Sublime Thoughts

November 3, 2025
Attack spotlight

ICS phishing: Stopping a surge of malicious calendar invites

ICS phishing: Stopping a surge of malicious calendar invites
Ahry Jeon
Product Manager
ICS phishing: Stopping a surge of malicious calendar invites
Brandon Murphy
Detection
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
November 3, 2025
Attack spotlight

ICS phishing: Stopping a surge of malicious calendar invites

Ahry Jeon
Product Manager
Brandon Murphy
Detection
October 28, 2025
Sublime news

Sublime raises $150M Series C to arm defenders for the post-LLM world

Josh Kamdjou
Co-founder & CEO
Ian Thiel
Co-founder & COO
October 23, 2025
Attack spotlight

Direct Send abuse on Microsoft 365: Just another failed authentication

Peter Djordjevic
Detection
October 16, 2025
Attack spotlight

Facebook credential phishing with job scams impersonating well-known companies

Bryan Campbell
Detection
October 14, 2025
Attack spotlight

Google Careers impersonation credential phishing scam with endless variation

Brandon Murphy
Detection
October 8, 2025
Attack spotlight

UK Home Office visa & immigration scam targets Sponsor Management System accounts

Bryan Campbell
Detection
October 2, 2025
Attack spotlight

Impersonated Evite and Punchbowl invitations used for credential phishing and malware distribution

Brandon Webster
Detection
Bryan Campbell
Detection
September 25, 2025
Machine learning

More than “plausible nonsense”: A rigorous eval for ADÉ, our security coding agent

Bobby Filar
Machine Learning
Dr. Anna Bertiger
ML Researcher
September 23, 2025
Attack spotlight

Fake Meta Ads Manager in App Store and TestFlight used to phish Meta ad accounts

Brandon Webster
Detection
Threat Research Team
Sublime
September 11, 2025
Sublime news

Meet ADÉ: The Autonomous Detection Engineer for email

AJ Williams
Product Manager
Aryan Luthra
ML Researcher
September 4, 2025
Attack spotlight

Callback phishing with online appointment abuse and distribution lists

Brandon Webster
Detection
August 28, 2025
Sublime news

Email bomb detection and prevention with Sublime

Dr. Anna Bertiger
ML Researcher
AJ Williams
Product Manager
August 26, 2025
Machine learning

Technical deep dive of NLU 3.0: Modular, multi-headed, with advanced synthetic training

Stefano Meschiari
ML Researcher
Aryan Luthra
ML Researcher
August 18, 2025
Sublime news

Everything old is new again: 3 trends from Black Hat USA, BSides LV, and DEF CON 33

Andrew Becherer
CISO
August 13, 2025
Sublime news

Sublime NLU 3.0: Faster, more accurate, future-proof defense against AI email attacks

Aryan Luthra
ML Researcher
Stefano Meschiari
ML Researcher
July 31, 2025
Attack spotlight

Multi-RMM attack: Splashtop Streamer and Atera payloads delivered via Discord CDN link

Josh "Soup" Campbell
Detection
Brandon Murphy
Detection
July 24, 2025
Threat detection

Keitaro TDS abused to deliver AutoIT-based loader targeting German speakers

Bryan Campbell
Detection
Brian Baskin
Threat Research
July 17, 2025
Attack spotlight

Phishing for Xfinity credentials with malicious Zoom Docs

Brandon Webster
Detection
July 2, 2025
Attack spotlight

Living Off Trusted Sites: Zoom service abuse to deliver credential phishing attack

Josh "Soup" Campbell
Detection
June 25, 2025
Attack spotlight

Using the X/Twitter link shortener (t.co) to hide an AITM credential phishing payload

Brandon Webster
Detection
June 18, 2025
Threat detection

Community Spotlight: Email Detection Rules built by the Sublime Community

Threat Detection Team
Sublime
June 12, 2025
Attack spotlight

AITM phishing with Russian infrastructure and detection evasion from a lapsed domain

Brandon Murphy
Detection
Threat Research Team
Sublime
May 29, 2025
Attack spotlight

Detecting an email-based ClickFix attack that delivers DCRat malware payload

Josh "Soup" Campbell
Detection
Brandon Murphy
Detection
May 15, 2025
No items found.

How ASA thinks: The technical architecture of Sublime’s Autonomous Security Analyst

Aryan Luthra
ML Researcher
May 8, 2025
Attack spotlight

ScreenConnect as malware via Canva abuse and Docusign impersonation

Brian Baskin
Threat Research
Brandon Webster
Detection
April 30, 2025
Attack spotlight

Figma abuse from compromised vendor used in credential theft attack

Sam Scholten
Detection
April 28, 2025
Sublime news

Key findings from the Q1 2025 Sublime Email Threat Research Report

Machine Learning Team
Sublime
Threat Detection Team
Sublime
April 23, 2025
Sublime news

Introducing ASA: The Autonomous Security Analyst for email

AJ Williams
Product Manager
Brian Wilcox
Product Manager
April 21, 2025
Sublime news

Welcoming Andrew Becherer as Sublime’s CISO

Josh Kamdjou
Co-founder & CEO
April 17, 2025
Sublime news

Elastic + Sublime: Adding email to your security and observability stack

AJ Williams
Product Manager
April 10, 2025
Threat detection

TROX Stealer: A deep dive into a new Malware as a Service (MaaS) attack campaign

Threat Research Team
Sublime
Brian Baskin
Threat Research
April 3, 2025
Attack spotlight

$500K financial fraud built on BEC, a domain lookalike, and a fake thread

Sam Scholten
Detection
April 1, 2025
Attack spotlight

Who are you trying to April Fool with that email scam?

Threat Detection Team
Sublime
March 27, 2025
Attack spotlight

Tycoon 2FA credential phishing with cloned internal employee login

Peter Djordjevic
Detection
March 20, 2025
Attack spotlight

Microsoft OAuth URL used as redirect to AITM credential phishing site

Brandon Murphy
Detection
March 13, 2025
Attack spotlight

Seeing both sides of a service abuse financial fraud using YOPmail disposable messages

Josh "Soup" Campbell
Detection
March 6, 2025
Attack spotlight

Base64-encoding an SVG attack within an iframe and hiding it all in an EML attachment

Sam Scholten
Detection
Brandon Murphy
Detection
February 25, 2025
Attack spotlight

Scripting Vector Grifts: SVG phishing with smuggled JS and adversary in the middle tactics

Brandon Murphy
Detection
Brandon Webster
Detection
February 18, 2025
Attack spotlight

Tax season email attacks: AdWind RATs and Tycoon 2FA phishing kits

Brandon Webster
Detection
Brandon Murphy
Detection
February 7, 2025
Machine learning

Email Topic Modeling: Simplifying detection with ML-powered granularity

Aryan Luthra
ML Researcher
January 29, 2025
Attack spotlight

Credential phishing Charles Schwab account holders with 2FA bypass

Aiden Mitchell
Detection
January 24, 2025
Sublime news

Enhanced message groups: Improving efficiency in email incident response

AJ Williams
Product Manager
January 7, 2025
Attack spotlight

Hiding a $50,000 BEC financial fraud in a fake email thread

Sam Scholten
Detection
December 19, 2024
Attack spotlight

Callback phishing via invoice abuse and distribution list relays

Brandon Murphy
Detection
December 17, 2024
Attack spotlight

B2B freight-forwarding scams on the rise to evade financial fraud crackdowns

Sam Scholten
Detection
December 12, 2024
Sublime news

Sublime raises Series B to… keep doing what we’ve been doing, but better

Josh Kamdjou
Co-founder & CEO
December 11, 2024
Threat detection

Xloader deep dive: Link-based malware delivery via SharePoint impersonation

Threat Research Team
Sublime
December 4, 2024
Threat detection

Detecting malicious AnonymousFox email messages sent from compromised sites

Sam Scholten
Detection
November 27, 2024
Attack spotlight

Talking phish over turkey

Brandon Murphy
Detection
Aiden Mitchell
Detection
November 20, 2024
Attack spotlight

Hidden credential phishing within EML attachments

Aiden Mitchell
Detection
November 14, 2024
Attack spotlight

Living Off the Land: Credential Phishing via Docusign abuse

Brandon Murphy
Detection
November 6, 2024
Attack spotlight

Living Off the Land: Callback Phishing via Docusign comment

Brandon Murphy
Detection
October 30, 2024
Attack spotlight

Adversarial ML: Extortion via LLM Manipulation Tactics

Threat Detection Team
Sublime
October 21, 2024
Machine learning

Combating GenAI Email Attacks with BERT LLM

Aryan Luthra
ML Researcher
Vivek Sharath
ML Engineer
September 26, 2024
Threat detection

Correlate Sublime Logs in Panther for Centralized Threat Detection

Robbie Adams
Sales Engineer
Jonathan Bunce
Software Engineer
August 30, 2024
Attack spotlight

Payroll Fraud via LLM-Generated Emails

Threat Detection Team
Sublime
July 2, 2024
Attack spotlight

Abusing Discord to deliver Agent Tesla malware

Threat Detection Team
Sublime
June 26, 2024
Attack spotlight

Fake invoice used to conduct $16,800 BEC attempt

Threat Detection Team
Sublime
June 10, 2024
Machine learning

Sublime Attack Score: Explainable, AI-backed threat analysis

Bobby Filar
Machine Learning
April 24, 2024
Sublime news

Announcing our $20M Series A to redefine email security

Josh Kamdjou
Co-founder & CEO
March 23, 2024
Threat detection

Gotta Catch 'Em All: Detecting PikaBot Delivery Techniques

Sam Scholten
Detection
October 4, 2023
Threat detection

QR Code Phishing: Decoding Hidden Threats

Sam Scholten
Detection
September 6, 2023
Threat detection

Call Me Maybe? The Rise of Callback Phishing Emails

Sam Scholten
Detection
April 18, 2023
Machine learning

Unmasking BEC attacks using Natural Language Understanding + MQL

Bobby Filar
Machine Learning
April 12, 2023
Threat detection

Detecting QakBot: WSF attachments, OneNote files, and generic attack surface reduction

Sam Scholten
Detection
March 30, 2023
Attack spotlight

Detecting Credential Phishing using Deep Learning + MQL

Bobby Filar
Machine Learning
March 24, 2023
Threat detection

Introduction to Message Query Language (MQL)

Ross Wolf
Engineering
February 22, 2023
Sublime news

Introducing Sublime: A new, open approach to email security

Josh Kamdjou
Co-founder & CEO

No Results Found

Oops! No Blog found for this category.

Get the latest

Sublime releases, detections, blogs, events, and more directly to your inbox.

Thank you!

Thank you for reaching out.  A team member will get back to you shortly.

Oops! Something went wrong while submitting the form.

Now is the time.

See how Sublime delivers autonomous protection by default, with control on demand.