Loading summary
A
Hey everyone, this is Casey for the Risky Business podcast. I'm talking today with Josh Kamju, the founder and CEO of Sublime Security. For those who don't know, Sublime is an adaptive AI powered cloud email security platform that combines best in class effectiveness with unprecedented visibility and control. It's good to see you, Josh.
B
Good to see you, Casey. Excited to be chatting, man.
A
Absolutely. Likewise. Likewise. So we were talking a little bit about some observations you guys are having on, on Bad Guy Land. Like one of the things I love about platforms Sublime is just the telemetry and visibility you'll get on. You know, what's happening out there in the, in the wide world of the, the Internet. So did you want to touch into that? What, what are you guys seeing?
B
Yeah, so the big thing that we've been seeing recently, really in the past couple months, I would say in September, it really picked up, we were seeing a little bit throughout the summer, is ICS phishing or malicious calendar invite phishing. And this is not a new technique by any means. I think we were chatting and you got one of these five years ago spammed onto your calendar. So it's not like anything dramatically new. But what we're seeing is a huge uptick in abuse of ICS phishing up to 100x now in terms of volume, it reminds me of, I don't know if you remember, like maybe a year or two ago, QR code phishing became a really big thing. And QR code phishing wasn't new at the time like it was. It's been done before. But I think it got commoditized or, you know, integrated into like some phishing as a service platforms or something. And I suspect that that's like similar to what's happening here. And it has been exploding in just the volume that we've been seeing and the variety.
A
Yeah, so talk a little bit more about that because when we were chatting about this ahead of time, a question I threw across was like, is this a new threat actor or is there some other reason for the explosion? You brought up the phishing as a service kit, but talk about some of the, I guess, intents or uses you see.
B
Yeah, so when we're talking about email security, there's various kinds of objectives that an attacker might have with sending their attacks. It might be like some examples of those are like bec or fraud to like, you know, steal money or something like that. Other examples are credential theft or callback phishing or malware ransomware delivery. So we've been seeing A variety of different intents and really just different kinds of campaigns that don't necessarily resemble, like, don't lead us to believe that this is a single actor. We're seeing credential theft, we're seeing callback. Phishing is like the most prevalent one that we've been seeing. We're seeing like even this, even like the old Lowe's dewalt scams, you know, like click here to win a thing. It's like we're seeing it. We're seeing all the traditional kinds of types of phishing, but now using calendar invites as a, as a delivery mechanism mechanism. And it's like pretty clever to be honest, just in terms of how it works.
A
Yeah. Do you want to explain how it works? Because, yeah, when we're talking about this, it's like, oh, that's that thing. You know, I've seen variations of this and been targeted by, by various variations of this over the years with different intents behind them. But do you want to talk through just how it works?
B
I guess, yeah. So with ICS phishing, the attacker is sending, generally you're sending an invite, and that invite, that calendar invite can generate an email, but it can also go directly to the user's calendar. And so when it goes directly to the user's calendar, it actually bypasses like if you have an inline email, a security solution or even like an email gateway. The gateway doesn't actually see the invite because it's going to the go. Going to the calendar, but it could see the, like if there's an email also associated with it. Like you ever, when you send an invite to an event, have you. You sometimes you get like a. Do you want to also like send the. Send an email with an update or things like that? And so that's how it gets delivered. It's like you're sending it and then depending on the settings of the organization or the individual user, it will get auto added to the user's calendar. And so even if you, from an email security perspective, you can see, let's say you can see the email, right? The calendar is like a totally separate permission. It's out of band. It has nothing to do with the email itself. And so when we started to see this, we can detect the, from the email layer, we could detect the invite from the email itself. But then the calendar invite was actually like still resident on the calendar because it requires like a totally set of permissions to go and remediate it off the calendar. And so this is why it's been such A big, I think attractive, ish, like attractive technique for attackers is because, like, if you're dealing with. Just if you're dealing with email security, maybe you can detect and prevent the email itself, but you also need to remediate the calendar invite. So when we started to see this, we were detecting and we can remediate the attack from the inbox. But then the calendar invite stayed. So now what we're doing, we actually just roll it out, rolled this out to. In. In beta for. For our customers is the ability to auto remediate the calendar invite too. And I think by the time that this episode drops, it might be fully released. We'll see. But yeah, that's been part of the. Just like what's been kind of unique about this particular attack?
A
Yeah, definitely, definitely. It's cool that you guys. I guess my question with that is how are people remediating that right now in the absence of a solution like you guys and what you've kind of built as a new feature here?
B
It is very painful. There really is not a good, like, you got to go full, like IR and it's like, it's very painful. So actually to this end, we're gonna open source a script, we're gonna open source a tool for the community to. Even if you're not using Sublime, in particular, if you're not using Sublime, where you can basically give it the message that it originated from, and then the tool will go and find the associated calendar invite and then remediate. So it's like a tool for ir, basically. So we're actually, we're working on that right now and we'll open source that soon.
