#modzero
catch a glimpse of us holding our annual “state of the zero” meetup - to wrap our heads around all of IT and us.

we also took a boat trip, ate too many sweets, touched some grass, saved the world, had a barbecue and a drink or two…💓

#modzero #infosec #itsecurity #captainitswednesday
September 28, 2025 at 6:01 PM
🚨 Security Alert: Synology Active Backup for Microsoft 365 Vulnerability 🚨

Modzero discovered a critical vulnerability in Synology’s "Active Backup for Microsoft 365" (ABM) that exposed sensitive cloud data.
July 6, 2025 at 11:01 AM
OAuth is hard and we often find security flaws, but this is next level. Kudos to Modzero.
Teammate Leonid discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of orgs that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data like Teams channel messages. 🤓
#synology #disclosure #modzero
modzero.com/en/blog/when...
When Backups Open Backdoors: Accessing Sensitive Cloud Data via
modzero.com
June 29, 2025 at 10:24 AM
Teammate Leonid discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of orgs that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data like Teams channel messages. 🤓
#synology #disclosure #modzero
modzero.com/en/blog/when...
When Backups Open Backdoors: Accessing Sensitive Cloud Data via
modzero.com
June 29, 2025 at 8:01 AM
Gmail allows more than the „+“, from the excellent modzero folks:

Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes / modzero

„The charset that was allowed boiled down to +&|`${}#*.“

https://modzero.com/en/blog/beyond-the-at-symbol/
February 1, 2025 at 8:04 AM
it wasn't me. 🫶
#38c3
December 29, 2024 at 7:28 PM
i am going on a trip
and i am taking with me ...

💓 #38C3
December 18, 2024 at 8:23 AM
Just reinstalled a #Windows10 "Enterprise" VM -- amazed how much bloat they ship by default.
Also, must-have: https://github.com/modzero/fix-windows-privacy
GitHub - modzero/fix-windows-privacy: Fix Windows 10 Privacy
Fix Windows 10 Privacy. Contribute to modzero/fix-windows-privacy development by creating an account on GitHub.
github.com
December 7, 2024 at 8:45 PM