{"id":138458,"date":"2024-12-18T16:31:02","date_gmt":"2024-12-18T09:31:02","guid":{"rendered":"https:\/\/hotvideos24.online\/?p=138458"},"modified":"2024-12-18T16:31:02","modified_gmt":"2024-12-18T09:31:02","slug":"new-google-gmail-and-calendar-attack-warning-for-millions-of-users","status":"publish","type":"post","link":"https:\/\/hotvideos24.online\/?p=138458","title":{"rendered":"New Google Gmail And Calendar Attack Warning For Millions Of Users"},"content":{"rendered":"<p> <script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-3711241968723425\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-layout-key=\"-fb+5w+4e-db+86\"\r\n     data-ad-client=\"ca-pub-3711241968723425\"\r\n     data-ad-slot=\"7910942971\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><br \/>\n<\/p>\n<div>\n<figure class=\"embed-base image-embed embed-0\" role=\"presentation\"><figcaption><fbs-accordion><\/p>\n<p class=\"color-body light-text\" role=\"button\">Beware these Google Calendar and Gmail threats<\/p>\n<p><\/fbs-accordion><small>SOPA Images\/LightRocket via Getty Images<\/small><\/figcaption><\/figure>\n<p><em>Update, Dec. 18, 2024: This story, originally published Dec. 17 now includes a new attack warning from Check Point researchers about an ongoing threat that is targeting Google users via Calendar, Drawings, Gmail and Forms.<\/em><\/p>\n<p>Security threats surrounding Google applications, specifically Gmail and Calendar, are never far from the headlines, and for good reason: these platforms are a prime target for cybercriminals and hackers. But what are the latest threats you must be aware of, and how are they best mitigated? The latest, as revealed by Check Point security researchers, is using a combination of Google Calendar, Drawings, Forms and Gmail in the attack methodology. Here\u2019s everything you need to know to stay safe.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/16\/gmail-account-deletion-warning-act-now-to-save-your-email-in-2025\/\" target=\"_blank\" aria-label=\"Gmail Account Deletion Warning\u2014Act Now To Save Your Email In 2025\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/16\/gmail-account-deletion-warning-act-now-to-save-your-email-in-2025\/\"><span class=\"link-embed__info\"><span class=\"link-embed__provider\">Forbes<\/span><span class=\"link-embed__title\">Gmail Account Deletion Warning\u2014Act Now To Save Your Email In 2025<\/span><small class=\"link-embed__byline\">By <span class=\"link-embed__author\">Davey Winder<\/span><\/small><\/span><span class=\"link-embed__thumbnail-wrapper\"><span class=\"link-embed__thumbnail allow-inline-style\" style=\"background-image: url(https:\/\/specials-images.forbesimg.com\/imageserve\/64c375bd59f798618116a805\/960x0.jpg);\"\/><\/span><\/a><\/p>\n<h2 class=\"subhead-embed color-accent bg-base font-accent font-size text-align\">Check Point Researchers Warn Of Ongoing New Google Calendar Attack<\/h2>\n<p>Check Point has just published a report into <a href=\"https:\/\/blog.checkpoint.com\/securing-user-and-access\/google-calendar-notifications-bypassing-email-security-policies\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\" class=\"color-link\" title=\"https:\/\/blog.checkpoint.com\/securing-user-and-access\/google-calendar-notifications-bypassing-email-security-policies\/\" data-ga-track=\"ExternalLink:https:\/\/blog.checkpoint.com\/securing-user-and-access\/google-calendar-notifications-bypassing-email-security-policies\/\" aria-label=\"a new Google Calendar notification attack\">a new Google Calendar notification attack<\/a> that has been found bypassing email security policies. The attackers would appear to be determined to use the new attack methodologies uncovered by the researchers, with 2,300 attacks in a single two-week period, according to Check Point. This may not sound like a big deal, given that Google Calendar is used by 500 million people across 41 countries, but all attacks have to start somewhere, and this should not be a reason to dismiss the methods being employed by these threat actors. \u201cCyber criminals are modifying sender headers,\u201d Check Point researchers said, \u201cmaking emails look as though they were sent via Google Calendar on behalf of a known and legitimate individual.\u201d So far, at least 300 brands have been impersonated by the attackers in their drive to \u201cphish\u201d their victims.<\/p>\n<p><fbs-ad position=\"inread\" progressive=\"\" ad-id=\"article-0-inread\" aria-hidden=\"true\" role=\"presentation\"\/><\/p>\n<p>These attacks initially exploited the user-friendly features that are so useful to Google Calendar users to link to malicious Google Forms. However, the researchers said that \u201cafter observing that security products could flag malicious Calendar invites,\u201d the attackers have evolved their methodology to \u201calign with the capabilities of Google Drawings.\u201d Once at the form or drawing endpoint, another link is presented, often a fake reCAPTCHA or support button. The end goal is the same: payment fraud.