January 2026 Summaries
4 posts from Sublime Security
Filter
Month:
Year:
Post Summaries
Back to Blog
Sublime's Attack Spotlight series provides insights into the evolving email threat landscape by showcasing real-world attack samples, detailing adversary tactics, and explaining detection methods. A recent spotlight highlights an increase in credential phishing attacks via Google Cloud's Application Integration platform, where attackers exploit this legitimate service to send convincing emails from a seemingly authentic Google address. These phishing emails often lead victims to a fake CAPTCHA page, which uses sophisticated bot detection and challenge methods to filter out automated systems before redirecting them to a phishing site. The attack's complexity is underscored by its use of AI-generated content and a script with multiple bot detection configurations, making it a potent tool for bypassing email security. Sublime's AI-driven detection engine successfully identifies these threats by analyzing various indicators such as Google impersonation, suspicious links, and urgency cues. The series emphasizes the importance of adaptive email security platforms that utilize AI and machine learning to detect and mitigate such sophisticated scams.
Jan 29, 2026
958 words in the original blog post.
The 2026 Sublime Email Threat Research Report highlights a rapidly evolving threat landscape in which attackers increasingly prioritize precision and trust exploitation over high-volume campaigns. In 2025, business email compromise (BEC) attacks remained prevalent, with thread hijacking surpassing traditional methods by inserting attackers into legitimate conversations to deceive targets. QR code phishing surged, exploiting the vulnerability of mobile devices outside corporate security, while AI-generated attacks rose significantly, showcasing the adaptability of attackers using AI. Calendar invites emerged as a new phishing vector, bypassing traditional email security, and evasion stacking combined multiple techniques to outsmart defenses. Attackers also shifted towards abusing lesser-known platforms, leveraging trust in emerging services. Organizations are urged to adopt adaptive detection systems integrating machine learning and agentic AI to counteract these sophisticated social engineering tactics and the increasing speed of attack evolution.
Jan 21, 2026
1,103 words in the original blog post.
Sublime has developed Mjölnir, a specialized load testing framework designed to meet the unique demands of email security platforms and simulate enterprise-scale traffic. Existing tools like k6, Gatling, and JMeter were insufficient for emulating realistic email behaviors and handling Google Workspace or Microsoft 365 API simulations, prompting the creation of Mjölnir. This framework employs a producer/consumer architecture to separate email preparation from sending, ensuring precise timing and efficient memory use. Mjölnir's realistic email address generator and suffix-compressed radix trees manage millions of addresses efficiently, while its worker pool with configurable delay and jitter can simulate realistic, bursty email traffic patterns. The tool has effectively validated Sublime's platform capabilities, supporting inline processing and user reports under high load, and continues to evolve with additional features like API mockups for Google Workspace and Microsoft 365. Through Mjölnir, Sublime can confidently ensure their infrastructure is ready for large enterprise customers, addressing specific challenges that generic load testing tools cannot.
Jan 15, 2026
1,777 words in the original blog post.
Sublime's Attack Spotlight series highlights various real-world email threats, including credential phishing, callback phishing, and financial scams, that target Microsoft 365 and Google Workspace users. The series showcases examples such as a Geek Squad impersonation scam and a credential phishing attack using a malicious SVG file with embedded JavaScript. Sublime's threat hunting efforts have detected diverse attack strategies, including Living off Trusted Services (LOTS) abuses leveraging GoDaddy and HostPapa infrastructures. These attacks employ sophisticated evasion tactics like employing obfuscated HTML and exploiting calendar invite features to bypass security measures. Sublime's AI-powered detection engine, equipped with features like OCR analysis and AI-driven threat identification, effectively counters these threats by recognizing indicators such as authentication failures, self-sender patterns, and suspicious encoding techniques. The series emphasizes the importance of adaptive security platforms that leverage AI and machine learning to identify and mitigate evolving email threats across various service providers.
Jan 06, 2026
1,399 words in the original blog post.