Tl;dv: Over 180k meetings left wide open
colesantiago
359 points
121 comments
August 10, 2026
Related Discussions
Found 5 related stories in 43.3ms across 4,128 title embeddings via pgvector HNSW
- 24,650 internet-accessible BMCs leak password-derived hashes before login ilreb · 20 pts · July 28, 2026 · 49% similar
- 21,000 MCP servers exposed: the protocol reaches a security inflection point Wpnx330 · 11 pts · August 16, 2026 · 45% similar
- I accidentally logged hundreds of thousands of phone calls to military bases gavide · 490 pts · August 21, 2026 · 44% similar
- Security incident disclosure – July 2026 fdb · 24 pts · July 19, 2026 · 43% similar
- The Hacker's Renaissance (2025) yu3zhou4 · 120 pts · August 09, 2026 · 43% similar
Discussion Highlights (20 comments)
sktb
Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.
idiotsecant
Is this still active? I wouldn't mind spying on some meeting notes. Sounds fun.
Ekaros
I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.
SpaceL10n
Hmm, does Ukraine know that Russia is watching the Ministry of Digital Transformation's meetings?
palmotea
Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.
Aeroi
holy crap. how do you respond as CEO to this and not escalate to like priority #1? then kick the can for 6 months?
gyanchawdhary
This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk. Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026 PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice .. https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator) https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator) It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.
Oras
Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it. Wasn't a dating app exposed this year with same negligence or firebase security?
hluska
I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
seb1204
So did he email privacy@tldv.io? Why not? Maybe someone who understands it would read it.
Aeroi
"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. " oof
wkirby
I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem. The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
yellow_lead
Seems like they fixed this a few days ago: https://tldv.io/blog/our-thoughts-on-the-darkreading-com-art... But they try to play it off as though this were public data: > Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search. Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless. [1] https://tldv.io/features/security-commitment/
usamaasfar
I'm starting to believe Firebase is cursed at this point.
iJohnDoe
I think this is one of the few times public disclosure wasn’t a good idea. Some of these are government meetings and could put lives in danger. Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.
purplemoonx
It's hilarious how these companies handle security breaches. I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault . I had just started working there and found it in the first week. Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history. Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file). ----- I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
cube00
I saw an YouTuber the other day sharing their "day in the life" as an Amazon Software Engineer while promoting (as part of a paid sponsorship) the AI note taking feature of SoundCore headphones, claiming they now record their meetings and receive an AI summary at the end. I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.
nope1000
To forget tenant isolation on one endpoint is bad enough but to ignore it for 6 months is madness. I am at a SaaS company and our customers have such strict security requirements for us and that is for less confidential data.
fsuts
> He responded within minutes: "thank you! can you report it to our CTO and we will look at it immediately?" Why could he not speak to HIS ceo himself instead of asking Bob to
brohee
Now let's see if European users get their GDPR article 33 notification of the breach...