Rule Name & Severity | Last Updated | Author | Types, Tactics & Capabilities | |
|---|---|---|---|---|
Link: Figma design deck with credential theft language | 12h ago Mar 4th, 2026 | Sublime Security | /feeds/core/detection-rules/link-figma-design-deck-with-credential-theft-language-87601924 | |
Brand Impersonation: Disney | 16h ago Mar 4th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-disney-bf90b8fb | |
Attachment: QR code with recipient targeting and special characters | 12d ago Feb 21st, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-qr-code-with-recipient-targeting-and-special-characters-fc9e1c09 | |
Cloud storage impersonation with credential theft indicators | 13d ago Feb 20th, 2026 | Sublime Security | /feeds/core/detection-rules/cloud-storage-impersonation-with-credential-theft-indicators-4c20f72c | |
Brand impersonation: Gusto | 15d ago Feb 18th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-gusto-54025c1c | |
Impersonation: Recipient organization in sender display name with credential theft image | 16d ago Feb 17th, 2026 | Sublime Security | /feeds/core/detection-rules/impersonation-recipient-organization-in-sender-display-name-with-credential-theft-image-6abfb20e | |
Brand Impersonation: PayPal | 20d ago Feb 13th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-paypal-a6b2ceee | |
Brand impersonation: USPS | 20d ago Feb 13th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-usps-28b9130a | |
Brand impersonation: TikTok | 21d ago Feb 12th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-tiktok-aaacc8b7 | |
Callback Phishing via Zoom comment | 22d ago Feb 11th, 2026 | Sublime Security | /feeds/core/detection-rules/callback-phishing-via-zoom-comment-8ec30881 | |
Brand impersonation: Fake Fax | 28d ago Feb 5th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-fake-fax-2a96b90a | |
Brand impersonation: File sharing notification with template artifacts | 1mo ago Jan 23rd, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-file-sharing-notification-with-template-artifacts-37d89611 | |
Brand impersonation: Quickbooks | 1mo ago Jan 15th, 2026 | Sublime Security | /feeds/core/detection-rules/brand-impersonation-quickbooks-4fd791d1 | |
Callback phishing via e-signature service | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/callback-phishing-via-e-signature-service-ed37b4fd | |
Attachment: QR code with credential phishing indicators | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-qr-code-with-credential-phishing-indicators-9f1681e1 | |
QR Code with suspicious indicators | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/qr-code-with-suspicious-indicators-04f5c34f | |
Suspicious invoice reference with missing or image-only attachments | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/suspicious-invoice-reference-with-missing-or-image-only-attachments-466c1680 | |
Credential phishing: DocuSign embedded image lure with no DocuSign domains in links | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/credential-phishing-docusign-embedded-image-lure-with-no-docusign-domains-in-links-dfe8715e | |
Callback phishing via Adobe Sign comment | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/callback-phishing-via-adobe-sign-comment-7eb4516d | |
Attachment: HTML smuggling - QR Code with suspicious links | 1mo ago Jan 12th, 2026 | Sublime Security | /feeds/core/detection-rules/attachment-html-smuggling-qr-code-with-suspicious-links-010e757d |