logo

Google Calendar Event Injection with MailSniper

ID: 88a2d90a-8b73-58e6-b5a7-2c58ac512975

STIX ID: report--88a2d90a-8b73-58e6-b5a7-2c58ac512975

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2017-11-01

Date Updated: 2026-04-27

Author: BHIS

...
...

Black Hills Information Security demonstrates an "Event Injection" issue in Google Calendar where an attacker can insert events into a victim's calendar (without sending email) and, using the Calendar API, mark attendees as 'accepted' to bypass user protections—enabling highly effective social-engineering/phishing. The post includes MailSniper PowerShell modules and detailed OAuth/API steps to perform the injection, discusses mitigations and settings, and provides a disclosure timeline with Google.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.