

Built to Move Fast
While Mariana is actively constructing and developing greenfield projects – with the goal of compressing engineering, procurement, construction, and commissioning timelines leveraging CapitalProjectOS – Copper One is uniquely positioned to accelerate deployment of MarianaOS at scale. With an existing open pit mine, heap leach pad, and SX-EW refining infrastructure already in place, Mariana will rapidly ramp production that would take years to replicate elsewhere.

Mariana’s longer-term plan is to scale Copper One output to 50,000 metric tons per year of high-purity copper cathode by 2030, leveraging additional proven deposits on the property and integrating copper scrap recycling.

A Critical Supply Gap
The U.S. currently imports approximately 50% of its refined copper. With domestic demand projected to nearly double by 2035 — driven by AI data centers, defense systems, EVs, and grid modernization — the supply gap is a national security issue. The Trump Administration’s Section 232 investigation cited copper imports as a direct concern, and the Pentagon has identified critical minerals vulnerability as a threat to the defense industrial base.

Domestic operations like Copper One, and the step-change in productivity that autonomous operations deliver, have become strategically essential.

About Mariana Minerals
Mariana engineers, builds, and operates mines and refineries, using proprietary AI and machine learning tools to accelerate project execution and optimize production across critically needed metals. Copper One is Mariana’s second active project, alongside Lithium One, the world’s first GWh-scale lithium extraction facility from oil and gas produced water, currently under construction in East Texas. Mariana has raised $120 million in total capital, including a Series A led by Andreessen Horowitz with participation from Breakthrough Energy Ventures, Khosla Ventures, and strategic investors.

View original content to download multimedia:https://www.prnewswire.com/news-releases/mariana-minerals-restarts-utah-copper-mine-as-the-worlds-only-autonomous-first-mine-and-refinery-302753491.html

SOURCE Mariana Minerals

Continue Reading

Technology

State CISOs Report Lower Confidence Across the Public Sector Cyber Ecosystem, 2026 NASCIO-Deloitte Survey Finds

Published

on

By

The 2026 National Association of Chief Information Officers – Deloitte biennial cybersecurity study finds state officials face increasingly sophisticated threats, including new artificial intelligence-enabled tactics, and highlights steps CISOs are taking to better protect public data and critical digital services

NEW YORK, April 27, 2026 /PRNewswire/ — 

Key takeaways

The survey of Chief Information Security Officers (CISOs) from all 50 states and two territories found that just 26% of state CISOs are “extremely” or “very” confident that their state’s information assets are protected from cyber threats, down from 48% in 2022.Implementing effectiveness metrics is now CISOs’ top priority: 49% named it a top cybersecurity initiative in 2026, up from 15% in 2022.Nearly all state CISOs (94%) said they are involved in developing Generative AI security policies and 84% are involved in Generative AI strategy development.Budget pressure is rising with 16% of CISOs reporting their budgets have been cut, up from none in 2024.The percentage of CISOs who described themselves as “not very confident” in the ability of local government and public higher education to secure public data rose significantly, from 35% in 2022 to 63% in 2026.

Why this decline in confidence matters
States share data and systems with counties, cities, and public colleges and universities, so a vulnerability in one network can cascade, exposing personal information, disrupting essential services and driving costly incident response. As attackers adopt AI-enabled tactics, the urgency is growing for faster coordination, clearer policy and stronger baseline defenses across the public sector. This may explain why roughly one-fifth of CISOs indicated that their states were moving toward a “whole-of-state” approach to cybersecurity.

Metrics reporting becomes CISOs’ top priority
Top priorities for CISOs have shifted since the 2024 survey. When asked to identify their states’ top cybersecurity initiatives for 2026, half of CISOs named implementing effectiveness metrics (49%, up from 25% in 2024 and 15% in 2022). Capturing the effectiveness of cyber spending can be difficult, but without metrics, it is challenging to show the benefits of investments. Tracking operational, compliance and risk-based key performance indicators, such as incident response time and phishing click rate, can help demonstrate the return on cyber investment.

