September 2025 Summaries
4 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
The recent discourse in AI circles highlights the limitations of generic evaluations, emphasizing the need for tailored frameworks that align with specific problem-solving goals. In cybersecurity, there is skepticism toward AI tools, especially in Large Language Model (LLM) code generation, due to concerns about generating plausible but flawed detection rules. To address this, a three-pillar framework focusing on Detection Accuracy, Robustness, and Economic Cost has been developed to objectively evaluate AI-generated detection rules. This framework assesses whether rules effectively stop unique attacks, resist evasion, and are economically viable to produce and maintain. By comparing AI-generated rules to human-crafted ones, the framework demonstrates that AI can quickly create high-precision rules, enhancing detection capabilities while maintaining economic efficiency. The framework's adaptability ensures continuous improvement, integrating adversarial testing to teach AI agents to generalize detection rules effectively. This approach not only measures performance but also strengthens machine learning models over time, fostering customer trust through transparency and realistic evaluations. The full evaluation framework is detailed in a paper available on ArXiv, and its findings will be presented at the Conference on Applied Machine Learning in Information Security (CAMLIS).
Sep 25, 2025
1,673 words in the original blog post.
Sublime's Attack Spotlight series reveals a sophisticated email threat involving malware, ransomware, and credential phishing, where attackers used both Apple's TestFlight platform and the App Store to distribute a fake Meta Ads Manager app to Apple devices. The attackers employed tactics like brand impersonation using Meta's name, sending emails from freemail domains, and utilizing homoglyph substitutions to evade detection. The TestFlight variant required targets to install the app via TestFlight after downloading it from the App Store, while the App Store variant directly linked to the app's page on the App Store. Sublime's AI-powered detection system identified and thwarted these attacks by recognizing signals such as brand impersonation and suspicious sender behavior, leading to the removal of the malicious app from the App Store. This case underscores the importance of adaptive email security platforms that use AI and machine learning to detect subtle signs of malicious activity, highlighting the need for vigilance as malware increasingly targets personal devices through email.
Sep 23, 2025
816 words in the original blog post.
Email attacks have significantly increased in complexity and frequency due to advancements in AI, prompting new strategies in email security. A novel approach involves using transparent, specialized agents that operate under human oversight, enhancing precision and adaptability compared to traditional, opaque models. Sublime has developed AI agents like ASA and ADÉ that autonomously manage and respond to security threats, ensuring tailored detection and closing coverage gaps in real time. ADÉ, in particular, refines and validates detection rules with transparency, enabling human analysts to review and approve new rules while maintaining efficiency and minimizing false positives. This approach represents a shift towards proactive, evolving email security, offering customizable solutions that integrate transparency and human collaboration to keep pace with sophisticated cyber threats.
Sep 11, 2025
655 words in the original blog post.
Sublime's Attack Spotlight series highlights real-world email threats, focusing on callback phishing attacks that exploit legitimate communication channels to evade detection. A recent example involved adversaries using a bank's "Request a Meeting" form to distribute phishing emails, cleverly mixing financial and tech support narratives to prompt recipients to call specific phone numbers. These emails, sent to distribution lists, maintain a legitimate appearance as they originate from recognized domains, making them less likely to be flagged as suspicious. Sublime's AI-powered detection engine effectively identifies such attacks by recognizing patterns like mismatched contexts, multiple call-to-action phone numbers, and urgent language. The series underscores the importance of adaptive security measures that leverage AI and machine learning to detect subtle inconsistencies in seemingly legitimate communications.
Sep 04, 2025
727 words in the original blog post.