Sublime Core Feed

This repo contains open-source Rules for Sublime, a free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing.

Sublime Security
Last updated Apr 21st, 2026
Feed Source
Tactic or Technique is
Rule Name & Severity
Author
Last Updated
Labels
Anthropic Magic String in HTML
Sublime Security
2mo ago
Feb 9th, 2026
Attachment: Archive containing HTML file with file scheme link
Sublime Security
1mo ago
Mar 17th, 2026
Attachment: Archive contains DLL-loading macro
Sublime Security
3y ago
Dec 28th, 2023
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: CVE-2023-21716 - Microsoft Office Remote Code Execution Vulnerability
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
Sublime Security
1y ago
Mar 21st, 2025
Attachment: LNK with embedded content
@ajpc500
3mo ago
Jan 12th, 2026
Attachment: WinRAR CVE-2025-8088 exploitation
Sublime Security
3mo ago
Jan 12th, 2026
Attachment: ZIP file with CVE-2026-0866 exploit
Sublime Security
1mo ago
Mar 20th, 2026
Callback Phishing via Signable E-Signature Request
Sublime Security
3mo ago
Jan 12th, 2026
Callback phishing via SignFree e-signature request
Sublime Security
3mo ago
Jan 12th, 2026
Callback phishing via Xodo Sign comment
Sublime Security
3mo ago
Jan 12th, 2026
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
Sublime Security
3mo ago
Jan 12th, 2026
Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
Sublime Security
2y ago
Feb 15th, 2024
Mass campaign: Cross Site Scripting (XSS) attempt
Sublime Security
9mo ago
Jul 16th, 2025
Open redirect: City of Calgary
Sublime Security
11mo ago
May 23rd, 2025
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Sublime Security
4mo ago
Dec 10th, 2025