3 Sources
[1]
Deep trouble: Infosec firm finds a DeepSeek database 'completely open and unauthenticated' exposing chat history, API keys, and operational details
DeepSeek has been the name on everyone's lips this week, as the release of its R1 AI model spooked the tech market and caused significant financial losses for several major players. Concerns have been raised regarding the security of the Chinese AI startup and its models -- and if reports regarding
[2]
DeepSeek's Database Might Have Been Leaked Exposing Chat History
It is said to contain chat history, secret keys, and backend details DeepSeek's dataset might have suffered public exposure, claimed a cybersecurity research firm. As per a report, a publicly accessible ClickHouse database belonging to DeepSeek was discovered which allowed full control over its
[3]
DeepSeek report raises serious doubts about its security
The lack of security not only left sensitive data exposed, but also made it possible for outsiders to take full control of the database and escalate privileges within DeepSeek's environment. Chinese startup DeepSeek caught a lot of people off guard with the sudden emergence of its R1 AI model.
Share
Copy Link
A cybersecurity firm discovers an unprotected DeepSeek database, exposing sensitive information and raising questions about the AI startup's security practices.

In a startling revelation, New York-based cloud security provider Wiz has uncovered a significant security lapse in DeepSeek's infrastructure. The Chinese AI startup, which recently made waves with its R1 AI model, left a ClickHouse database "completely open and unauthenticated," exposing sensitive information to potential attackers
1
.The exposed database contained a wealth of sensitive information, including:
Wiz researchers claim that the database was so poorly protected that it allowed for full database control and privilege escalation within DeepSeek's environment, all without any authentication or defense mechanisms
2
.The security flaw was identified within minutes of Wiz's investigation into DeepSeek's cybersecurity resilience. The researchers found two open ports (8123 and 9000) associated with multiple public hosts, leading them to the exposed ClickHouse database
2
.This discovery raises serious concerns about DeepSeek's security practices, especially given the company's rapid rise to prominence. The R1 AI model's sudden emergence and ability to compete with established players like OpenAI's ChatGPT and Meta's Llama had already drawn attention to the company
3
.Related Stories
The incident has sparked wider discussions about DeepSeek's overall security:
AI security provider HiddenLayer claims that DeepSeek-R1 is vulnerable to various exploitation techniques, including jailbreak methods, prompt injections, and glitch tokens
1
.DeepSeek's security lapse comes at a critical time for the AI industry. The company's R1 model had already caused significant market disruption, leading to financial losses for several major tech players. This incident is likely to intensify scrutiny of AI startups and their security measures, potentially influencing investor confidence and regulatory approaches in the rapidly evolving AI sector.
Summarized by
Navi
[3]
1
Policy and Regulation

2
Technology

3
Technology
