Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2025-01-30 17:35:36| Engadget

The generative intelligence platform DeepSeek has set the world on fire this week, but with great popularity comes increased scrutiny. Analysts with Wiz Research have found a fairly substantial hole in the softwares security. The research shows that DeepSeek left one of its critical databases exposed. This means that whoever came across the database would be allowed access to more than one million records, including user data, system logs, API keys and even prompt submissions. The researchers also noted that they were able to find the database almost immediately, without too much scanning or probing. BREAKING: Internal #DeepSeek database publicly exposed Wiz Research has discovered "DeepLeak" - a publicly accessible ClickHouse database belonging to DeepSeek, exposing highly sensitive information, including secret keys, plain-text chat messages, backend details, and logs. pic.twitter.com/C7HZTKNO3p Wiz (@wiz_io) January 29, 2025 Usually when we find this kind of exposure, its in some neglected service that takes us hours to findhours of scanning, Nir Ohfeld, the head of vulnerability research at Wiz, told Wired. But this time, he said, here it was at the front door. Wiz Research says its possible that a nefarious actor could have used this security hole to access other DeepSeek systems, but the company admits it only performed the base minimum assessment. This was to confirm its findings without further compromising user privacy. There is also no evidence that anyone else found the database. Wiz staffers didnt exactly know how to disclose their findings, given that DeepSeek is both a new entity and based in China. Researchers eventually sent their findings to every email address and LinkedIn profile they could find. The database was locked down within 30 minutes of the mass email. DeepSeek isnt the only AI company that has experienced a serious security breach (or two.) A hacker was able to access OpenAIs internal messaging logs back in 2023 and a bug exposed personal information later that year. AI is the new frontier in everything related to technology and cybersecurity, Ohfeld said. Still we see the same old vulnerabilities like databases left open on the internet. As previously mentioned, DeepSeek took the world by storm in the past week or so. The disruptive AI model was allegedly created for just several million dollars. OpenAI runs through billions of dollars each year. This massive financial discrepancy sent the stock market into a tailspin, with many AI-adjacent stocks taking a plunge.This article originally appeared on Engadget at https://www.engadget.com/ai/security-researchers-found-a-big-hole-in-deepseeks-security-163536961.html?src=rss


Category: Marketing and Advertising

 

Latest from this category

13.03See Brad Pitt behind the wheel in the trailer for 'F1'
13.03Facebook creators can now monetize their Stories
13.03Nintendo's San Francisco store will open on May 15
13.03Apple reportedly plans to add a live-translation feature to AirPods
13.03Jeff Strain is suing investor NetEase, claiming internal gossip caused his game company to shut down
13.03Warhammer 40K: Space Marine 2 is unsurprisingly getting a sequel
13.03Disco Elysium is coming to Android mobile this summer
13.03Black Mirror is playing the hits in its season 7 trailer
Marketing and Advertising »

All news

14.03UK economy shrank unexpectedly in January
14.03Russia leans on cryptocurrencies for oil trade, sources say
14.03Bernstein sees no upside in Indian market despite slide
14.0319,826 km roads constructed so far under Bharatmala: Nitin Gadkari
14.03Magma sells general insurance business to Patanjali, DS Group
14.03Rupee ends at 87.01 vs US dollar, gains 20p from previous close
14.03Car sharing switches to electric to boost appeal
14.03Every McDonald's warned over staff sexual abuse
More »
Privacy policy . Copyright . Contact form .