Home / Companies / Sublime Security / Blog / October 2025

October 2025 Summaries

6 posts from Sublime Security

Filter
Month: Year:
Post Summaries Back to Blog
Sublime has experienced significant growth, quadrupling its customer base this year and maintaining zero enterprise customer churn since its inception, which has culminated in raising $150 million in Series C funding. This funding round, led by Georgian and supported by both new and existing investors, aims to advance Sublime's vision of enhancing email security through agent-based technology. The company has introduced innovative products like email bomb protection and AI agents that autonomously manage user reports, and it plans to use the new capital to expand its platform capabilities, improve protection against sophisticated cyberattacks, and reduce reliance on traditional security solutions. Sublime is also focused on expanding its global presence to better support its customers and partners, emphasizing its commitment to providing adaptive and transparent email security solutions that align with each organization's specific needs.
Oct 28, 2025 346 words in the original blog post.
Sublime's Attack Spotlight series highlights the detection and prevention of phishing attacks using Microsoft 365's Direct Send feature, which allows unauthenticated messages to be sent to mailboxes, potentially bypassing inline email security solutions. Despite its legitimate uses, such as sending emails from internal devices and applications, Direct Send can be exploited by attackers for phishing by spoofing emails within a tenant. Sublime's AI-powered detection engine effectively identifies and stops these attacks by analyzing various indicators, such as failed authentication, self-sender patterns, and encoded threats within attachments, rather than relying solely on Direct Send as a malicious indicator. Examples include phishing attempts using QR codes and SVG files with embedded malicious scripts, demonstrating the importance of comprehensive email analysis techniques. The series encourages staying informed through their blog and newsletter to keep up with evolving email threat landscapes.
Oct 23, 2025 1,629 words in the original blog post.
Sublime's Attack Spotlight series highlights the methods and prevention of email threats, such as a recent credential phishing campaign using fake job opportunities to target individuals seeking social media manager roles. This campaign involved impersonating well-known companies, including a notable example where attackers mimicked Red Bull, using deceptive URLs and brand impersonation tactics to direct victims to fake job listings and phishing sites. The attack exploited the slowed U.S. job market by presenting enticing but fraudulent job offers, with the scammers employing phishing kits and potential use of LLMs to craft varied attack messages. Sublime's AI-powered detection engine effectively identified and blocked these attacks by recognizing mismatched sender details, deceptive URLs, and language indicative of Facebook credential phishing. The series encourages readers to stay informed of evolving threats by following their blog and subscribing to their updates for the latest information on email security.
Oct 16, 2025 651 words in the original blog post.
The Sublime Attack Spotlight series explores a credential phishing scam impersonating Google Careers, targeting users of Google Workspace and Microsoft 365. The scam involves sending emails that mimic Google Careers outreach, leading recipients to a fake meeting scheduler and eventually a phishing page designed to steal personal information and credentials. The attack is notable for its ongoing development, with threat actors refining tactics to evade detection. Variations include messages in multiple languages, different sender impersonations, and the use of newly registered domains. The phishing process often involves HTML word padding evasions and Adversary in the Middle (AITM) infrastructure for credential theft. Sublime's AI-powered detection engine and Autonomous Security Analyst flag these malicious emails by identifying brand impersonation, domain deception, and other suspicious signals.
Oct 14, 2025 1,261 words in the original blog post.
Sublime's Attack Spotlight series highlights a recent surge in credential phishing attacks targeting visa sponsors in the UK, where attackers impersonate the UK Visas and Immigration department to lure victims into fake Sponsor Management System login pages. These phishing attempts, characterized by their urgency and deceptive URL structures, aim to extract sensitive identity information, posing significant risks to individuals and national security. The attacks exploit the complexity of immigration systems, potentially resulting in identity theft, fraudulent submissions, and undermining trust in UKVI systems. Sublime's AI-powered detection engine identifies these threats through signals such as brand impersonation, deceptive URLs, and urgency in messages. Despite the attacks' scale and variety, the exact motivations remain unclear but may involve financial gain through identity or visa sales. The series emphasizes the need for adaptive email security measures to counteract evolving phishing tactics.
Oct 08, 2025 974 words in the original blog post.
Sublime's Attack Spotlight series aims to educate readers about the email threat landscape through real-world examples of attacks, detailing adversary tactics and techniques, and explaining detection methods. It highlights a surge in malicious digital invitation-based attacks, particularly impersonating brands like Evite and Punchbowl, which utilize tactics such as credential phishing and malware distribution. These attacks often involve sophisticated brand impersonation, with payloads varying across attack types, and are typically distributed to undisclosed recipient lists. The series discusses specific examples, such as a Google-specific credential phishing attack using Cloudflare-hosted pages and Remote Monitoring and Management (RMM) malware attacks. It underscores the importance of adaptive email security platforms that use AI and machine learning to detect these threats by identifying discrepancies such as brand impersonation and suspicious domains. The series encourages readers to stay informed by subscribing to Sublime's newsletter and checking their blog for regular updates on new attack patterns and security strategies.
Oct 02, 2025 1,071 words in the original blog post.