Showing posts with label China. Show all posts
Showing posts with label China. Show all posts

Tuesday, February 4, 2025

Chinese AI DeepSeek Database Is Exposed


A Chinese company DeepSeek AI Database is exposed recently and over 1 million log lines and secret keys are leaked.


Choose your AI wisely. Choose your software wisely. Cheap software might end up costing you far more in the long run. While no choice is entirely risk-free, it's best to use software from countries that uphold strong democratic values, justice, and human rights. Your data is being collected and sold to third parties. This is almost unavoidable. If it must happen, it's (relatively) safer in the hands of democratic countries. (Consider it the lesser of two evils.)


https://bit.ly/4hmIqBQ


[Headlines]


"Buzzy Chinese artificial intelligence (AI) startup DeepSeek, which has had a meteoric rise in popularity in recent days, left one of its databases exposed on the internet, which could have allowed malicious actors to gain access to sensitive data.


The ClickHouse database 'allows full control over database operations, including the ability to access internal data,' Wiz security researcher Gal Nagli said.


The exposure also includes more than a million lines of log streams containing chat history, secret keys, backend details, and other highly sensitive information, such as API Secrets and operational metadata. DeepSeek has since plugged the security hole following attempts by the cloud security firm to contact them.


The database, hosted at oauth2callback.deepseek[.]com:9000 and dev.deepseek[.]com:9000, is said to have enabled unauthorized access to a wide range of information. The exposure, Wiz noted, allowed for complete database control and potential privilege escalation within the DeepSeek environment without requiring any authentication."


"Furthermore, DeepSeek's apps became unavailable in Italy shortly after the country's data protection regulator, the Garante, requested information about its data handling practices and where it obtained its training data..."


"Bloomberg, Financial Times, and The Wall Street Journal have also reported that both OpenAI and Microsoft are probing whether DeepSeek used OpenAI's application programming interface (API) without permission to train its own models on the output of OpenAI's systems, an approach referred to as distillation."

Wednesday, February 14, 2024

Chinese Hackers Infect Dutch Military Network


 

Why do you have to have to a solid vulnerability and patch management processes?

Well? The answer is quite easy: To avoid being hacked.


A part of Dutch military network was hacked by Chinese hackers using a FortiGate firewall vulnerability which was first detected in October 2022. (CVE-2022-42475 FortiOS SSL-VPN) The damage was limited due to the network segmantation in the network design.


https://bit.ly/3uwhqN7


"A Chinese cyber-espionage group breached the Dutch Ministry of Defence last year and deployed malware on compromised devices, according to the Military Intelligence and Security Service (MIVD) of the Netherlands."


"During the follow-up investigation, a previously unknown malware strain named Coathanger, a remote access trojan (RAT) designed to infect Fortigate network security appliances, was also discovered on the breached network."


"Even fully patched FortiGate devices may therefore be infected, if they were compromised before the latest patch was applied.


The malware operates stealthily and persistently, hiding itself by intercepting system calls to avoid revealing its presence. It also persists through system reboots and firmware upgrades."


"While the attacks weren't attributed to a specific threat group, MIVD linked this incident with high confidence to a Chinese state-sponsored hacking group and added that this malicious activity is part of a broader pattern of Chinese political espionage targeting the Netherlands and its allies."


"'For the first time, the MIVD has chosen to make public a technical report on the working methods of Chinese hackers. It is important to attribute such espionage activities by China,' said Defense Minister Kajsa Ollongren."


Wednesday, May 20, 2020

Is China a (Digital) Threat to Global Health?

According to me USA wants to "bite" China somehow and is trying to find some excuses for it. Nowadays the hot topic is "Covid-19" between them.

But care must be taken in case of the allegations are true, the health care organizations and pharmaceutical companies DO have to be careful against the cyber threats,
(News from cyberscoop.com)

"The Department of Homeland Security and the FBI on Wednesday blamed hackers linked with the Chinese government for attempting to steal U.S. research into a coronavirus vaccine,..."

"The U.S. agencies accused Chinese hackers as well as spies of trying to pilfer intellectual property and other information related to coronavirus treatments."

"Beijing has denied all of those allegations. “It is immoral to target China with rumors and slanders in the absence of any evidence,” Zhao Lijian, China’s Ministry of Foreign Affairs spokesperson, said Monday after media reports that the DHS-FBI statement was imminent."

"...The Trump administration has accused Beijing of misleading the world about the virus’s severity, which first emerged in the Chinese city of Wuhan. The White House has also labeled the illness the “Chinese virus” as the U.S. federal government has struggled to respond to an outbreak that has infected some 1.4 million people in the U.S."

"Tonya Ugoretz, deputy assistant director of the FBI’s cyber division, said last month that state-sponsored hackers were spying on U.S. organizations researching the coronavirus, but did not name a specific government. Last week, cybersecurity officials from DHS and Britain’s National Cyber Security Centre echoed that warning by saying that spies are targeting multiple global health care organizations and pharmaceutical companies worldwide."

"This would not be the first time that Chinese hackers have been mobilized in Beijing’s response to a public health threat. Faced with a surging cancer rate in China, hackers have repeatedly targeted organizations conducting cancer research, according  to cybersecurity company FireEye."

(For more: https://www.cyberscoop.com/coronavirus-vaccine-china-hacking-dhs-fbi/)