DeepSeek's Cybersecurity Woes: Exposed Database Raises Serious Concerns

3 Sources

Share

A cybersecurity firm discovers an unprotected DeepSeek database, exposing sensitive information and raising questions about the AI startup's security practices.

News article

DeepSeek's Unsecured Database Discovered

In a startling revelation, New York-based cloud security provider Wiz has uncovered a significant security lapse in DeepSeek's infrastructure. The Chinese AI startup, which recently made waves with its R1 AI model, left a ClickHouse database "completely open and unauthenticated," exposing sensitive information to potential attackers

1

.

Extent of the Exposure

The exposed database contained a wealth of sensitive information, including:

  1. Chat history
  2. Backend data
  3. API keys
  4. Operational metadata
  5. Plaintext passwords
  6. Local files
  7. Proprietary information

Wiz researchers claim that the database was so poorly protected that it allowed for full database control and privilege escalation within DeepSeek's environment, all without any authentication or defense mechanisms

2

.

Discovery and Implications

The security flaw was identified within minutes of Wiz's investigation into DeepSeek's cybersecurity resilience. The researchers found two open ports (8123 and 9000) associated with multiple public hosts, leading them to the exposed ClickHouse database

2

.

This discovery raises serious concerns about DeepSeek's security practices, especially given the company's rapid rise to prominence. The R1 AI model's sudden emergence and ability to compete with established players like OpenAI's ChatGPT and Meta's Llama had already drawn attention to the company

3

.

Broader Security Concerns

The incident has sparked wider discussions about DeepSeek's overall security:

  1. Data regulators from the UK, Italy, Ireland, and Australia have initiated inquiries into the company's practices.
  2. OpenAI has accused DeepSeek of copying its models.
  3. The US Navy has warned its members against using DeepSeek "in any capacity."
  4. The US National Security Council is investigating the security implications of the DeepSeek app.

AI security provider HiddenLayer claims that DeepSeek-R1 is vulnerable to various exploitation techniques, including jailbreak methods, prompt injections, and glitch tokens

1

.

Industry Impact

DeepSeek's security lapse comes at a critical time for the AI industry. The company's R1 model had already caused significant market disruption, leading to financial losses for several major tech players. This incident is likely to intensify scrutiny of AI startups and their security measures, potentially influencing investor confidence and regulatory approaches in the rapidly evolving AI sector.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo