Apple’s calendar service lets users send event invitations to outside contacts. By default, Apple sends these emails through noreply@email.apple.com on the user’s behalf. Attackers are now exploiting this feature by planting phishing URLs in the Notes field. Because the messages come from Apple’s infrastructure, spam filters and secure email gateways rarely flag them


