Twelve years ago, Google introduced a new feature to Google Calendar settings that allowed users to share their calendars with others. It's a great feature and invaluable in a corporate environment because it gives teams an easy way to collaborate. Google itself even touted the "make it pubic" feature of their calendar.
Unfortunately, as with most things, there's a potential downside. A security researcher named Avinash Jain discovered more than 8,000 publicly accessible Google Calendars, searchable via Google's own search engine. Many of these calendars contain sensitive information (which is bad enough), but worse, they allow any user to add new events that can cause real harm to the system hosting the calendar. Done via maliciously crafted events or poisoned links.
As Avinash Jain reports:
"I was able to access public calendars of various organizations leaking out sensitive details like their email IDs, their event name, event details, location, meeting links, zoom meeting links, google hangout links, and much, much more.
This is more of an intended setting by the users and intended behavior of the service. People can view anyone's public calendar, add anything to it without being shared with the calendar link.
Jain goes onto say that several calendars belonging to many of the top 500 Alexa company's employees were made public, which is certainly cause for concern.
This most recent finding adds to the chorus already warning of the dangers of calendar sharing. Just a few months ago, researchers from Kaspersky Lab discovered scammers abusing Google Calendar in a variety of ways. For example, there were phishing scams that contained poisoned links masquerading as google calendar event links.
Have all employees check their Google Calendar settings to not reveal more than you intended to.