Wiz researchers found publicly reachable, unauthenticated ClickHouse services tied to DeepSeek at oauth2callback.deepseek.com and dev.deepseek.com on ports 8123 and 9000. The database reportedly contained more than one million log records, including user chat histories, API secrets, backend details, and operational metadata in plaintext; its configuration also permitted full database control and created potential paths to privilege escalation or local-file access. DeepSeek secured the exposed database after responsible disclosure.
Separately, a researcher reported that a Filevine non-production demo instance exposed a Box API token through an unauthenticated recommendation endpoint identified in client-side JavaScript. The token allegedly granted administrative access to one law firm’s Box environment, where testing returned nearly 100,000 files matching “confidential”; the researcher stopped further access testing. Filevine said the issue affected a single law firm rather than its broader platform, remediated it, and confirmed resolution.

Map this exposure pattern across your cloud, code, and identities.
9 events from the most recent confirmed update back to the earliest known activity.
Filevine confirmed that it had resolved the issue. The company said the exposure was limited to a non-production environment for one law firm and was not system-wide.
The researcher followed up with Filevine to verify whether the remediation had been deployed.
Filevine's security team acknowledged the report and said it would review and quickly remediate the issue.
A researcher discovered that an unauthenticated Filevine recommendation API endpoint returned a live, fully scoped Box administrative token for one law firm's filesystem. The researcher validated the impact by searching for "confidential" and receiving nearly 100,000 results, then reported the issue to Filevine.
The researcher publicly disclosed the Filevine vulnerability, describing the unauthenticated endpoint and its exposure of a Box token capable of accessing sensitive legal documents and related data.
After reviewing the DeepSeek exposure, ClickHouse disabled network access for the default user by default in its official Docker images. The change was backported to the last three releases and two LTS versions.
DeepSeek promptly secured the exposed ClickHouse database after Wiz's disclosure.
Wiz responsibly disclosed the exposed database to DeepSeek after limiting its testing to enumeration and non-intrusive queries.
Wiz Research identified a publicly accessible, unauthenticated ClickHouse database on DeepSeek infrastructure that permitted database operations and exposed more than one million log entries, including plaintext chat history, API secrets, backend details, and operational metadata.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
alexschapiro.com
Open sourcewiz.io
Open sourcewiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.