August 2025 Summaries
4 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Email bombs are a type of cyberattack where a large volume of emails is sent to overwhelm a target mailbox, potentially disabling it or facilitating further attacks, such as machine or account takeovers. These attacks are challenging to counter due to the sheer volume of emails and their often legitimate appearance. Sublime offers a solution by detecting sustained spikes in email volume, which are indicative of an email bomb, and using automation to sort and quarantine malicious emails. The platform employs machine learning techniques, including Attack Score, Natural Language Understanding, and Topic Modeling, to enhance detection and processing, allowing for efficient identification and remediation of email bombs. Users can benefit from customizable automations through Message Query Language, enabling them to tailor defenses to their specific needs. The system provides a detailed interface for tracking ongoing and remediated email bombs, ensuring that both automated and manual triage options are available for handling legitimate messages caught in the attack.
Aug 28, 2025
855 words in the original blog post.
NLU 3.0 introduces significant advancements in natural language understanding by addressing limitations of previous versions and enhancing the system's agility and accuracy in detecting threats. The update employs synthetic data augmentation using generative AI to anticipate diverse phishing tactics and includes a unified multi-head architecture that processes multiple tasks simultaneously, such as intent classification, named entity recognition, and topic modeling. This approach leverages shared context and improves computational efficiency, enabling faster iterations and expansions of NLU capabilities without retraining entire models. The modular design allows for the rapid addition of new functionalities, thereby maintaining a proactive stance against evolving threats.
Aug 26, 2025
959 words in the original blog post.
The recent Las Vegas cybersecurity conferences, including BSides LV, Black Hat USA, and DEF CON, highlighted enduring themes with new iterations, particularly the increasing focus on the human element in cyber attacks, where attackers are now using AI to exploit human recovery processes and impersonation techniques to bypass technical defenses. The conferences showcased an evolving arms race in automation, with both defensive and offensive sides developing AI agents to enhance cybersecurity strategies; however, this shift also introduces new vulnerabilities, as these AI agents, granted privileged access, become potential insider threats. Additionally, there is a pervasive sense of dissatisfaction and professional burnout in the industry, with criticisms that defensive advice has stagnated and official guidance is not keeping pace with innovation, leading to a cultural crisis in cybersecurity. The industry's challenge now lies in adapting to these evolving threats while addressing the systemic issues of burnout and dissatisfaction among professionals.
Aug 18, 2025
832 words in the original blog post.
Sublime has announced the release of NLU 3.0, a significant upgrade to its Natural Language Understanding model, designed to enhance email security by detecting sophisticated threats such as business email compromise and polymorphic phishing attacks. This new version leverages synthetic data augmentation with Generative AI and a unified multi-head architecture to improve the model's ability to understand email context and intent, thus reducing false positives and increasing threat detection accuracy. The model's modular design allows for rapid expansion, enabling it to adapt quickly to new attack patterns. NLU 3.0's insights are integrated into Sublime's Message Query Language (MQL), simplifying rule creation for security teams and helping them focus on real threats. This upgrade promises to outpace adversaries by adapting to evolving threats, offering a more resilient defense against GenAI-generated attacks while maintaining system performance and transparency.
Aug 13, 2025
905 words in the original blog post.