Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      June 1, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      June 1, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      June 1, 2025

      How To Prevent WordPress SQL Injection Attacks

      June 1, 2025

      My top 5 must-play PC games for the second half of 2025 — Will they live up to the hype?

      June 1, 2025

      A week of hell with my Windows 11 PC really makes me appreciate the simplicity of Google’s Chromebook laptops

      June 1, 2025

      Elden Ring Nightreign Night Aspect: How to beat Heolstor the Nightlord, the final boss

      June 1, 2025

      New Xbox games launching this week, from June 2 through June 8 — Zenless Zone Zero finally comes to Xbox

      June 1, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Student Record Android App using SQLite

      June 1, 2025
      Recent

      Student Record Android App using SQLite

      June 1, 2025

      When Array uses less memory than Uint8Array (in V8)

      June 1, 2025

      Laravel 12 Starter Kits: Definite Guide Which to Choose

      June 1, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      My top 5 must-play PC games for the second half of 2025 — Will they live up to the hype?

      June 1, 2025
      Recent

      My top 5 must-play PC games for the second half of 2025 — Will they live up to the hype?

      June 1, 2025

      A week of hell with my Windows 11 PC really makes me appreciate the simplicity of Google’s Chromebook laptops

      June 1, 2025

      Elden Ring Nightreign Night Aspect: How to beat Heolstor the Nightlord, the final boss

      June 1, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»DeepSeek Security Scrutinized Amid Data Leaks, Jailbreaks

    DeepSeek Security Scrutinized Amid Data Leaks, Jailbreaks

    January 30, 2025

    DeepSeek security issues overshadow AI breakthrough

    DeepSeek’s sudden fame this week has come with a downside, as security and AI researchers have wasted no time probing for flaws in the AI model and its security.

    Claims that DeepSeek can be easily jailbroken appeared within hours of the AI startup’s rise to the center of the AI world, followed by reports of misinformation and inaccuracies found in the would-be rival to ChatGPT and other large language models (LLMs). Scammers wasted no time piling on, as Cyble detected a surge in fraud and phishing attempts aimed at exploiting DeepSeek’s sudden popularity.

    The latest DeepSeek security issue involves an exposed database discovered by Wiz Research, which added to concerns about the AI startup’s security and privacy controls.

    “The rapid adoption of AI services without corresponding security is inherently risky,” the Wiz researchers wrote. “This exposure underscores the fact that the immediate security risks for AI applications stem from the infrastructure and tools supporting them.”

    One downside to the security and misinformation issues surrounding DeepSeek is they threaten to detract from what appears to be a genuine breakthrough in AI efficiency that has attracted the attention of tech luminaries like Snowflake CEO Sridhar Ramaswamy.

    Database Leak Underscores DeepSeek Security Concerns

    The Wiz researchers said they discovered a publicly accessible ClickHouse database belonging to DeepSeek that allowed full control over database operations, including the ability to access internal data.

    The exposure includes more than “a million lines of log streams containing chat history, secret keys, backend details, and other highly sensitive information,” the researchers wrote. They immediately disclosed the issue to DeepSeek, which promptly secured the database.

    The researchers said they began investigating DeepSeek’s security posture for any vulnerabilities following the AI startup’s sudden fame. It didn’t take long to find significant issues.

    “Within minutes, we found a publicly accessible ClickHouse database linked to DeepSeek, completely open and unauthenticated, exposing sensitive data,” they said.

    The unsecured instance allowed for “full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world,” the researchers added.

    The data appeared to be recent, with logs dating from January 6, 2025. It included references to internal DeepSeek API endpoints and exposed plaintext logs that included chat history, API keys, backend details, and operational metadata.

    “This level of access posed a critical risk to DeepSeek’s own security and for its end-users,” the researchers said. “Not only an attacker could retrieve sensitive logs and actual plain-text chat messages, but they could also potentially exfiltrate plaintext passwords and local files along propriety information directly from the server.”

    An AI Breakthrough Clouded By Security and Misinformation Issues

    An unfortunate side effect of the widespread focus on DeepSeek’s security and accuracy issues is that the controversy threatens to obscure the fact that DeepSeek may well be the cost and efficiency breakthrough that the company claims to be.

    In a market full of hugely expensive, energy-inefficient GenAI models, a model that can compete while using 90% to 98% less power is very good news indeed. And DeepSeek has even open-sourced one of its models, giving others a chance to work with it.

    It remains to be seen whether DeepSeek’s security and misinformation issues could limit its adoption, but the window for getting it right may not be open long, as rivals like Alibaba are quickly following with their own claims of GenAI breakthroughs.

    And perhaps there’s a lesson here for other startups, whether they’re focused on AI or other technologies: Don’t let cybersecurity issues detract from your biggest breakthroughs.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleImproving MongoDB Queries by Simplifying Boolean Expressions
    Next Article Google: Over 57 Nation-State Threat Groups Using AI for Cyber Operations

    Related Posts

    Security

    New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora

    June 2, 2025
    Security

    Google AI Edge Gallery: Unleash On-Device AI Power on Your Android (and Soon iOS!)

    June 2, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    New ‘Cuckoo’ Persistent macOS Spyware Targeting Intel and Arm Macs

    Development

    Google AI Introduces LAuReL (Learned Augmented Residual Layer): Revolutionizing Neural Networks with Enhanced Residual Connections for Efficient Model Performance

    Development

    What happens if you have a non-TPM 2.0-chip PC but you want to run Windows 11?

    Development

    Introducing Gemini 2.0: our new AI model for the agentic era

    Artificial Intelligence

    Highlights

    Monitoring and optimizing website performance

    November 11, 2024

    Post Content Source: Read More 

    Wikileaks’ Julian Assange Released from U.K. Prison, Heads to Australia

    June 25, 2024

    Laravel Log Files Support in PhpStorm

    August 12, 2024

    Reimagining the Semantic Web

    August 1, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.