A
That's dope. That's dope. Yeah. That's good guy. Sublime. Doing the thing, solving a hard problem. That's really interesting. So I guess on top of that, there's this ics, this particular type of attack, the particular set of techniques that are behind it, and the benefits for the attacker. And then really the explosion that you've seen in it over the past period of time. How often does that happen when you see a new technique or you see an old technique that's just been kicking around a little bit that suddenly blows up. Is that a common thing or.
B
This is. This is very common. Yeah. I mean, there's like, it happens to various degrees in terms of like, what kind of technique are we actually talking about in terms of evasions? We're seeing almost weekly. We're like maybe even more different types of evasions within, you know, different, different, like we're seeing there was another one where it's just like in the actual body of the message, it's, you know, different kinds of like ways of hiding the actual text from analysis, but making it visible to the user. And so, you know, we use computer vision for, you know, being able to pick those up. But the other big one, I mean, we actually talked about this on the. On the podcast was like SVG phishing was big, where you were basically smuggling like malicious code in SVGs which are very like SVG attachments, which generally you've got. Is actually pretty common in the email environment because they can be used as image files in people's signatures where they're responsive, they can like. And so that was being abused. So there's all kinds of new stuff that we constantly see.
A
And do you see. I mean, I guess that's a product of the folks that are writing these fishing kits or kind of writing these kind of collaborative tools. Crowdsourcing. Or is it them observing other techniques or what's your take on kind of how that works on the back end?
B
I think that. And actually this is a fun combo to have with you, because I am.
A
There's a crowd angle here.
B
Yeah, well, yeah, there's definitely a crowd angle here. And the way that I. And I'm sure that we think about some of this stuff similarly is how are. Is really thinking about what attacker incentives are because that drives their decision making. And you've got. In the email security world, the vast majority of the volume of attacks that you see are E crime. Like they are financially motivated in some way. It's not like it's not apt. Is not the. In terms of volume, obviously that's there too. But if you think about what E crime's objectives are, it's to maximize roi. That's literally their. Like their decree. That's the joke, right? Yeah. And so email has historically been. I mean, it still is like up there in terms of initial access vectors. Right. And now you've got adversaries starting to adopt LLMs and generative AI to automate in terms of the investment side of the ROI equation. That dramatically reduces the investment cost. Right. And so now you can. So they're like highly incentivized to adopt AI to make their attacks more scalable. Do the recon generate the phishing attack, find new bypasses. They're highly incentivized to do this and then send the attacks. So I think that's a big part of why we're seeing continued and even faster innovation from the adversary side, it's so much easier to do it now because you've got this. You can freaking throw it to an agent to do it for you.
A
Yeah. Nice. Which I guess lends itself to what you guys have gone and done to deploy AI on the defender side. So you can kind of keep that cycle time or at least attempt to keep pace with it. Right?
B
Yeah, I think, I think the way of the future in the defensive security world is going to be to fight fire with fire. I think it's like the only way that we will be able to keep up with adversary innovation. And we. So, like, that's been a big part of, just like, our thesis and how we've been developing our product and how we've integrated AI, I would say very thoughtfully, not just like slapping AI on there, but like, truly from the core, building it to. To enable, like, agents. And we released our first couple agents this past year and we've got. We've got a bunch more that we've got. We've got a lot that we're working on now.
A
Yeah, that's very cool. Very cool. Well, to that end, you've. You guys have had some pretty awesome announcements over, over the past week or so, seeing, you know, a lot of celebrations and hand clapping and high fives and all that kind of stuff on Twitter. Joined in on that because it's just been. It's been so much fun to watch the Sublime journey, like, you guys jumping in and just really trying to decompose the problem solution, fit down to its smallest possible pieces, and then kind of build those things well and now assemble them together. Do you want to talk about what you guys have announced last week?
B
Yeah. Yeah. I mean, really, I feel just a ton of great gratitude and excitement, really, for the future. We announced our Series C. So we raise 150 million in a Series C. And, you know, the Sublime's been growing quite, like, pretty crazily this past year. And we are just so grateful to have. We have incredible customers that we've been partnering with to build the product hand in hand. And it's a big part of how Sublime functions in the way it does today. And there's so much more that we want to do and continue to build. On top of the. We talked about, like, the agents, for example. This is like very much the beginning for us in terms of how we can apply AI to solve problems for our customers. And there's really like two. There's like two main buckets. There's really more than that. But the interesting Ones right now are like how there's like two main things that we do for our customers. There's reduce email born or email originating or email related risk. That's like the one bucket and number two is we save teams time and make them more efficient. And in the first bucket, really our first two agents help with both of these things. But the really cool thing around, like let's take like our most recent agent, our Autonomous Detection Engineer, as an example. So our ADE is our, is our Autonomous Detection Engineer can detect, triage and respond and adapt to attacker evolution. So like that's the really key part around how do we use AI to actually continuously improve such that we can, we can mitigate risk over time, especially as adversaries move faster. And then in the other bucket, asa, our Autonomous Security Analyst acts as a tier one, tier two analyst in the soc. So it just saves a ton of time and is actually really, really effective. We've heard from our customers that it's more effective than human analysts. So those are like the first two of a team of agents that we are building. And so this funding is largely in the majority of this funding is to feed right back into the product and to continue to build out these capabilities. So we're building a team of agents that's going to further our ability to improve efficacy over time and mitigate risk more and more and then identify other areas that teams are spending time like IR or whatever it might be, and build really thoughtful capabilities or agents to solve those problems as well. And the really powerful thing with Sublime is that we architected it in a way that just allows us to do that in a way that is transparent, is explainable, but also wildly effective because we've built essentially a computer language that an agent can speak. And so that's like at the, at the core of how Sublime is built. That's one of the things that makes it super effective at doing these things.
A
That's awesome. Well look, congrats again man. It's been, been great to catch up. It's been been too long. Hey, outside of getting the connect here, but really cool to hear what you guys are working on, what you're seeing and you know, congratulations again on the financing and all the progress. It's going to be super exciting to see what comes out of Sublime next.
B
Appreciate man, and always great to nerd out with you.
A conversation between host Casey (Risky Biz) and Josh Kamju (Founder & CEO, Sublime Security)
Date: November 2, 2025
This episode delves into the rapidly evolving landscape of email-based cyber threats, focusing on the resurgence and explosive growth of ICS (calendar invite) phishing attacks. Josh Kamju shares insider telemetry from Sublime Security’s platform, discusses the technical hurdles defenders face, and reveals how Sublime is leveraging AI-driven agents to automate both detection and remediation. The conversation also covers broader trends in attacker innovation and major company news, including Sublime’s recent $150M Series C funding.
[00:23-03:25]
“We’re seeing all the traditional kinds of types of phishing, but now using calendar invites as a delivery mechanism. And it’s pretty clever, to be honest, just in terms of how it works.” – Josh Kamju [02:50]
[03:25-06:20]
“The calendar is like a totally separate permission. It’s out of band. It has nothing to do with the email itself…this is why it’s been such a big, I think, attractive technique for attackers.” – Josh Kamju [04:33]
[05:53-07:17]
“In the absence of a solution like you guys…you’ve gotta go full IR and it’s very painful…We’re gonna open source a tool…where you can give it the message it originated from, and then the tool will go and find the associated calendar invite and then remediate.” – Josh Kamju [06:32]
[07:17-09:11]
[09:11-11:25]
“Now you’ve got adversaries starting to adopt LLMs and generative AI…to make their attacks more scalable…So I think that’s a big part of why we’re seeing continued and even faster innovation from the adversary side.” – Josh Kamju [10:33]
[11:25-13:00]
[13:00-16:48]
“This is like very much the beginning for us in terms of how we can apply AI to solve problems…We’re building a team of agents that’s going to further our ability to improve efficacy over time and mitigate risk more and more.” – Josh Kamju [15:19]
[16:48-17:06]
“Congratulations again on the financing and all the progress. It’s going to be super exciting to see what comes out of Sublime next.” – Casey [16:54]
ICS Phishing Explosion:
“It’s not like anything dramatically new. But what we’re seeing is a huge uptick in abuse of ICS phishing up to 100x now in terms of volume.” – Josh Kamju [00:46]
AI Arms Race:
“Adversaries starting to adopt LLMs and generative AI…to make their attacks more scalable…So I think that’s a big part of why we’re seeing continued and even faster innovation from the adversary side.” – Josh Kamju [10:33]
Automated Remediation Tooling:
“Even if you’re not using Sublime…you can give it the message that it originated from, and then the tool will go and find the associated calendar invite and then remediate.” – Josh Kamju [06:37]
AI-Driven Agents at Sublime:
“We released our first couple agents this past year … Our ADE can detect, triage and respond and adapt to attacker evolution … ASA acts as a tier one, tier two analyst in the SOC.” – Josh Kamju [13:59]
The episode offers a timely, expert view into evolving phishing techniques—especially the weaponization of calendar invites—and the challenge these bring to traditional security tools. Josh Kamju details both the attacker’s technical playbook and the practical challenges facing defenders. Sublime responds by automating and democratizing both detection and remediation, leveraging explainable AI agents designed to adapt at attacker speed. With new funding in hand and a roadmap oriented around true AI-driven security operations, Sublime is positioning itself at the leading edge of email threat defense.
For security teams, this episode is a primer on why phishing remains such a tough, quickly-changing adversary—and a look at the next-generation tools and strategies aiming to close the gap.