January 2025 Summaries
3 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Sublime's Attack Spotlight series highlights real-world email threats, focusing on credential phishing and brand impersonation tactics, specifically within Google Workspace environments. A recent case involved a sophisticated phishing attempt mimicking Charles Schwab, where attackers used CAPTCHA redirection and a fake login page to harvest credentials. They incorporated two-factor authentication (2FA) by prompting victims to enter their phone numbers, which attackers then used to trigger a legitimate authentication SMS, capturing the code to complete the fraudulent login. Sublime's AI-powered detection engine identified these attacks through several indicators, including unusual sender domains and language aimed at credential theft. The platform offers a suite of tools to prevent such phishing attempts, allowing users to customize threat handling within their environments, and continues to expand its detection capabilities to cover a broad range of brand impersonation scenarios.
Jan 29, 2025
417 words in the original blog post.
Sublime has enhanced its message grouping algorithm to improve the detection and remediation of email attack campaigns by grouping similar messages, even when attackers introduce variations in subject, sender, and content to evade detection. This update leverages set similarity algorithms to identify related messages, enabling faster and more efficient triage and remediation by security analysts. By grouping messages with subtle differences, Sublime reduces alert fatigue, decreases false negatives, and improves overall herd immunity, allowing for automatic remediation across all mailboxes once a single message in a group is flagged as malicious. The improved system helps analysts prioritize and investigate attacks more effectively, streamlining the incident response process and reducing the median time to remediate (MTTR) email-originated incidents.
Jan 24, 2025
918 words in the original blog post.
Sublime's Attack Spotlight series highlights real-world examples of email threats, focusing on Business Email Compromise (BEC) scams within platforms like Google Workspace. These scams often involve attackers fabricating email threads using names of co-workers, trusted companies, and industry jargon, creating the illusion of legitimate conversations to deceive recipients into transferring money to attacker-controlled accounts. The process typically involves gathering intelligence, crafting fake invoices, and delivering them within fabricated email threads to pressure targets into making payments. Sublime's AI-powered detection engine identifies such scams by monitoring signals like fake message threads, unknown or suspicious senders, and engaging fraud language. The platform offers tools for detecting and preventing BEC and other email-based threats, with options for customization to suit different environments.
Jan 07, 2025
825 words in the original blog post.