S3cur1ty101

S3cur1ty101 Modern Defense Need Modern Attack, Fixing a bug never fix others

03/07/2025

NO WAY VITRO, Inc. / PLDT Enterprise

25/02/2025
30/01/2025

DeepSeek Database Breach Exposes AI Chat Logs and API Secrets

A critical security vulnerability in DeepSeek, a rising Chinese AI startup, exposed an unprotected ClickHouse database containing over a million log entries, including chat histories, API keys, and backend service metadata. The publicly accessible database, hosted on multiple DeepSeek subdomains, allowed unauthorized users to execute SQL queries, retrieve plaintext passwords, and access proprietary information. Security researchers from Wiz identified the issue through routine reconnaissance and warned that attackers could have exploited the flaw to escalate privileges and compromise DeepSeek’s infrastructure.

The breach underscores the growing cybersecurity risks faced by AI startups as they scale rapidly. DeepSeek, known for its AI reasoning model DeepSeek-R1, competes with industry giants like OpenAI, but its failure to secure sensitive user data raises concerns about its security practices. The exposed database granted full access to backend systems without authentication, potentially allowing cybercriminals to manipulate stored data or extract confidential information. Security experts emphasized that such vulnerabilities highlight the urgent need for stricter access controls, encryption, and real-time monitoring in AI-driven platforms.

Following the disclosure by Wiz Research, DeepSeek promptly secured the exposed database, but the company has yet to release an official statement. The incident serves as a stark reminder that even the most innovative AI firms remain vulnerable to basic cybersecurity lapses. As AI technologies become integral to businesses and consumers, companies must prioritize security frameworks to safeguard user data, prevent unauthorized access, and maintain public trust in AI-driven ecosystems.

20/01/2025

The National Bureau of Investigation (NBI) is looking into an alleged data breach after an anonymous user from the Philippine IT Security Forum claimed to have leaked information from the NBI, officials said yesterday.

12/09/2024

https://www.bugbountyhunting.com/

BugBountyHunting.com collects writeups, resources and content related to bug bounty hunting to help you access them quickly. It's goal is to help beginners starting in web application security to learn more about bug bounty hunting.

Address

Manila

Alerts

Be the first to know and let us send you an email when S3cur1ty101 posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share