Security1 distinct publisher2 min readPublished
The release adds Proxmox VE, Nutanix AHV and Google Workspace coverage plus volume-level encryption at rest, while the anomaly detection and pre-restore malware scanning that catch a poisoned backup wait for an undated 2.1.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
In an encryption event the on-premises appliance sits inside the blast radius, which is what makes the Cloud DR path the substantive change in this release. A copy already held in Amazon S3 or Azure Blob Storage can be restored directly into an EC2 instance or an Azure VM with no round trip through on-premises hardware [5]. Synology describes that as significantly reducing recovery times and gives no measured figure, so the claim is architectural rather than benchmarked [12].
Cross-platform recovery is the other piece that ships now. A workload captured in one environment can be brought back in another, which Synology positions for both disaster recovery and workload migration [3]. It is one mechanism serving two different buyers, but the responder's interest is narrower than the migration pitch: the platform that was compromised is no longer the only place the workload can start.
The controls aimed at a contaminated backup are not in this build. Anomaly detection per backup version, tracking change rate, file modifications, mass deletions and entropy, with suspicious copies moved to quarantine for an administrator to review, is scheduled for APM 2.1 [7]. So is pre-restore malware scanning through Microsoft Defender, Bitdefender or ESET, with Auto Fallback restoring the latest clean version when the newest backup is infected [9]. Both features that address the case where the backup itself is the problem are held for 2.1 [11]. Synology calls 2.1 upcoming and names neither a date nor a price [10]. APM 2.0 itself is available across the DP Series appliances [13].
The security addition that did land is software-based volume-level encryption, scoped in Synology's own description to drive theft and hardware loss [6]. That is the stated threat model: a physical-loss control [15].
As market evidence the release is thinner than its feature list. Four of the five newly covered platforms are compute targets and the fifth is a SaaS suite [14]. One appliance vendor extending hypervisor coverage in a point release shows what Synology believes its buyers run [2], but it is a single vendor's read on its own customers, not an industry baseline. Jia-Yu Liu, who runs Synology's Data Protection Group, argues the case on cost: fragmented backup infrastructure raises spend and slows recovery, and APM 2.0 consolidates hybrid coverage into one console [1].
Deciding whether a restore is safe to run is the job left to 2.1, which Synology has not yet dated [10].
Ranked by verification strength, evidence, and original report placement.
Jia-Yu Liu, EVP of the Synology Data Protection Group, said managing fragmented backup infrastructure drives up costs and slows recovery, and that APM 2.0 enables organizations to safeguard their entire hybrid infrastructure through one centralized, scalable solution.
ActiveProtect Manager 2.0 extends protection to Amazon EC2, Azure VM, Proxmox VE, Nutanix AHV and Google Workspace.
Cross-platform recovery in APM 2.0 allows workloads to be backed up and restored across different environments, supporting both disaster recovery and workload migration.
ActiveProtect Vault now supports a wider range of Synology NAS, and Azure Blob Storage joins the supported copy and tiering targets.
Backups stored in Amazon S3 Storage or Azure Blob Storage can be restored directly into Amazon EC2 or Azure VM as a Cloud DR strategy, without routing through on-premises hardware.
APM 2.0 adds software-based storage encryption at the volume level, so backup data and system configurations remain inaccessible in the event of drive theft or hardware loss.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
GuardDuty says exfiltration and the patch is four hours out: revoke the sessions first1 distinct publisher
build
A key in the app binary is a bucket handover; presigned uploads also drop the proxy data bill1 distinct publisher
build
The nightly shutdown Lambda earns its postmortem on the morning restart1 distinct publisher
build
PyInstaller exits zero, then the real work starts: notarization traps that report success1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Everything rests on the vendor's release
Every fact in our coverage comes from Synology's own announcement as relayed by Help Net Security: the five new platform targets, the volume encryption, the 2.1 feature promises. No tester, customer or competitor corroborates any of it, and the single performance assertion carries no number, baseline or test condition.
Shipping to DP Series, unmeasured beyond that
General availability across the DP Series appliance range is the only adoption fact on offer. Nobody is quoted running 2.0, no deployment or upgrade count appears, and the new EC2 and Azure VM coverage has no named user behind it.
AI headline over an encryption release
The security story being sold is machine-learning anomaly detection and clean-restore fallback; the security feature that actually ships is volume encryption at rest, a defense against a stolen drive, while catching a backup an attacker has already poisoned is left to the still-undated 2.1 release. Add an unquantified 'significantly reducing recovery times' and the billing sits well ahead of the delivery.
Announcement-shaped coverage
Synology set the frame and this reporting keeps it: same section order, same executive quote, same weight on future AI capability. Help Net Security runs vendor product news as a standing category, so the piece is doing the job it exists for, but no customer, rival or independent tester appears in it to push back on the characterizations.
Firm on the feature list
What Synology announced, and which release each capability belongs to, is stated plainly enough that we can be confident about both. How the cross-environment restores behave, how the anomaly model reacts to ordinary backup churn, and what any of it costs are all outside what this reporting can tell us.