Ireland Britain Usa China Australia New York Italy Provident Discover Merit security Research reports Markets Ireland Britain Usa China Australia New York Italy

Deep trouble: Infosec firm finds a DeepSeek database 'completely open and unauthenticated' exposing chat history, API keys, and operational details

pcgamer.com

DeepSeek has been the name on everyone's lips this week, as the release of its R1 AI model spooked the tech market and caused significant financial losses for several major players.

Concerns have been raised regarding the security of the Chinese AI startup and its models—and if reports regarding an open database are to be believed, those claims may have some merit.

New York-based cloud security provider Wiz has issued an advisory claiming its research wing identified a publicly accessible ClickHouse database, belonging to DeepSeek, left «completely open and unauthenticated» (via The Register).

The database was said to have been discovered within minutes of the Wiz research team's investigation into DeepSeek's cybersecurity resilience and it contained «a significant volume of chat history, backend data, and sensitive information.» Worse still, the database was so completely unprotected that it was possible to gain full database control and privilege escalation from inside the environment, with no authentication or defence mechanism present.

A potential attacker could have easily obtained plaintext passwords, local files, and proprietary data with a simple SQL command.

Все новости дня

This page might use cookies if your analytics vendor requires them.