AI both accelerates threats and becomes a frontline defense
AI is accelerating the scale and sophistication of attacks targeting public sector systems, making it easier and cheaper for adversaries to generate and automate cyberattacks. CISOs also point to an emerging threat toolkit, including deepfakes that can fool people and evade detection, AI agents that probe for weaknesses and adapt, and AI-driven ransomware-as-a-service operations.

At the same time, CISOs describe AI as a practical way to keep pace, using it to triage security alerts, summarize events, and explore faster report creation, threat identification and training. Several states are already utilizing Generative AI in core security operations, including security information and event management (SIEM) and security orchestration, automation and response (SOAR). The report also underscores how central CISOs have become to state AI efforts.

Key quotes
“We’re seeing more states move toward a ‘whole-of-state’ cybersecurity approach where the state helps extend protection beyond state agencies to local governments, public education and other critical entities that can become an entry point for attackers. At its core, it’s about scaling capabilities through shared services and better collaboration so a weakness in one part of the ecosystem doesn’t become a statewide incident. Many states are looking to scale capabilities through security operations centers and regional support, so counties, cities and schools can benefit from the same cyber-defense muscle as the enterprise.”

Mike Wyatt, Stale local and higher education cyber risk leader, Deloitte

“It’s an encouraging development that state CISOs are being placed at the center of Generative AI security. They are helping shape the strategy, establishing security policies and reviewing proposed use cases. By being involved from the beginning, CISOs are helping governments move faster without sacrificing safeguards because security and governance complement each other. We’re also seeing CISOs explore practical uses of AI to strengthen day-to-day defense, while putting clearer guardrails around responsible uses.”

Meredith Ward, deputy executive director, NASCIO

Additional data
To read the 2026 NASCIO-Deloitte report in its entirety, click here.

About NASCIO
The National Association of State Chief Information Officers is the premier network and resource for state CIOs and a leading advocate for technology policy at all levels of government. NASCIO represents state chief information officers and information technology executives from the states, territories, and the District of Columbia. For more information about NASCIO visit www.nascio.org.

As used in this document, “Deloitte” means Deloitte & Touche LLP, a subsidiary of Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of our legal structure. Certain services may not be available to attest clients under the rules and regulations of public accounting.

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/state-cisos-report-lower-confidence-across-the-public-sector-cyber-ecosystem-2026-nascio-deloitte-survey-finds-302751899.html

SOURCE Deloitte

Continue Reading

Technology

Duck Creek Kicks Off Formation ’26 as Strong Fiscal Momentum Signals Accelerating Demand for its Intelligent Core Insurance Platform

Published

on

By

Company highlights double-digit SaaS growth, global expansion, and launch of its new agentic AI platform as industry leaders gather in Orlando

BOSTON, April 27, 2026 /CNW/ — Duck Creek Technologies, the intelligent core of insurance, today kicks off Formation ’26: Agents of Innovation, its flagship user conference, as the company builds strong momentum in the first half of fiscal 2026, marked by double-digit year-over-year SaaS ARR growth fueled by new logos and expansion across its global customer base.

Duck Creek’s strong start to fiscal 2026 reflects this demand, with double-digit new customer wins and existing customer expansions across its core, specialty, and AI-powered solutions. Adoption of Duck Creek’s intelligent cloud continues to scale globally. Insurers are selecting Duck Creek for its enterprise depth including policy, billing, claims, rating, loss control, reinsurance, distribution management, and payments solutions to operate faster, more accurately, and maintain regulatory compliance.

“We are expanding our leadership in insurance technology with more than 370 customers globally. Including 33 of the top 50 North American insurers,” said Hardeep Gulati, Chief Executive Officer of Duck Creek. “Insurers modernizing their core systems are looking for more from their technology. They need a trusted partner like Duck Creek with proven enterprise scale and speed-to-value to help them drive profitable impact and growth. At Formation, we are excited to announce our new agentic platform that will help further improve the combined ratios for insurers with more than $150B in premium flowing through Duck Creek annually.”

Formation ’26 will bring together more than 800 insurance professionals, ecosystem partners, and industry leaders to explore how technology is transforming the insurance lifecycle. The event underscores growing market demand for intelligent, cloud-native platforms that enable insurers to accelerate cloud migration, product development, and automate core insurance workflows to accelerate decision-making and improve operational agility. A highlight of the event will be Duck Creek unveiling its agentic AI platform and showcasing live demonstrations of agentic applications and agents.

