Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Despite Spider-Man: Brand New Day’s success, the MCU is on shaky ground

    August 5, 2026

    Zenity Raises $125 Million in Series C Funding

    August 5, 2026

    Poolin owes wallet users $163.7M, and its $52M Texas sale can still unravel next week

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Despite Spider-Man: Brand New Day’s success, the MCU is on shaky ground
    • Zenity Raises $125 Million in Series C Funding
    • Poolin owes wallet users $163.7M, and its $52M Texas sale can still unravel next week
    • A common sugar may help cancer cells break free and spread
    • Nepal’s newest national parks drive tiger recovery, but new concerns arise
    • Murderous heat, an endangered food supply and no net zero: this is the life the radical right wants you to have | George Monbiot
    • US revokes Brazilian ambassador’s visa amid escalating diplomatic dispute
    • Arizona’s Democratic Governor Set to Pick a Republican Running Mate
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AI Notetaker Exposes Government, Corporate Video Calls

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 5, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A popular AI notetaker is allowing hackers to spy on any of its users’ conference calls.

    Tl;dv (Too Long; Didn’t View) is a meeting assistant that automatically joins, records, and transcribes video calls, unless its users specify otherwise. Its website boasts that it’s trusted by more than two million users worldwide, including at brand name companies like Salesforce, Forbes, and Cloudflare. In fact, its marketing may be modest. Tl;dv is used across dozens of government agencies, plus large universities and major organizations, across the globe. We know this now because a hacker got into its Google Firebase environment and lurked in some of those customers’ calls.

    In late January, application security whiz BobDaHacker figured out that with a little gumption, any tl;dv user can access the company’s back end Google Firebase environment. And from there, they can access any other users’ meeting information. BobDaHacker then used that information to identify and join calls hosted by government agencies and large organizations.

    Related:AI Harnesses Burst With Potential Exploit Opps

    After trying to report the issue to no avail, they notified Dark Reading about the issue. Dark Reading then tried reaching tl;dv through its press and marketing contacts, but received no reply. The issue is still live as of the time of publication.

    Vulnerabilities in the tl;dv Meeting Assistant

    When a user signs up for or signs into tl;dv, they’re assigned a session ID in the app’s back end Firebase system. This session ID affords them unusual power, though, to query the app’s Cloud Firestore database.

    It would be one thing if the user could only see the Firestore data associated with their account. Indeed, that’s almost entirely the case. Users cannot see other users’ transcripts, recordings, chats, etc., thanks to basic tenant isolation. The app has an Achilles’ heel, though: its “meetings” collection.

    Thanks to missing isolation for that one container, any tl;dv user can query every live conference call in the world into which tl;dv is invited. They can also grab some light metadata — like meeting timestamps and recording status — as well as its creator’s email address.

    When developers build apps with Firebase, “Firestore security rules are the first thing Google tells you to configure,” BobDaHacker tells Dark Reading. “The documentation walks you through it with examples. The default rules when you create a new Firestore database even warn you that they’re open and need to be locked down.”

    The fix would be just as effortless to implement. “A few lines of security rules that scope reads to the authenticated user’s organization,” they say.

    Related:OpenAI’s Rogue Model Claims More Victims Beyond Hugging Face

    Major Government, Corporate Conference Calls Exposed

    Obtaining meeting information doesn’t itself grant access to the meeting. Yet in their testing, BobDaHacker found a way into most tl;dv users’ meetings, most of the time.

    Some, such as a large Google Meet call hosted by the Malaysian Ministry of Education’s primary management training institute, were left open to the public. For private calls, BobDaHacker says, impersonating an AI notetaker like tl;dv and then requesting to join the meeting typically did the trick. They tell Dark Reading that they were allowed into meetings roughly 80% of the time.

    When they weren’t actively joining live calls, BobDaHacker was delving deeper into the app’s back end. There, they found more than 180,000 completed call records belonging to more than 80,000 users. These records documented meetings which, judging by the .gov domains exposed, were convened by governments of 23 different countries. They also included meetings hosted by large corporations — like HubSpot and Japan’s largest real estate developer, Mitsui Fudosan — and internationally acclaimed universities such as the University of California at Berkeley, the University of Tokyo, and others.

    Related:When AppSec Scanners Become a Supply Chain Attack Vector

    In a minority of cases, meeting IDs led to further data leakage. BobDaHacker took a sample of more than 27,000 meeting IDs, scraped them for publicly exposed data, and found that more than 1,000 left invitees’ emails and call transcripts on the open Internet. Among them were a meeting at Ukraine’s Ministry of Digital Transformation, and a meeting between the state government in São Paulo, Brazil and various conservation groups.

    The Risk in AI Notetakers

    Have you ever been on a conference call and half the participants are AI notetakers? Notetakers from people on the call, notetakers in place of people who couldn’t make the call, notetakers people forgot they still have running — they all seem to pop up these days.

    Few users give much thought to their AI notetakers, or especially anyone else’s, even though they’re near-ubiquitous and often wield high-level permissions. Most notetakers join and scribe all of a user’s meetings by default, unless users specify otherwise. They require access to video and audio, and, usually, related apps like calendars, contacts, etc.

    BobDaHacker warns that “the market is growing fast, with very little security scrutiny relative to what these tools have access to. Most people treat them like browser extensions they installed and forgot about. They’re a silent participant with deep access to your communication layer.”

    To limit the risk in running AI notetakers, they suggest two areas of focus. First, “Be aware that the bot is a participant. If you see an AI notetaker in a call you didn’t invite, that’s a red flag. In the Malaysian government meeting I joined, the tl;dv bot was right there in the participant list. 157 people saw it and nobody questioned it.”

    Most importantly, users should always configure their meeting privacy settings proportionate to the sensitivity of those meetings’ content and participants. “Out of roughly 70,000 meetings I checked through the REST API, only about 1,000 had public sharing enabled. Those users had their transcripts and invitee emails exposed. The other 69,000 were protected from content exposure by their privacy settings alone. Default to private,” they say.

    Internal Company Game Leaks Employee Data

    Besides leaking users’ meeting data, tl;dv is also leaking its own employees’ names and email addresses, through rather less conventional means.

    While exploring the company’s subdomains, BobDaHacker came across an internal and possibly vibecoded World Cup bracket game called “Too Long; Didn’t Score.” TL;DS’s application programming interface (API) endpoint for player data has no authentication, and a simple GET request yields all 42 employees who played. Just shy of half of those employees signed up with their guessable work emails, but the rest have unintentionally leaked their personal email addresses. Other leaked data includes chosen usernames — some creative, like “ChocoLoco” and “Super Duper CEO” — and the identity of the game’s admin, the company’s in-house blogger.

    The game remains live, weeks after the World Cup concluded.

    Calls corporate exposes government Notetaker video
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Zenity Raises $125 Million in Series C Funding

    Investigation exposes Cambodia’s illegal wildlife trade linked to transnational crime

    OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

    Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

    Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

    CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Despite Spider-Man: Brand New Day’s success, the MCU is on shaky ground

    August 5, 2026

    Zenity Raises $125 Million in Series C Funding

    August 5, 2026

    Poolin owes wallet users $163.7M, and its $52M Texas sale can still unravel next week

    August 5, 2026

    A common sugar may help cancer cells break free and spread

    August 5, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Despite Spider-Man: Brand New Day’s success, the MCU is on shaky ground

    August 5, 2026

    Zenity Raises $125 Million in Series C Funding

    August 5, 2026

    Poolin owes wallet users $163.7M, and its $52M Texas sale can still unravel next week

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.