Tech.Yahoo Surge in ICS Phishing via Calendar Invites Reaches 33,000%
Article Content
- •ICS phishing attacks via calendar invites surged by 33,000% from May to September 2026.
- •Attackers use legitimate services to bypass email security filters, targeting users in their inbox and calendar.
- •Victims are often tricked into downloading malicious RMM tools, leading to full system compromise.
Cybersecurity researchers from Sublime report a staggering 33,000% increase in ICS phishing attacks using calendar invites from May to September 2026. This method exploits legitimate services like Gmail to send calendar invites that bypass email security filters, exposing victims to attacks in both their inbox and calendar. The invites typically contain links to download malicious remote management and monitoring tools, such as ScreenConnect, allowing attackers to compromise endpoints and deploy further malware. The rise in these attacks has been exponential, with increases of 282% from May to June, 338% from June to July, and a projected 2,852% increase for September compared to August. Users are advised to scrutinize invites, verify senders, and treat ICS attachments with caution to defend against these threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…