

there are some admin endpoints that are authenticated using any local IP, but the method they use allows spoofing the IP so those endpoints become accessible essentially without authentication
there were some other issues to do with unauthenticated enumeration and playback of content i believe too
which they handled about as well as you can: prompt and clear notification without trying to pass the buck
the potential of a data breach is just a fact of life with any SAAS product - bugs happen… and it’s exactly the SAAS part of the product that makes the invites/login/aggregation of servers so smooth