Our teammate Leonid had a look on Synology. He discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of organizations that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data such as all Teams channel messages. #synology #disclosure #modzero #infosec
https://modzero.com/en/blog/when-backups-open-backdoors-synology-active-backup-m365/