CourionAI
EN
Newsletter
← All news
security 2 min read

An AI Notetaker Left 181,874 Meetings Open to Anyone With a Free Account

A security researcher found that tl;dv, an AI meeting recorder used by over two million people, let any signed-in user list every meeting on the platform, including live calls they could join.

An empty meeting room seen through a door left ajar, with an oversized keyhole and light spilling out

A researcher who publishes as bobdahacker disclosed a flaw in tl;dv, an AI meeting recorder that joins your Google Meet, Zoom or Teams call and produces transcripts and summaries. One collection in the company’s database, the one holding meeting records, had no separation between customers. Any signed-in tl;dv user could list every meeting on the platform: 181,874 records from 84,312 users across 35,003 email domains.

Each record carried the creator’s email address, the conference ID, the provider and the recording status. A conference ID for a call currently marked as recording is a live room. The researcher watched the collection in real time, took an ID and walked into a Malaysian Ministry of Education call with more than 157 participants, and a second call where university students were screen-sharing their startup project. At any moment, he counted around 1,000 meetings in recording status. The exposed set included government domains from 23 countries and corporate names including HubSpot and Confluent.

The disclosure timeline is the uncomfortable part. He reported it on 28 January 2026. The CEO replied within minutes and pointed him at the CTO. The CTO never responded. Follow-ups in February, March and July went unanswered, and the researcher published on 4 August with the issue still open. The company’s security page lists SOC 2, GDPR and EU AI Act compliance badges and promises a response within 24 hours.

The lesson generalises well beyond one company. AI notetakers are unusually concentrated risk: they sit inside sales calls, job interviews, performance reviews and strategy sessions, which is precisely the material an attacker wants, and they are often adopted by one enthusiastic team member rather than procured by anyone who asks security questions. The specific bug here is a missing tenant isolation rule, a single setting that says users may only see their own rows. Every other collection at tl;dv had it. The meetings one did not.

What this means for you: if a bot named after a notetaking product has been joining your calls, it is fair to ask who runs it, where the recordings live and whether anyone reviewed it. Compliance badges describe process, not the state of a database, and they did not catch this. Practical steps that cost nothing: turn recording off for conversations involving salaries, health, legal matters or customer data, delete old recordings you no longer need, and if you are the person who introduced the tool to your team, check whether your account still holds meetings from people who have left. None of this requires you to swear off AI notetakers. It requires treating them like any other vendor holding your most sensitive conversations.

Sources

Source: https://bobdahacker.com/blog/tldv-hack

Next story

Deepseek Gave Away Its Agent Software and Raised API Prices on the Same Day

Deepseek Harness v0.1 is out under the MIT license, a free open alternative to Codex and Claude Code. On the same day the company announced steep API price increases, with cache hits jumping sixfold.

An open crate with harness straps and gears floating free out of it, while a fuel pump nozzle beside it drips into a bowl