DEPEPEK database exposed to chat and internal data
“It is quite shocking to build an AI model and leave the back wide open in terms of security,” says the independent security researcher Jeremiah Fowler, who did not participate in the WIZ study but specializes in opening databases. “This type of operational data and the ability of anyone with an internet connection has access to it and then manipulating it is a major risk to organization and users.”
Deepseek systems at first glance are designed to be very similar to Openai’s, Wedns’ researchers said on Wednesday, it may make it easier for new customers to switch to using Deepeek without difficulty. The entire Deepseek infrastructure seems to mimic that of Openai, they say, to detail like the shape of the API keys.
WIZ researchers say they don’t know if anyone else has found the open database before doing so, but it would not be surprising given how simple it is to find out. Fowler, the independent researcher, also notes that the vulnerable database will be “definitely” to be found quickly – if it wasn’t already – whether by other researchers or bad actors.
“I think this is a waking up for the wave of AI products and services that we will see in the near future and how seriously they accept cybersecurity,” he says.
Deepseek has made a global impact over the past week, with millions of people flowing to the service and pushing it to the top of Apple and Google stores. The resulting shock waves have deleted billions of stock prices of US AI companies and scared executives in companies all over the countryS On Wednesday sources at Openai said before Financial Times that he was looking at the estimated use of Ratgpt results by Deepseek to train his models.
At the same time, Depepeek is increasingly attracting the attention of lawmakers and regulators around the world, who have begun to ask questions about the company’s confidentiality policies, the impact of its censorship and whether its Chinese property provides fears of national security.
The data protection regulator in Italy has sent a Depepeek series of questions, asking the question of where he received his training data, whether the personal information of the people is included in this, and the legal basis of the company to use this information. AS Wired Italy reportedThe Deepseek app seems to be not available for download within the country after the questions sent.
Deepseek’s Chinese connections also seem to cause security concerns. At the end of last week, according to CNBC reportingThe US Navy has signaled to its staff, warning them not to use Deepseek services “In any ability.” The email stated that the Navy Navy members should not download, install or use the model and expressed concerns about “potential security and ethical” issues.
Despite HYPE, the data displayed show that almost all databases relying on cloud hosts can be vulnerable through simple security gaps. “AI is the new border in everything related to technology and cybersecurity,” says Opold of Wiz, “and yet we see the same old vulnerabilities as databases left open on the Internet.”