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-8\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/17\/elon-musk-xmail-teaser-poses-new-threat-for-billions-of-gmail-users\/\" target=\"_blank\" aria-label=\"Elon Musk Xmail Teaser Poses New Threat For Billions Of Gmail Users\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/17\/elon-musk-xmail-teaser-poses-new-threat-for-billions-of-gmail-users\/\"><span class=\"link-embed__info\"><span class=\"link-embed__provider\">Forbes<\/span><span class=\"link-embed__title\">Elon Musk Xmail Teaser Poses New Threat For Billions Of Gmail Users<\/span><small class=\"link-embed__byline\">By <span class=\"link-embed__author\">Davey Winder<\/span><\/small><\/span><span class=\"link-embed__thumbnail-wrapper\"><span class=\"link-embed__thumbnail allow-inline-style\" style=\"background-image: url(https:\/\/specials-images.forbesimg.com\/imageserve\/67600ab5a986fcdbf646700b\/960x0.jpg);\"\/><\/span><\/a><\/p>\n<h2 class=\"subhead-embed color-accent bg-base font-accent font-size text-align\">Google Calendar Security Cyber Attacks\u2014Change Gmail Options To Mitigate<\/h2>\n<p>A recent alert from Stu Sjouwerman, the chief executive officer and founder of human risk management specialists KnowBe4, warned of an ongoing attack campaign that is targeting Google users by way of the abuse of Google Calendar invites. \u201cAttackers only need your Gmail address to send you an invite,\u201d <a href=\"https:\/\/blog.knowbe4.com\/alert-your-users-about-calendar-scams-and-what-to-do-about-them\" rel=\"nofollow noopener noreferrer\" target=\"_blank\" class=\"color-link\" title=\"https:\/\/blog.knowbe4.com\/alert-your-users-about-calendar-scams-and-what-to-do-about-them\" data-ga-track=\"ExternalLink:https:\/\/blog.knowbe4.com\/alert-your-users-about-calendar-scams-and-what-to-do-about-them\" aria-label=\"Sjouwerman said\">Sjouwerman said<\/a>, \u201cand the event will be placed in your calendar by default.\u201d This is far from the first time that such tactics have been used by threat actors. Indeed, I have written about just such <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2019\/09\/17\/exclusive-1-billion-google-calendar-users-are-one-click-away-from-privacy-disaster\/\" target=\"_self\" class=\"color-link\" title=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2019\/09\/17\/exclusive-1-billion-google-calendar-users-are-one-click-away-from-privacy-disaster\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2019\/09\/17\/exclusive-1-billion-google-calendar-users-are-one-click-away-from-privacy-disaster\/\" aria-label=\"abuse of Google Calendar invites\" rel=\"noopener\">abuse of Google Calendar invites<\/a> at Forbes.com for some years now. However, it\u2019s worth reading a <a href=\"https:\/\/www.popsci.com\/google-calendar-spam-what-to-do\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\" class=\"color-link\" title=\"https:\/\/www.popsci.com\/google-calendar-spam-what-to-do\/\" data-ga-track=\"ExternalLink:https:\/\/www.popsci.com\/google-calendar-spam-what-to-do\/\" aria-label=\"Popular Science report\">Popular Science report<\/a> referenced by Sjouwerman to get up to date with the latest threat tactics.<\/p>\n<p>Mitigating these attacks is relatively simple, according to Sjouwerman: head to the Google Calendar settings and the event settings, switch the automatically add invitations option to only show invitations to which I have responded. That\u2019s step one. Step two involves going to the events from Gmail option and unchecking automatically add events from Gmail to my calendar. Doing so will, however, impact functionality as genuine automatic invites will also be disabled. It\u2019s that old choice between usability and security again; only you can decide which takes priority.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/15\/googles-new-security-warning-for-android-chrome-users-what-to-do-now\/\" target=\"_blank\" aria-label=\"Google\u2019s New Security Warning For Android Chrome Users\u2014What To Do Now\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/15\/googles-new-security-warning-for-android-chrome-users-what-to-do-now\/\"><span class=\"link-embed__info\"><span class=\"link-embed__provider\">Forbes<\/span><span class=\"link-embed__title\">Google\u2019s New Security Warning For Android Chrome Users\u2014What To Do Now<\/span><small class=\"link-embed__byline\">By <span class=\"link-embed__author\">Davey Winder<\/span><\/small><\/span><span class=\"link-embed__thumbnail-wrapper\"><span class=\"link-embed__thumbnail allow-inline-style\" style=\"background-image: url(https:\/\/specials-images.forbesimg.com\/imageserve\/676070088680c47483d48d02\/960x0.png);\"\/><\/span><\/a><\/p>\n<p>The calendar spam on display in the recent campaigns is annoying but generic phishbait,\u201d Sjouwerman said, warning that \u201cit\u2019s easy to imagine how this technique could be used in more targeted and sophisticated attacks.