DeepSeek's Cybersecurity Woes: Exposed Database Raises Serious Concerns

3 Sources

A cybersecurity firm discovers an unprotected DeepSeek database, exposing sensitive information and raising questions about the AI startup's security practices.

News article

DeepSeek's Unsecured Database Discovered

In a startling revelation, New York-based cloud security provider Wiz has uncovered a significant security lapse in DeepSeek's infrastructure. The Chinese AI startup, which recently made waves with its R1 AI model, left a ClickHouse database "completely open and unauthenticated," exposing sensitive information to potential attackers 1.

Extent of the Exposure

The exposed database contained a wealth of sensitive information, including:

  1. Chat history
  2. Backend data
  3. API keys
  4. Operational metadata
  5. Plaintext passwords
  6. Local files
  7. Proprietary information

Wiz researchers claim that the database was so poorly protected that it allowed for full database control and privilege escalation within DeepSeek's environment, all without any authentication or defense mechanisms 2.

Discovery and Implications

The security flaw was identified within minutes of Wiz's investigation into DeepSeek's cybersecurity resilience. The researchers found two open ports (8123 and 9000) associated with multiple public hosts, leading them to the exposed ClickHouse database 2.

This discovery raises serious concerns about DeepSeek's security practices, especially given the company's rapid rise to prominence. The R1 AI model's sudden emergence and ability to compete with established players like OpenAI's ChatGPT and Meta's Llama had already drawn attention to the company 3.

Broader Security Concerns

The incident has sparked wider discussions about DeepSeek's overall security:

  1. Data regulators from the UK, Italy, Ireland, and Australia have initiated inquiries into the company's practices.
  2. OpenAI has accused DeepSeek of copying its models.
  3. The US Navy has warned its members against using DeepSeek "in any capacity."
  4. The US National Security Council is investigating the security implications of the DeepSeek app.

AI security provider HiddenLayer claims that DeepSeek-R1 is vulnerable to various exploitation techniques, including jailbreak methods, prompt injections, and glitch tokens 1.

Industry Impact

DeepSeek's security lapse comes at a critical time for the AI industry. The company's R1 model had already caused significant market disruption, leading to financial losses for several major tech players. This incident is likely to intensify scrutiny of AI startups and their security measures, potentially influencing investor confidence and regulatory approaches in the rapidly evolving AI sector.

Explore today's top stories

NVIDIA Unveils Major GeForce NOW Upgrade with RTX 5080 Performance and Expanded Game Library

NVIDIA announces significant upgrades to its GeForce NOW cloud gaming service, including RTX 5080-class performance, improved streaming quality, and an expanded game library, set to launch in September 2025.

CNET logoengadget logoPCWorld logo

9 Sources

Technology

3 hrs ago

NVIDIA Unveils Major GeForce NOW Upgrade with RTX 5080

Space: The New Frontier of 21st Century Warfare

As nations compete for dominance in space, the risk of satellite hijacking and space-based weapons escalates, transforming outer space into a potential battlefield with far-reaching consequences for global security and economy.

AP NEWS logoTech Xplore logoeuronews logo

7 Sources

Technology

19 hrs ago

Space: The New Frontier of 21st Century Warfare

OpenAI Tweaks GPT-5 to Be 'Warmer and Friendlier' Amid User Backlash

OpenAI updates GPT-5 to make it more approachable following user feedback, sparking debate about AI personality and user preferences.

ZDNet logoTom's Guide logoFuturism logo

6 Sources

Technology

11 hrs ago

OpenAI Tweaks GPT-5 to Be 'Warmer and Friendlier' Amid User

Russian Disinformation Campaign Exploits AI to Spread Fake News

A pro-Russian propaganda group, Storm-1679, is using AI-generated content and impersonating legitimate news outlets to spread disinformation, raising concerns about the growing threat of AI-powered fake news.

Rolling Stone logoBenzinga logo

2 Sources

Technology

19 hrs ago

Russian Disinformation Campaign Exploits AI to Spread Fake

AI in Healthcare: Patients Trust AI Medical Advice Over Doctors, Raising Concerns and Challenges

A study reveals patients' increasing reliance on AI for medical advice, often trusting it over doctors. This trend is reshaping doctor-patient dynamics and raising concerns about AI's limitations in healthcare.

ZDNet logoMedscape logoEconomic Times logo

3 Sources

Health

11 hrs ago

AI in Healthcare: Patients Trust AI Medical Advice Over
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo