Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Weaponized Invite Enabled Calendar Data Theft via Google Gemini

Weaponized Invite Enabled Calendar Data Theft via Google Gemini

Posted on January 20, 2026January 20, 2026 By CWS

A vulnerability in Google’s AI assistant Gemini allowed attackers to leak a sufferer’s non-public conferences through Google Calendar occasions, cybersecurity agency Miggo experiences.

The assault concerned making a malicious calendar occasion and sending an invitation to the focused consumer.

Utilizing a payload within the Calendar occasion’s description, the oblique immediate injection assault bypassed Calendar’s privateness controls to entry assembly knowledge and create misleading occasions with out consumer interplay.

The assault, Miggo explains, abused Calendar’s integration with Gemini, the place the AI features as an assistant, parsing all occasion knowledge, together with titles, instances, attendees, and descriptions.

“As a result of Gemini mechanically ingests and interprets occasion knowledge to be useful, an attacker who can affect occasion fields can plant pure language directions that the mannequin might later execute,” Miggo notes.

The cybersecurity agency found it was potential to create a calendar description that may instruct Gemini to summarize a sufferer’s conferences, together with non-public ones, write the information within the description of a brand new calendar occasion, and ship a innocent response to the consumer, to cover the malicious actions.Commercial. Scroll to proceed studying.

“The payload was syntactically innocuous, that means it was believable as a consumer request. Nonetheless, it was semantically dangerous when executed with the mannequin device’s permissions,” Miggo notes.

The payload was triggered when the consumer requested Gemini a query about their schedule, and resulted within the AI creating a brand new calendar occasion containing the consumer’s knowledge within the description. The brand new calendar occasion with the sufferer’s non-public assembly knowledge was accessible to the attacker, Miggo says.

Because the cybersecurity agency notes, the assault was profitable as a result of it relied on seemingly innocuous directions that any consumer would possibly give to Gemini. The context and intent made it malicious and harmful.

“This shift reveals how easy pattern-based defenses are insufficient. Attackers can cover intent in in any other case benign language and depend on the mannequin’s interpretation of language to find out the exploitability,” Miggo notes.

The cybersecurity agency reported the findings to Google, which confirmed the vulnerability and addressed it.

Associated: Vibe Coding Examined: AI Brokers Nail SQLi however Fail Miserably on Safety Controls

Associated: New ‘Reprompt’ Assault Silently Siphons Microsoft Copilot Information

Associated: ‘ZombieAgent’ Assault Let Researchers Take Over ChatGPT

Associated: Google Patches Gemini Enterprise Vulnerability Exposing Company Information

Security Week News Tags:Calendar, Data, Enabled, Gemini, Google, Invite, Theft, Weaponized

Post navigation

Previous Post: VoidLink Rewrites Rootkit Playbook with Server-Side Kernel Compilation and AI-Assisted Code
Next Post: Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers

Related Posts

Stealthy Attack Risks in Claude Code OAuth Tokens Revealed Stealthy Attack Risks in Claude Code OAuth Tokens Revealed Security Week News
Trusted Relationships: Emerging Threat in Email Security Trusted Relationships: Emerging Threat in Email Security Security Week News
Major US Banks Impacted by SitusAMC Hack Major US Banks Impacted by SitusAMC Hack Security Week News
CISA’s Ransomware Alerts in KEV: A Silent Update Challenge CISA’s Ransomware Alerts in KEV: A Silent Update Challenge Security Week News
US Calls Reported Threats by Pro-Iran Hackers to Release Trump-Tied Material a ‘Smear Campaign’ US Calls Reported Threats by Pro-Iran Hackers to Release Trump-Tied Material a ‘Smear Campaign’ Security Week News
Zero-Day Flaw in Palo Alto Firewalls Potentially Linked to China Zero-Day Flaw in Palo Alto Firewalls Potentially Linked to China Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark