<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data Breach in AI Industry &#8211; cybernews.pt</title>
	<atom:link href="https://cybernews.pt/tag/data-breach-in-ai-industry/feed/" rel="self" type="application/rss+xml" />
	<link>https://cybernews.pt</link>
	<description></description>
	<lastBuildDate>Fri, 31 Jan 2025 10:56:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
	<item>
		<title>Wiz Research Discovers DeepSeek Database Vulnerability Exposing Sensitive Data</title>
		<link>https://cybernews.pt/wiz-research-uncovers-exposed-deepseek-database-leaking-sensitive-information/</link>
					<comments>https://cybernews.pt/wiz-research-uncovers-exposed-deepseek-database-leaking-sensitive-information/#respond</comments>
		
		<dc:creator><![CDATA[news room]]></dc:creator>
		<pubDate>Thu, 30 Jan 2025 15:56:48 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Tech Industry Trends]]></category>
		<category><![CDATA[AI Infrastructure Security]]></category>
		<category><![CDATA[AI Security Vulnerability]]></category>
		<category><![CDATA[AI System Vulnerabilities]]></category>
		<category><![CDATA[API Key Exposure]]></category>
		<category><![CDATA[ClickHouse Database Leak]]></category>
		<category><![CDATA[Cloud Database Security]]></category>
		<category><![CDATA[Cybersecurity in AI]]></category>
		<category><![CDATA[Data Breach in AI Industry]]></category>
		<category><![CDATA[DeepSeek Chat History Leak]]></category>
		<category><![CDATA[DeepSeek Data Leak]]></category>
		<category><![CDATA[DeepSeek Database Exposure]]></category>
		<category><![CDATA[DeepSeek Security Breach]]></category>
		<category><![CDATA[Sensitive Data Leak]]></category>
		<category><![CDATA[Unauthorized Database Access]]></category>
		<category><![CDATA[Wiz Research Cybersecurity Report]]></category>
		<guid isPermaLink="false">https://cybernews.pt/?p=595</guid>

					<description><![CDATA[The Discovery of the DeepSeek Data Leak Security researchers at Wiz identified an unauthenticated ClickHouse database accessible from: oauth2callback.deepseek.com:9000 dev.deepseek.com:9000 This database, completely open to the internet, contained highly sensitive information, including logs of user interactions, API keys, and backend configurations. (Source: Wiz Research) By using ClickHouse’s HTTP interface, researchers executed queries via a browser, [&#8230;]]]></description>
										<content:encoded><![CDATA[<h2><strong>The Discovery of the DeepSeek Data Leak</strong></h2>
<p>Security researchers at <strong>Wiz</strong> identified an <strong>unauthenticated ClickHouse database</strong> accessible from:</p>
<ul>
<li><code>oauth2callback.deepseek.com:9000</code></li>
<li><code>dev.deepseek.com:9000</code></li>
</ul>
<p>This database, completely open to the internet, contained <strong>highly sensitive information</strong>, including logs of user interactions, API keys, and backend configurations.</p>
<h4><img fetchpriority="high" decoding="async" class="alignnone wp-image-596 size-full" src="https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-scaled.webp" alt="" width="2560" height="1439" srcset="https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-scaled.webp 2560w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-300x169.webp 300w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-1024x576.webp 1024w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-768x432.webp 768w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-1536x863.webp 1536w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-2048x1151.webp 2048w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-747x420.webp 747w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-696x391.webp 696w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-1068x600.webp 1068w, https://cybernews.pt/wp-content/uploads/2025/01/1738181377-screenshot-2025-01-29-at-21-47-46-1920x1079.webp 1920w" sizes="(max-width: 2560px) 100vw, 2560px" /></h4>
<h4></h4>
<p><em>(Source: Wiz Research)</em></p>
<p>By using ClickHouse’s <strong>HTTP interface</strong>, researchers <strong>executed queries via a browser</strong>, extracting system logs, API secrets, and internal server details.</p>
<h2><strong>Security Risks and Consequences</strong></h2>
<p>The leak posed <strong>multiple security threats</strong>:</p>
<h3><strong>1. User Privacy Breach</strong></h3>
<p>The log entries contained <strong>plain-text chat histories</strong>, potentially exposing <strong>private conversations and user data</strong>.</p>
<h4></h4>
<h4><img decoding="async" class="alignnone wp-image-597 size-full" src="https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47.webp" alt="" width="2062" height="1150" srcset="https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47.webp 2062w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-300x167.webp 300w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-1024x571.webp 1024w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-768x428.webp 768w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-1536x857.webp 1536w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-2048x1142.webp 2048w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-753x420.webp 753w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-696x388.webp 696w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-1068x596.webp 1068w, https://cybernews.pt/wp-content/uploads/2025/01/1738181347-screenshot-2025-01-29-at-21-56-47-1920x1071.webp 1920w" sizes="(max-width: 2062px) 100vw, 2062px" /></h4>
<p><em>(Source: Wiz Research)</em></p>
<h3><strong>2. API Key Leakage</strong></h3>
<p>Attackers could use exposed API keys to <strong>access DeepSeek’s backend, impersonate users, or manipulate AI outputs</strong>.</p>
<p><img decoding="async" class="alignnone wp-image-598 size-full" src="https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00.webp" alt="" width="2056" height="1152" srcset="https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00.webp 2056w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-300x168.webp 300w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-1024x574.webp 1024w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-768x430.webp 768w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-1536x861.webp 1536w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-2048x1148.webp 2048w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-750x420.webp 750w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-696x390.webp 696w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-1068x598.webp 1068w, https://cybernews.pt/wp-content/uploads/2025/01/1738181493-screenshot-2025-01-29-at-22-05-00-1920x1076.webp 1920w" sizes="(max-width: 2056px) 100vw, 2056px" /></p>