Formation ’26 will feature a distinguished lineup of guest speakers joining Gulati during his keynote, including Stephen Lord, Global CIO of AXIS Capital, and Monti Saroya, Senior Managing Director and Co-Head of the Flagship Fund at Vista Equity Partners. Together, they will share perspectives on large-scale transformation, AI adoption, and the future of agentic insurance.

The conference will also include a customer panel moderated by Chief Operating Officer Chris McCloskey, featuring leaders from Core Specialty, Europ Assistance, and Arbella Insurance, who will discuss their transformation journeys and business outcomes achieved through modern core systems. An analyst panel moderated by SVP of Sales William Magowan will bring together experts from AM Best, Celent, and Datos Insights to provide an external view on market trends and innovation benchmarks.

Customer Momentum

Millers Mutual Insurance advanced its modernization strategy with Duck Creek OnDemand, implementing Policy, Billing, and Reinsurance Clarity to modernize its core systems and support continued growth in the multifamily housing insurance market.Anchor Group Management Inc. partnered with Duck Creek to modernize its insurance payments infrastructure, enabling more streamlined billing processes and improved digital payment experiences for policyholders.Frankenmuth Insurance adopted Duck Creek OnDemand Distribution Management to transform how it manages agencies and producers, increasing visibility, improving operational efficiency, and strengthening collaboration across its distribution network.Indigo Insurance turned to Duck Creek OnDemand to accelerate its modernization strategy and support rapid growth, gaining a scalable cloud-based core platform designed to bring new products to market faster.Encova Insurance went live on an upgraded Duck Creek OnDemand Distribution Management system, unifying agency operations across lines of business, streamlining onboarding, and improving the overall agent experience.New Zealand’s Medical Assurance Society (MAS) selected Duck Creek’s full suite of core solutions delivered via OnDemand to modernize its general insurance business, enhance member experiences, and support a broader digital and data-driven transformation.Country-Wide Insurance selected Duck Creek Clarity to strengthen its data and analytics capabilities, enabling real-time insights and preparing for its upcoming OnDemand go-live with Active Delivery.Fortegra selected Duck Creek Reinsurance and Duck Creek Clarity to modernize financial operations, improve portfolio transparency, and support continued growth across products, geographies, and distribution models.Duck Creek secured more than a dozen additional new customer engagements across commercial specialty and personal lines.

Industry Recognition

Named a Leader in the 2025 Gartner Magic Quadrant for SaaS P&C Insurance Core Platforms North America, marking the seventh consecutive year the company has been recognized as a Leader.Named a Leader in the Everest Group 2025 Underwriting Orchestration Products PEAK Matrix Assessment, recognizing Duck Creek’s strength in delivering AI-driven underwriting, integrated core workflows, and measurable value across global P&C carriers.Featured in Everest Group’s 2026 Voice of the Customer Report for Insurance CXOPs, outperforming both core system peers and the market average, with customers citing strengths in seamless implementation, deep core system integration, and enterprise scalability and more.Received the 2025 IDC FinTech Real Results Award for Insurance Transformation for measurable customer outcomes.

About Duck Creek

Duck Creek is the intelligent core that leading insurers choose to build on. Purpose-built for property and casualty (P&C) and general insurance, Duck Creek unifies the full insurance lifecycle on a single platform with one data foundation. As an agentic platform, it connects intelligence across underwriting, policy, billing, claims, and payments workflows where decisions are made and compliance is non-negotiable. Duck Creek enables carriers to launch products faster, adapt quickly to change, and grow with precision and confidence. Solutions are available individually or as a full suite via Duck Creek OnDemand. Visit www.duckcreek.com and follow Duck Creek on LinkedIn and X.

Media Contacts:  
Marianne Dempsey / Tara Stred  
duckcreek@threeringsinc.com

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/duck-creek-kicks-off-formation-26-as-strong-fiscal-momentum-signals-accelerating-demand-for-its-intelligent-core-insurance-platform-302753478.html

SOURCE Duck Creek Technologies, Inc.

Continue Reading

Trending