Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.
I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.
Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.
This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.
PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..
I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "
I'm very intrigued by AI note takers, but I'm absolutely unwilling to expose me or my clients to this exact problem.
The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
That’s a very fair concern. I completely understand why you’d want to avoid exposing yourself or your clients to that risk.
I also agree that diarization and speaker identification are probably one of the hardest parts to get right if the speakers aren’t separated correctly, even a great summary won’t fix it.
We’re looking into more privacy preserving approaches for MindNote (a multimodal AI Notetaker), including local/on-device processing, so this is really useful feedback. Thanks for sharing your experience!
But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
Besides the downplaying and obfuscation about the timeline on the first half, I find the inclusion of anthropic and zoom examples to be wild. Just spraying in all directions.
It's hilarious how these companies handle security breaches.
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
I saw an YouTuber the other day sharing their "day in the life" as an Amazon Software Engineer while promoting (as part of a paid sponsorship) the AI note taking feature of SoundCore headphones, claiming they now record their meetings and receive an AI summary at the end.
I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.
Well, on the plus side, SoundCore (Anker) are at least reputable enough (even though security teams would still want to review that!):
Under the security part, they do seem to at least be compliant with your typical security standards (HIPAA, SOC 2 Type 1, etc.) and claim that all data is deleted within 12 hours of transcription. So it isn't like the contents of your meeting are being siphoned off to some fly-by-night service, at least.
To forget tenant isolation on one endpoint is bad enough but to ignore it for 6 months is madness. I am at a SaaS company and our customers have such strict security requirements for us and that is for less confidential data.
> Why could he not speak to HIS ceo himself instead of asking Bob to
You can't expect a founder/CEO to spend 2 minutes relaying an email with critical security information to his own CTO, he's surely way too busy disrupting and pivoting and doubling down on product market fit.
I've know executives like this; at some level they seem to be self aware enough* to realize that any message that passes through them will be garbled beyond recognition and so actively encourage people to route around them.
* I know they're just saying the words a self aware person would say to give that impression, but it can be eerily convincing.
64 comments
[ 0.19 ms ] story [ 11.1 ms ] threadthen kick the can for 6 months?
Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026
PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..
https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)
https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)
It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.
Wasn't a dating app exposed this year with same negligence or firebase security?
oof
The solution (theoretically) is a purely local note taker, but I haven't found one that's any good. Tried meetily and others in the same vein, including briefly rolling my own. The breakdown in the pipeline seems to be reliable local diarization and speaker identification; even if the transcription is good, when speakers aren't accurately identified and speech isn't well grouped, there's no rescuing it in the summary step.
I also agree that diarization and speaker identification are probably one of the hardest parts to get right if the speakers aren’t separated correctly, even a great summary won’t fix it.
We’re looking into more privacy preserving approaches for MindNote (a multimodal AI Notetaker), including local/on-device processing, so this is really useful feedback. Thanks for sharing your experience!
But they try to play it off as though this were public data:
> Public sharing settings across AI and SaaS products have surfaced similar findings in recent months. Anthropic addressed exposed public artifacts across Claude and its MCP ecosystem via Google Search.
Also, interesting, they are SOC2 compliant [1], proving again that SOC2 is meaningless/useless.
[1] https://tldv.io/features/security-commitment/
Also, shame on the CEO for not making this an emergency and confirming it was fixed by the end of the day.
I once reported superadmin user/pass committed to github at a major YC backed background check company I worked at and everyone tried to make it seem like it was my fault.
I had just started working there and found it in the first week.
Anyway, had to show that it was committed by their main Staff engineer 2 years before I even worked there. For 2 years everyone's background check data in the United States that went through this thing - millions per year - thousands of Uber drivers, DoorDash, etc. all were viewable with no clearance. Anyone including overseas contractors, new hires, etc. could just login and check anyone's criminal history.
Reporting it was a disaster. They all tried to cover their asses, this huge drama and hand waving started. They tried to blame anyone and everyone. Eventually it was just AWS fault somehow (it wasn't, the Staff engineer was a dumbass, he committed it to a ruby seed file).
-----
I digress, the CTO didn't respond because he was more worried about how it would make him look. This industry is dead - the wrong people work in it.
I wonder how many companies realise these devices that appear as "headsets" are now funnelling their meetings into these new AI companies who are more worried about the World Cup then replying to security researchers.
Under the security part, they do seem to at least be compliant with your typical security standards (HIPAA, SOC 2 Type 1, etc.) and claim that all data is deleted within 12 hours of transcription. So it isn't like the contents of your meeting are being siphoned off to some fly-by-night service, at least.
https://www.soundcore.com/soundcore-work-ai-voice-recorder
Why could he not speak to HIS ceo himself instead of asking Bob to
You can't expect a founder/CEO to spend 2 minutes relaying an email with critical security information to his own CTO, he's surely way too busy disrupting and pivoting and doubling down on product market fit.
* I know they're just saying the words a self aware person would say to give that impression, but it can be eerily convincing.