<p><em>(Source: Wiz Research)</em></p>
<h3><strong>3. Infrastructure Vulnerabilities</strong></h3>
<p>The exposure allowed <strong>privilege escalation</strong> and the ability to <strong>execute queries directly on DeepSeek’s database</strong>.</p>
<h4><img loading="lazy" decoding="async" class="alignnone size-medium wp-image-599" src="https://cybernews.pt/wp-content/uploads/2025/01/Screenshot-2025-01-30-at-3.46.59 PM-300x161.png" alt="" width="300" height="161" srcset="https://cybernews.pt/wp-content/uploads/2025/01/Screenshot-2025-01-30-at-3.46.59 PM-300x161.png 300w, https://cybernews.pt/wp-content/uploads/2025/01/Screenshot-2025-01-30-at-3.46.59 PM-1024x548.png 1024w, https://cybernews.pt/wp-content/uploads/2025/01/Screenshot-2025-01-30-at-3.46.59 PM-768x411.png 768w, https://cybernews.pt/wp-content/uploads/2025/01/Screenshot-2025-01-30-at-3.46.59 PM-785x420.png 785w, https://cybernews.pt/wp-content/uploads/2025/01/Screenshot-2025-01-30-at-3.46.59 PM-696x373.png 696w, https://cybernews.pt/wp-content/uploads/2025/01/Screenshot-2025-01-30-at-3.46.59 PM-1068x572.png 1068w, https://cybernews.pt/wp-content/uploads/2025/01/Screenshot-2025-01-30-at-3.46.59 PM.png 1274w" sizes="auto, (max-width: 300px) 100vw, 300px" /></h4>
<p><em>(Source: Wiz Research)</em></p>
<h2><strong>Technical Details of the Exposure</strong></h2>
<p>Upon further inspection, researchers found that <strong>DeepSeek’s ClickHouse server</strong> was exposed via <strong>ports 8123 and 9000</strong>, making it <strong>publicly accessible without authentication</strong>.</p>
<h4><img loading="lazy" decoding="async" class="alignnone wp-image-600 size-full" src="https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23.webp" alt="" width="2060" height="1146" srcset="https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23.webp 2060w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-300x167.webp 300w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-1024x570.webp 1024w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-768x427.webp 768w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-1536x854.webp 1536w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-2048x1139.webp 2048w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-755x420.webp 755w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-696x387.webp 696w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-1068x594.webp 1068w, https://cybernews.pt/wp-content/uploads/2025/01/1738181402-screenshot-2025-01-29-at-21-51-23-1920x1068.webp 1920w" sizes="auto, (max-width: 2060px) 100vw, 2060px" /></h4>
<p><em>(Source: Wiz Research)</em></p>
<p>They ran a <strong>simple SQL command (<code>SHOW TABLES;</code>)</strong>, which <strong>listed multiple internal datasets</strong>, including <strong>log streams and operational metadata</strong>.</p>
<h4></h4>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-602 size-full" src="https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31.webp" alt="" width="1468" height="1018" srcset="https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31.webp 1468w, https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31-300x208.webp 300w, https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31-1024x710.webp 1024w, https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31-768x533.webp 768w, https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31-606x420.webp 606w, https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31-218x150.webp 218w, https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31-696x483.webp 696w, https://cybernews.pt/wp-content/uploads/2025/01/1738185067-screenshot-2025-01-29-at-23-09-31-1068x741.webp 1068w" sizes="auto, (max-width: 1468px) 100vw, 1468px" /></p>
<p><em>(Source: Wiz Research)</em></p>
<h2><strong>DeepSeek&#8217;s Response</strong></h2>
<p>Upon notification by <strong>Wiz Research</strong>, DeepSeek <strong>immediately secured the database</strong>, preventing further unauthorized access. However, <strong>no official statement</strong> has been made regarding <strong>whether any unauthorized breaches occurred before the fix</strong>.</p>
<h2><strong>Lessons for the AI Industry</strong></h2>
<p>This incident serves as a <strong>critical reminder</strong> that AI startups must <strong>prioritize security</strong> to prevent <strong>data leaks and infrastructure vulnerabilities</strong>.</p>
<h3><strong>Key Takeaways:</strong></h3>
<p><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Restrict Database Access:</strong> Use <strong>authentication</strong> and <strong>firewall rules</strong> to limit exposure.<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Encrypt Sensitive Data:</strong> Store <strong>API keys and chat histories securely</strong>.<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Monitor Infrastructure:</strong> Implement <strong>real-time threat detection</strong>.<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <strong>Regular Security Audits:</strong> Conduct <strong>penetration testing</strong> to prevent accidental exposure.</p>
<hr />
<h2><strong>Final Thoughts</strong></h2>
<p>AI companies are expanding <strong>faster than security measures can keep up</strong>. As <strong>AI becomes critical to businesses</strong>, ensuring <strong>secure data management practices</strong> is more important than ever.</p>
<p>This DeepSeek exposure highlights the <strong>real dangers of misconfigured AI infrastructure</strong>. Moving forward, <strong>companies must prioritize security</strong> to avoid similar breaches.</p>
<h3><strong>For More Details, Read the Full Wiz Report:</strong></h3>
<p><a href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak" target="_new" rel="noopener"><strong>Wiz Research Blog</strong></a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://cybernews.pt/wiz-research-uncovers-exposed-deepseek-database-leaking-sensitive-information/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
