Home / Companies / Sublime Security / Blog / February 2025

February 2025 Summaries

3 posts from Sublime Security

Filter
Month: Year:
Post Summaries Back to Blog
Sublime's Attack Spotlight series highlights emerging threats in the email threat landscape by showcasing real-world attack samples and explaining adversary tactics and techniques. One notable threat involves a credential phishing campaign utilizing SVG files, which are often underestimated as mere image files but can embed JavaScript to facilitate attacks. In this campaign, an email mimicking a voicemail notification from a law firm contains an SVG attachment that, when opened, displays a blue checkmark and redirects the user to a phishing site through embedded JavaScript. This site simulates a security process and leads the user to a fake Microsoft login page designed to harvest credentials, which are then verified against Microsoft's authentication service. Sublime's AI-powered detection engine successfully thwarted this attack by identifying signals such as embedded JavaScript in SVGs, fake voicemail notifications, and communications from unknown senders, offering a robust defense against such email-based threats.
Feb 25, 2025 742 words in the original blog post.
As tax season approaches, the prevalence of scams increases, with scammers exploiting opportune moments when people may be less vigilant. These scams often involve sophisticated techniques such as VIP impersonation, where attackers mimic high-ranking executives to gain credibility, and tax-themed phishing attacks that impersonate services like DocuSign to steal credentials. Sublime's detection systems, which use machine learning and a variety of signals to identify malicious intent, have intercepted multiple scams this year, including those using newly registered domains and urgent language to trick targets. One highlighted scam involved malware delivery via a fake PDF linked to a tax assistance request, while another utilized QR codes in a multi-step process to harvest credentials. The text emphasizes the importance of being cautious of these layered attacks, which often begin with seemingly innocuous emails, and highlights the role of technological solutions in identifying and mitigating such threats. Sublime offers AI-powered detection tools to help individuals and organizations protect themselves from these evolving email-based threats.
Feb 18, 2025 1,326 words in the original blog post.
Sublime has introduced a new beta feature called Topic Modeling, which employs machine learning to automatically classify message content into 27 predefined categories, enhancing detection capabilities and reducing false positives and negatives. This feature aims to bring transparency and granularity by enabling hyper-targeted detection, particularly useful for managing spam and graymail, which occupy spaces between benign and malicious communications. Built using few-shot classification with supervised learning, Topic Modeling refines detection through a collaboration between the company's Detection team and a large language model, ultimately training a more efficient classifier. By allowing detailed categorization of messages, it simplifies behavioral detection processes, exemplified by its ability to identify and prevent credential phishing with concise Message Query Language (MQL) statements. This technology is set to improve future spam and graymail Attack Score verdicts, and advanced users can now access Topic Modeling in beta for custom Detection Rules and automations.
Feb 07, 2025 992 words in the original blog post.