TITLE: AI Notetaker tl;dv Left 181,000 Business Meetings Exposed DATE: 2026-08-16 COMPANY: tl;dv TOPIC: AI Security SUMMARY: AI meeting notetaker tl;dv exposed 181,874 recorded meetings from 84,312 users across 35,003 domains due to a missing database security rule. Any authenticated user on the platform could read every other organisation's meeting records and join live calls uninvited. The flaw was reported to tl;dv in January 2026 but remained unpatched for more than six months before the researcher went public. WHAT CHANGED: Security researcher bobdahacker discovered that tl;dv's cloud database contained a critical misconfiguration. When a user authenticated to tl;dv, the platform issued a Firebase token that granted read access to the meetings collection across all tenants on the service, not just the user's own organisation. Most collections in the database enforced correct account boundaries. The meetings collection was the exception. The researcher first reported the issue to tl;dv on January 28, 2026, through standard responsible disclosure. After repeated follow-ups over six months with no fix applied, the researcher published the findings publicly in August 2026. The exposure went beyond archived transcripts. The researcher was able to identify active sessions and join live meetings uninvited by requesting access as an AI notetaker bot. This approach succeeded in approximately 80 percent of tested cases. Live sessions entered during testing included a government education institute meeting with more than 150 participants and a corporate session in which product development work was being shared on screen. The technical cause was a single missing configuration rule in Firestore. The fix required no architectural change, only a security rule that scoped collection access to the authenticated user's tenant. The six-month delay between disclosure and public reporting meant businesses across 35,003 domains were exposed without any notification or opportunity to respond. WHY IT MATTERS: AI meeting notetakers are now present in the most sensitive conversations most businesses have. They attend client negotiations, legal briefings, HR discussions, and strategy sessions where no written record would otherwise exist. The tl;dv flaw required no hacking skill to exploit. Any paying subscriber could have accessed meeting records from any other organisation on the platform using normal authentication. A six-month gap between responsible disclosure and public reporting signals that many AI SaaS vendors have not built security operations practices commensurate with their growth or the sensitivity of the data they hold. The researcher accessed live government and corporate meetings in real time, not just stored archives. This means conversations were observable as they happened. Businesses across 35,003 domains were affected. This is mainstream SMB adoption territory, not a niche user base. The flaw was a single missing configuration line, which makes the extended exposure period difficult to justify and raises questions about the maturity of the vendor's security review processes. DAVID & GOLIATH ANALYSIS: Most business operators assume that signing up for a reputable AI SaaS tool means their data is protected by default. The tl;dv breach is a direct challenge to that assumption. The platform had users across more than 35,000 domains, was integrated into three of the most widely used video conferencing platforms in the world, and was trusted with some of the most sensitive conversations those businesses had. A single missing database rule made all of it readable to any other subscriber. For operators running organisations of 10 to 200 people, the exposure is asymmetric. A large enterprise typically has a security team that reviews vendor contracts, assesses data handling architectures, and monitors breach disclosures. A smaller business usually relies on the vendor's reputation and assumes the product is safe. That assumption is now a documented liability. The practical shift is to treat AI tool procurement the same way you would treat hiring a new team member with access to everything. Ask where data is stored, how it is isolated from other customers, what the vendor's incident response process looks like, and whether they operate a formal responsible disclosure programme. If a vendor cannot answer those questions clearly in writing, that difficulty is itself the answer. Start this review with your meeting notetaker, then extend it to every other AI tool with access to your calendar, email, or internal communications. RELEVANT SYSTEMS: Secure AI Brain SOURCE URL: https://davidandgoliath.ai/daily-ai-briefing/tldv-ai-notetaker-breach-181000-meetings-exposed FEED URL: https://davidandgoliath.ai/daily-ai-briefing/feed --- Published by David & Goliath | https://davidandgoliath.ai Daily AI Briefing: one AI development per day, decoded for business operators. This is a structured companion file optimised for LLM retrieval and citation.