this post was submitted on 08 Nov 2023
102 points (86.4% liked)

Technology

59197 readers
2873 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Hackers have reportedly found a way to use the Google Calendar as command & control (C2) infrastructure which could create quite a few headaches in the cybersecurity community.

you are viewing a single comment's thread
view the rest of the comments
[–] jimbolauski@lemmy.world 7 points 1 year ago (1 children)

They are encoding commands in calendar events there is not a vulnerability in Google calendar. After your device is compromised its commanded to subscribe to a calendar. Those events have commands. Since checking your calendar is a normal event unlike connecting to a nefarious server it becomes more difficult to discover.

[–] tsonfeir@lemm.ee 1 points 1 year ago

Is it? Everything is in their cloud. You’d think since they have all the data they might check it for malicious activity. I guess that’s not much of a priority for them because it’s hard to tell what’s malicious and what’s “Google”