November 2025 Summaries
3 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Sublime's Attack Spotlight series sheds light on the rising threat of Meta for Business credential phishing scams, which have become increasingly prevalent as part of a broader trend of Meta/Facebook phishing attacks. These scams often begin with emails originating from legitimate Meta domains, inviting targets to seemingly legitimate programs like the Meta Professional Partner Program. The emails contain links to deceptive domains that mimic official Meta pages, leading users through a series of fake forms and password prompts designed to harvest credentials without actual verification. Variations of the attack include the use of non-English characters and fake verified badge notifications. Sublime's AI-powered detection engine effectively identifies these scams by recognizing deceptive domains, service abuse, and urgency cues in the emails. The series emphasizes the importance of adaptive security platforms that leverage AI and machine learning to detect such threats, encouraging readers to stay informed via their blog and newsletter.
Nov 21, 2025
872 words in the original blog post.
Sublime's Attack Spotlight series highlights various email threats exploiting trusted platforms like Salesforce to conduct spam, phishing, and crypto wallet attacks. Adversaries are leveraging Salesforce infrastructure to enhance legitimacy and evade detection, often by compromising existing accounts or creating fraudulent ones. Among the observed attacks are spam messages soliciting "opt out" responses, job scams impersonating recruiters to phish for credentials, and crypto phishing schemes offering token airdrops. These attacks, though sent via legitimate infrastructure, are detected by Sublime's AI-powered engine using specific signals such as suspicious sender behavior, brand impersonation, urgency, and redirects to Cloudflare pages. While Salesforce abuse is prevalent, Sublime emphasizes that effective email security relies on adaptive AI and machine learning to identify and mitigate these threats, offering demonstrations to showcase its preventative capabilities.
Nov 13, 2025
1,011 words in the original blog post.
Sublime's Attack Spotlight series highlights the increasing threat of ICS phishing attacks, which exploit calendar invitations to bypass security measures in email providers like Microsoft 365 and Google Workspace. These attacks leverage the automatic addition of calendar events, creating a dual threat by embedding malicious content both in emails and calendar entries. Despite traditional email security efforts, malicious calendar entries often remain, posing a unique challenge. Sublime addresses this by offering functionality that automatically removes harmful calendar invites, akin to its email threat prevention. The series provides real-world examples, detailing how attackers use tactics such as QR codes, brand impersonation, and urgent messaging to deceive targets. Sublime's AI-powered detection engine, including the Autonomous Security Analyst, identifies these threats using various signals, including manipulative language and suspicious attachments. The text also offers guidance on securing Google calendars against "silent" invitations and promotes Sublime's ongoing efforts to inform about the evolving email threat landscape through demos and podcasts.
Nov 03, 2025
1,131 words in the original blog post.