Google Calendar Event Injection with MailSniper
ID: 88a2d90a-8b73-58e6-b5a7-2c58ac512975
STIX ID: report--88a2d90a-8b73-58e6-b5a7-2c58ac512975
Feed Name: Black Hills Infosec Blog
Black Hills Information Security demonstrates an "Event Injection" issue in Google Calendar where an attacker can insert events into a victim's calendar (without sending email) and, using the Calendar API, mark attendees as 'accepted' to bypass user protections—enabling highly effective social-engineering/phishing. The post includes MailSniper PowerShell modules and detailed OAuth/API steps to perform the injection, discusses mitigations and settings, and provides a disclosure timeline with Google.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
