{"id":259078,"date":"2025-11-03T15:57:08","date_gmt":"2025-11-03T15:57:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/259078\/"},"modified":"2025-11-03T15:57:08","modified_gmt":"2025-11-03T15:57:08","slug":"warning-as-google-and-microsoft-calendar-hack-surge-confirmed","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/259078\/","title":{"rendered":"Warning As Google And Microsoft Calendar Hack Surge Confirmed"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2025\/11\/1762185428_97_960x0.jpg\" alt=\"Google logo is seen on a smartphone with a Microsoft logo in the background.\" data-height=\"3333\" data-width=\"5000\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Beware malicious Google and Microsoft calendar invites.<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>Not all cybersecurity attacks involve <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/03\/microsoft-confirms-free-windows-10-security-updates---how-to-get-them\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/03\/microsoft-confirms-free-windows-10-security-updates---how-to-get-them\/\" target=\"_self\" aria-label=\"unsupported operating systems\" rel=\"nofollow noopener\">unsupported operating systems<\/a>, vulnerabilities <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/01\/new-warning-as-microsoft-windows-attacks-confirmed---no-fix-available\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/01\/new-warning-as-microsoft-windows-attacks-confirmed---no-fix-available\/\" target=\"_self\" aria-label=\"without a patch\" rel=\"nofollow noopener\">without a patch<\/a>, or <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/29\/new-android-warning-as-humanized-password-stealer-confirmed\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/29\/new-android-warning-as-humanized-password-stealer-confirmed\/\" target=\"_self\" aria-label=\"password-stealing malware\" rel=\"nofollow noopener\">password-stealing malware<\/a>. Many, it has to be said, come under the remit of social engineering, exploiting human weaknesses alongside a little <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/01\/paypal-attack-update-another-do-not-pay-warning-issued\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/01\/paypal-attack-update-another-do-not-pay-warning-issued\/\" target=\"_self\" aria-label=\"technical threat tomfoolery\" rel=\"nofollow noopener\">technical threat tomfoolery<\/a>. The latest such warning has come from Sublime Security after it \u201cobserved a significant influx in phishing attacks\u201d against users of Google Workspace and Microsoft 365 calendars. Here\u2019s what you need to know and do.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/03\/microsoft-sounds-windows-11-and-server-update-failure-alarm\/\" target=\"_blank\" aria-label=\"Microsoft Sounds Windows 11 And Server Update Failure Alarm\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/03\/microsoft-sounds-windows-11-and-server-update-failure-alarm\/\" rel=\"nofollow noopener\">ForbesMicrosoft Sounds Windows 11 And Server Update Failure AlarmBy Davey Winder<\/a>A Surge Of Malicious Google And Microsoft Calendar Invites <\/p>\n<p>It has been almost a year since I <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/18\/new-gmail-and-google-calendar-security-alert-how-to-stay-safe\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/18\/new-gmail-and-google-calendar-security-alert-how-to-stay-safe\/\" target=\"_self\" aria-label=\"last reported\" rel=\"nofollow noopener\">last reported<\/a> about the threat surface that is, erm, your calendar. Yet that threat has not gone away, and Google and Microsoft users are now being warned of a surge in attacks that use calendar invites as a method to evade security solutions and deliver their undoubtedly dangerous payloads. A <a class=\"color-link\" href=\"https:\/\/sublime.security\/blog\/ics-phishing-stopping-a-surge-of-malicious-calendar-invites\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/sublime.security\/blog\/ics-phishing-stopping-a-surge-of-malicious-calendar-invites\/\" aria-label=\"newly published report\">newly published report<\/a> by Ahry Jeon, a product manager, and Brandon Murphy, a threat detection engineer, both working at Sublime Security, warns that \u201cdepending on the settings of the target\u2019s calendar, even if the email message is automatically quarantined by an email security solution, the calendar entry often remains on the target\u2019s calendar.\u201d<\/p>\n<p>An .ics file is a calendar data format used to enable the sharing of events between calendar applications from the likes of Apple, Google, and Microsoft. It is a hugely popular format, not least thanks to the ability to automatically add invites to calendars from Google Workspace and Microsoft 365. In the latter, the security boffins warn, \u201cit will also bring attachments from the email into the invitation.\u201d Obviously, this provides an attacker with a double-whammy threat of the email and the invite to deliver a payload. Double-whammy threat, double the chance of success.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/31\/linkedin-dm-attack-warning---what-users-need-to-know\/\" target=\"_blank\" aria-label=\"LinkedIn DM Attack Warning \u2014 What Users Need To Know\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/31\/linkedin-dm-attack-warning---what-users-need-to-know\/\" rel=\"nofollow noopener\">ForbesLinkedIn DM Attack Warning \u2014 What Users Need To KnowBy Davey Winder<\/a><\/p>\n<p>The Sublime report provides a number of examples of this kind of attack, and I recommend reading it yourself to get up to speed with these. The bullet point summary is:<\/p>\n<p>ICS phishing in the body of a calendar entryICS phishing with a QR code in an attachmentICS phishing with attached HTML<\/p>\n<p>I have reached out to both Google and Microsoft regarding the report and the dangers of .ics phishing attacks for advice to users. In the meantime, Sublime offers the following suggestions for securing your calendars: In the Google Workspace Admin Console, go to Apps|Google Workspace|Calendar|Advanced settings and ensure the \u2018Add invitations to my calendar\u2019 option is set to \u2018Invitations from known senders\u2019 or \u2018Invitations users have responded to via email.\u2019 For Microsoft 365, use PowerShell commands to set AutomateProcessing to None and disable the \u2018Calendar Attendant\u2019 from automatically processing invites.<\/p>\n","protected":false},"excerpt":{"rendered":"Beware malicious Google and Microsoft calendar invites. SOPA Images\/LightRocket via Getty Images Not all cybersecurity attacks involve unsupported&hellip;\n","protected":false},"author":2,"featured_media":259079,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,120285,120284,48,42746,120287,120283,63,116293,120282,120286,61],"class_list":{"0":"post-259078","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-ca","9":"tag-calendar-hack","10":"tag-calendar-invite-attack","11":"tag-canada","12":"tag-google-calendar","13":"tag-ics-hack","14":"tag-ics-phsihing","15":"tag-microsoft","16":"tag-microsoft-365","17":"tag-microsoft-365-calendar","18":"tag-sublime-security","19":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/259078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=259078"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/259078\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/259079"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=259078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=259078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=259078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}