imperialdrive 17 hours ago

Yikes. Copy of TL;DR from the Reddit discussion:

Every single bit of data (that you wanted to back up using Active Backup for Microsoft 365) in your Microsoft 365 tenant, could have also been accessed by a malicious actor. The exact period for which this flaw existed for is unknown, but it was fixed by Synology after modzero disclosed it to them. Inspecting the setup process once, of any Synology Active Backup for Microsoft 365 install - gives you the master key to all M365 tenants that had authorised the Active Backup for Microsoft 365 enterprise app.

Source: https://old.reddit.com/r/msp/comments/1lm3z1e/flaw_in_synolo...