ICalendar is a technology platform tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity November 28, 2025.
ICalendar is a calendar platform that uses the iCalendar (ICS) format to enable sharing and subscriptions across devices. Recent reporting indicates attackers are abusing calendar subscriptions and the iCalendar format to deliver phishing and malware, turning trusted calendar infrastructure into an attack surface with wide potential impact on synced devices.
Cyber threat actors are exploiting a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform, tracked as CVE-2025-12480. This vulnerability allows unauthorized administrative access and…
Threat actors are manipulating digital calendar subscription services to deliver phishing and malware content. This exploitation affects users of synced calendars, including platforms like Google Calendar and iCalendar,…
Hackers are increasingly using the iCalendar file format to bypass traditional email defenses and deploy malicious payloads. This new attack vector targets users who receive calendar invites, potentially compromising…
Hackers have exploited a critical unauthenticated access vulnerability (CVE-2025-12480) in Gladinet's Triofox file-sharing platform, allowing them to gain unauthorized administrative access and execute remote code. The…