Chinese AI Chatbot DeepSeek Exposes Sensitive User Data in Major Security Breach
Chinese AI chatbot DeepSeek exposed over a million lines of unsecured log entries, including sensitive user data and API secrets, raising major privacy concerns.
Summary of DeepSeek Security Breach
- Major Security Failure: Chinese AI chatbot DeepSeek exposed a database containing over a million lines of log entries, including chat history and secret keys, due to lack of authentication.
- Discovery by Wiz Research: Security researchers from Wiz Research found the publicly accessible ClickHouse database, which allowed full control over internal data operations.
- Sensitivity of Exposed Data: The exposed data included chat logs, backend information, API secrets, and operational details, raising significant privacy concerns.
- Disclosure Issues: Wiz Research had difficulty finding a security contact at DeepSeek, leading them to spam multiple email addresses to disclose the vulnerability.
- Immediate Action by DeepSeek: Once informed, DeepSeek secured the database.
- Ongoing Investigations: The company is under investigation in both Europe and the US over privacy and national security concerns.
- App Store Removal in Italy: DeepSeek has been removed from the App Store in Italy following actions by the country’s privacy watchdog. This move may be replicated in other countries.
- Market Impact: AAPL stock increased by 3% on news of DeepSeek's issues, while other tech stocks declined.
Latest News
Gaming
Silksong Prepares for the Deep: Final Major Patch Arrives Ahead of Expansion
47 minutes ago
Apple
MacBook Neo Defies Expectations by Outperforming Enterprise Cloud Servers
2 hours ago
Nvidia
Jensen Huang Defends DLSS 5: AI Enhancements Won't Kill Creative Control
2 hours ago
Warhammer
Warhammer’s New Black Library App Unlocks a Galaxy of Free Stories
2 hours ago
Apple
iPhone 18 Pro: The Next Big Design Revolution Revealed
4 hours ago
Windows
Microsoft Sneaks 10 Essential Upgrades Into New Windows 11 Insider Build
4 hours ago