\u201d<\/p>\n<p>Google advises users with an eligible Google Workspace subscription can use email verification for appointment schedules to prevent unwanted appointments. \u201cYou can ask guests to verify their email address before they schedule an appointment in Google Calendar\u201d <a href=\"https:\/\/support.google.com\/calendar\/answer\/11902347\" rel=\"nofollow noopener noreferrer\" target=\"_blank\" class=\"color-link\" title=\"https:\/\/support.google.com\/calendar\/answer\/11902347\" data-ga-track=\"ExternalLink:https:\/\/support.google.com\/calendar\/answer\/11902347\" aria-label=\"Google said\">Google said<\/a>, \u201cThis is only required for users who aren&#8217;t signed in to a Google Account.\u201d More information regarding <a href=\"https:\/\/support.google.com\/calendar\/answer\/10366125\" rel=\"nofollow noopener noreferrer\" target=\"_blank\" class=\"color-link\" title=\"https:\/\/support.google.com\/calendar\/answer\/10366125\" data-ga-track=\"ExternalLink:https:\/\/support.google.com\/calendar\/answer\/10366125\" aria-label=\"Google Calendar privacy options can be found here\">Google Calendar privacy options can be found here<\/a>.<\/p>\n<p>\u201cWe recommend users enable the known senders setting in Google Calendar,\u201d a Google spokesperson said, \u201cThis setting helps defend against this type of phishing by alerting the user when they receive an invitation from someone not in their contact list and\/or they have not interacted with from their email address in the past.\u201d<\/p>\n<p>Similar warnings have recently been made about <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/10\/18\/hackers-avoid-google-chrome-security-features-in-new-attack-researchers-warn\/\" target=\"_self\" class=\"color-link\" title=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/10\/18\/hackers-avoid-google-chrome-security-features-in-new-attack-researchers-warn\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/10\/18\/hackers-avoid-google-chrome-security-features-in-new-attack-researchers-warn\/\" aria-label=\"ClickFix attackers using fake Google Meet pages\" rel=\"noopener\">ClickFix attackers using fake Google Meet pages<\/a>, so the interactive meetings attack surface is certainly opening up and something to be aware of.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/07\/gmail-takeover-hack-attack-google-warns-you-have-just-7-days-to-act\/\" target=\"_blank\" aria-label=\"Gmail Takeover Hack Attack\u2014Google Says You Have 7 Days To Act\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/07\/gmail-takeover-hack-attack-google-warns-you-have-just-7-days-to-act\/\"><span class=\"link-embed__info\"><span class=\"link-embed__provider\">Forbes<\/span><span class=\"link-embed__title\">Gmail Takeover Hack Attack\u2014Google Says You Have 7 Days To Act<\/span><small class=\"link-embed__byline\">By <span class=\"link-embed__author\">Davey Winder<\/span><\/small><\/span><span class=\"link-embed__thumbnail-wrapper\"><span class=\"link-embed__thumbnail allow-inline-style\" style=\"background-image: url(https:\/\/specials-images.forbesimg.com\/imageserve\/64e7031f115ba4a1a14af6bb\/960x0.jpg);\"\/><\/span><\/a>\n<\/div>\n<p><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-3711241968723425\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-layout-key=\"-fb+5w+4e-db+86\"\r\n     data-ad-client=\"ca-pub-3711241968723425\"\r\n     data-ad-slot=\"7910942971\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><br \/>\n<br \/><div data-type=\"_mgwidget\" data-widget-id=\"1660802\">\r\n<\/div>\r\n<script>(function(w,q){w[q]=w[q]||[];w[q].push([\"_mgc.load\"])})(window,\"_mgq\");\r\n<\/script>\r\n<br \/>\n<br \/><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/18\/new-gmail-and-google-calendar-security-alert-how-to-stay-safe\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Beware these Google Calendar and Gmail threats SOPA Images\/LightRocket via Getty Images Update, Dec. 18, 2024: This story, originally published Dec. 17 now includes a new attack warning from Check &hellip; <a href=\"https:\/\/hotvideos24.online\/?p=138458\" class=\"more-link\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8630],"tags":[],"class_list":["post-138458","post","type-post","status-publish","format-standard","hentry","category-technology","entry"],"_links":{"self":[{"href":"https:\/\/hotvideos24.online\/index.php?rest_route=\/wp\/v2\/posts\/138458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hotvideos24.online\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hotvideos24.online\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hotvideos24.online\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hotvideos24.online\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=138458"}],"version-history":[{"count":0,"href":"https:\/\/hotvideos24.online\/index.php?rest_route=\/wp\/v2\/posts\/138458\/revisions"}],"wp:attachment":[{"href":"https:\/\/hotvideos24.online\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=138458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hotvideos24.online\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=138458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hotvideos24.online\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=138458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}