BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

A Researcher Joined a Government Meeting Nobody Invited Them To — Because an AI Notetaker Left the Door Open

Security researcher BobDaHacker didn’t need to break any encryption or exploit sophisticated malware to walk into a live government meeting uninvited. They just queried a database that had no

AnonymousCryptoCompass newsroom
August 16, 2026
4 min read
NEWS
A Researcher Joined a Government Meeting Nobody Invited Them To — Because an AI Notetaker Left the Door Open
CryptoCompass editorial visual for markets coverage.

Security researcher BobDaHacker didn’t need to break any encryption or exploit sophisticated malware to walk into a live government meeting uninvited. They just queried a database that had no lock on it at all.

What Went Wrong

Tl;dv is an AI meeting assistant, used by more than 2 million people, that joins Google Meet, Zoom, and Teams calls to record, transcribe, and summarize them. The core of the problem was a missing security rule on a single database collection: the app’s Firestore backend had no tenant isolation, meaning any authenticated tl;dv user — even a free-tier account — could query and retrieve meeting records belonging to every other customer on the platform, not just their own.

By the researcher’s count, the exposed collection held 181,874 meeting records across 84,312 unique users and 35,003 email domains. Exposed .gov domains traced back to government agencies in 23 different countries, including the US, Japan, and Ukraine, alongside university domains from institutions like UC Berkeley and corporate meetings from companies including HubSpot and Confluent.

It Wasn’t Just Old Recordings

The most alarming part wasn’t the historical data — it was live access. At any given moment, roughly 1,000 meetings in the exposed collection had a “recording” status, meaning their conference IDs functioned as active doorways into calls happening in real time. The researcher demonstrated this directly, grabbing a live conference ID and joining a Google Meet hosted by the Malaysian Ministry of Education’s training institute, where a presenter was addressing more than 150 participants with no idea an uninvited guest had entered. According to Dark Reading’s reporting, impersonating the tl;dv notetaker bot and requesting entry succeeded roughly 80% of the time — meeting hosts, accustomed to seeing bot participants join automatically, often approved entry without verifying which account was actually behind it.

Six Months of Silence

Perhaps the most damning detail: the vulnerability was responsibly disclosed to tl;dv in January 2026 and remained unfixed six months later, according to the researcher’s writeup and subsequent reporting from OffSeq’s threat intelligence team. That gap — half a year between private disclosure and public exposure — is the detail security researchers tend to flag hardest, since it turns a fixable engineering oversight into a prolonged, unaddressed exposure of sensitive data across governments, universities, and corporations worldwide.

A Pattern Bigger Than One Company

This isn’t an isolated incident. It follows a string of AI-product security failures disclosed in recent months, and it’s part of a broader trend security researchers have been tracking: as AI tools get embedded deeper into sensitive workflows — meetings, code repositories, internal documents — the access-control failures that would have been contained to one system in the past now expose data across an AI vendor’s entire customer base at once. That’s a similar dynamic to the AI agent sandbox failures covered elsewhere this month; see our roundup of AI agent safety incidents for how containment failures are showing up across the industry in different forms.

What It Means for Anyone Using AI Notetakers

If your organization uses an AI meeting assistant, it sits inside some of the most sensitive conversations you have — hiring decisions, board discussions, legal matters. That access is the entire value proposition, and it’s also the entire risk. In the wake of this disclosure, discussion among security-focused communities has increasingly turned toward local-first transcription tools that never send recordings to a third-party server at all, rather than cloud-hosted AI notetakers broadly.

What to Watch Next

Expect tl;dv to face continued scrutiny over its remediation timeline and whether affected organizations — particularly the government agencies whose meetings were exposed — pursue formal inquiries. More broadly, this incident is likely to accelerate enterprise security reviews of every AI tool with standing access to live meetings, documents, or communications, not just meeting notetakers specifically.

Sources: bobdahacker.com original disclosure, Dark Reading, OffSeq Threat Radar

Disclaimer: This content is meant to inform and should not be considered financial advice. The views expressed in this article may include the author’s personal opinions and do not represent Times Tabloid’s opinion. Readers are advised to conduct thorough research before making any investment decisions. Any action taken by the reader is strictly at their own risk. Times Tabloid is not responsible for any financial losses.

The post A Researcher Joined a Government Meeting Nobody Invited Them To — Because an AI Notetaker Left the Door Open appeared first on Times Tabloid.