logo

Wiz researchers find sensitive DeepSeek data exposed to internet

ID: fc424ef9-ba66-5ba8-92e3-8b4ee85c041a

STIX ID: report--fc424ef9-ba66-5ba8-92e3-8b4ee85c041a

Feed Name: CyberScoop

Threat Score
68/100

Date Published: 2025-01-30

Date Updated: 2026-04-21

Author: Greg Otto

...
...

A publicly accessible ClickHouse database tied to AI company DeepSeek exposed over a million lines of sensitive internal data — including plaintext user chat logs, API keys and cryptographic secrets, server directory and operational metadata, and internal API references — discovered by Wiz researchers via open ports (8123 and 9000). DeepSeek secured the database after notification; researchers warn attackers could have extracted files or leveraged secrets for privilege escalation or corporate espionage, and separate Kela analysis highlights the R1 model's susceptibility to jailbreaks, underscoring broader security risks in rapidly deployed AI services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.