A malicious invite looks like it's from a recruiter, a vendor, your boss, which is exactly why attackers moved there. The email carrying it is clean, no link, no attachment, because the payload sits in the event's Location or Description field. Both Google Workspace and M365 auto-add that event to the calendar by default, no click needed, so your filters never see it.
How to fix it:
→ Google Workspace: Admin Console → Calendar → Advanced settings → only add invites the user responds to
→ Microsoft 365: per mailbox via PowerShell (Set-CalendarProcessing -AutomateProcessing None)
→ Tell your team what these look like, since users can override both settings
→ Have a cleanup plan for events that already landed, compromised accounts still get through