December 2025 Summaries
5 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
As the year transitions between the Christmas and New Year's holidays, the preliminary findings from the upcoming 2026 email security report highlight several significant trends in email threats. Notably, there has been a dramatic 22-fold increase in ICS phishing attacks, which exploit default calendar automations to bypass email security measures. Malware attacks are evolving with a focus on behavioral evasions, leveraging tactics like social engineering and time-based delivery, possibly aided by generative AI. QR code-based attacks surged by nearly 300% in 2025, exploiting their ability to bypass traditional email security and target mobile devices. The use of lesser-known hosting services for Living Off Trust Sites (LOTS) attacks is growing, with about 25% originating from these platforms, often utilizing page and form builders or collaboration services. Additionally, the report notes the emergence of massive email bomb attacks, likened to a DDoS for inboxes, with the largest detected consisting of over 10,000 messages designed to overwhelm and obscure malicious activities. The full report, available on January 21, promises further insights into these evolving threats.
Dec 29, 2025
785 words in the original blog post.
Sublime's platform employs an advanced method of grouping similar email messages to enhance the analyst experience and improve system efficiency. By using set-based representations and techniques like tokenization, shingling, and MinHash, Sublime efficiently processes large volumes of messages, identifying highly similar ones in milliseconds. This process involves representing messages as sets of smaller fragments, utilizing the Jaccard index for calculating similarity, and leveraging MinHash for efficient approximation of set similarity. The banding technique further optimizes search processes by reducing the search space for messages with high similarity. This approach allows for fast retrieval and clustering of messages, supporting real-time grouping and enabling powerful features such as cascading remediation and live clustering in high-scale environments. The platform's ability to manage these processes efficiently is a testament to its sophisticated engineering and mathematical foundations, making it a robust tool for message processing and management.
Dec 18, 2025
2,932 words in the original blog post.
Sublime, a company that started in a small office and has grown significantly, is undergoing a rebranding to better reflect its evolution and success in the email security industry. The rebrand includes a new logo that builds on the company's legacy of visibility, transparency, and control, while also allowing for adaptability and memorability across various platforms. The rebranding initiative is guided by three core principles: being technical yet approachable, optimistic without being superficial, and trusted while maintaining professionalism. This new brand identity aims to provide a consistent and emotionally resonant experience for customers and stakeholders, showcasing Sublime's commitment to precision, empowerment, and enterprise-grade reliability. As Sublime continues to expand and serve a growing customer base, the rebrand represents both a celebration of past achievements and a foundation for future growth and innovation.
Dec 16, 2025
849 words in the original blog post.
Sublime, a feature of the security platform by Recon Infosec, has introduced a general availability feature that automatically remediates malicious calendar invitations to address the rise in calendar-based attacks. This feature enables Sublime to delete malicious calendar entries when their corresponding emails are quarantined, spammed, or trashed, effectively preventing both calendar and inbox infiltration. Additionally, if a suspicious invite is deemed safe upon review, Sublime can restore the event as a placeholder with details and RSVP options. Users need to extend app permissions to include calendar access, ensuring that the platform's AI-driven protection can efficiently manage these threats. The feature not only protects users by automatically handling threats but also allows analysts to focus on more critical tasks by reducing manual intervention.
Dec 09, 2025
368 words in the original blog post.
In 2025, Sublime introduced two AI agents, the Autonomous Security Analyst (ASA) and the Autonomous Detection Engineer (ADÉ), to streamline and enhance email security processes. ASA efficiently handles the majority of user-reported messages without requiring analyst intervention, while ADÉ addresses any coverage gaps identified by ASA, analyzing attacks and developing new detection strategies for rapid deployment. These agents are part of a planned suite designed to improve security and reduce the workload on security teams. The agents leverage advanced tools and technologies, such as message rendering, behavioral context analysis, and deep content analysis, to counter increasingly sophisticated adversarial AI systems. Sublime's platform, powered by Message Query Language (MQL), allows for precise agent coordination, ensuring accurate and auditable security measures. The agents are constantly updated to keep pace with evolving threats and benefit from collective intelligence across multiple organizations. With a strong focus on privacy, Sublime ensures that no customer data is shared with third-party providers. The collaborative system of agents acts as a cohesive team, automatically managing and closing coverage gaps quickly, supported by rigorous evaluation frameworks to maintain accuracy and reliability.
Dec 04, 2025
1,460 words in the original blog post.