Skip to content
  Thursday 15 January 2026
Trending
April 18, 2025Sr. Cybersecurity Analyst 2 – Security Threat Management August 22, 2024CISA Releases Five Industrial Control Systems Advisories January 9, 2024Discovery of New Vulnerabilities in QNAP and Kyocera Device Manager November 15, 2025Systems Cybersecurity May 5, 2025Cybersecurity Senior Engineer (Customer Cyber Threat Response) November 11, 2025Cybersecurity Mission Analyst July 29, 2025<h3>Coyote Trojan Exploits Accessibility for Cyber Attacks!</h3> January 25, 20247 Important Discoveries and Upcoming Patterns for 2024 July 13, 2025Cybersecurity Analyst November 26, 2024CISA Urges Immediate Patching of Critical “Array Networks” Flaw to Halt Active Attacks
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
Mister Cybersecurity
  • Home
  • News
    • Daily Update
    • Industry News
    • Threat Advisories
  • Simulators
    • Exam Simulators
      • CompTIA Security+
      • CompTIA Advanced Security Practitioner (CASP+)
      • Certified Ethical Hacker (CEH)
      • Certified Information Systems Security Professional (CISSP)
      •  Certified Information Systems Auditor (CISA)
      • Certified Information Security Manager (CISM)
      • Systems Security Certified Practitioner (SSCP)
      • GIAC Security Essentials Certification (GSEC)
      • GIAC Certified Incident Handler (GCIH)
      • Offensive Security Certified Professional (OSCP)
    • Training Simulators
      • Blue Team Simulator
      • Red Team Simulator
  • Tools
    • VulnVisor – Vulnerability Explorer
    • Takedown Request Generator
    • Dark Coder – Auto Code Generator
    • SKY VPN
  • Courses
    • SQL Injection Fundamentals with Kali Linux
    • Web Application Hacking
    • Session Hijacking
    • DoS & DDoS Attacks for Beginners
    • Cryptography for Cybersecurity & Hacking
    • Evasion Tactics – IDS, Firewalls & Honeypots
  • Tutorials
    • Security
    • Malware
    • Virus
    • Social Media Security
    • Wireless Security
    • Linux
    • Privacy
    • Windows
      • Windows 11
    • Android
    • iPhone
  • Software
    • Antivirus
    • Android APK
    • Best Free VPN
    • Encryption Tools
    • Hacking Tools
    • Network Utilities
    • Pentesting Tools
    • Themes and Skins
    • Operating Systems
  • More
    • Alternative Sites
    • Cloud Storage
    • Chrome OS
    • Encryption
    • Email Security
    • Ethical Hacking Books
    • Firewall
    • Hacking
    • Web
    • Ransomware
  • Careers
  • Store
  • Account
    • Log In
    • Your Profile
    • Membership Billing
    • Membership Account
Mister Cybersecurity
  Industry News  DeepSeek App Exposes Your Sensitive Data – No Encryption!
Industry News

DeepSeek App Exposes Your Sensitive Data – No Encryption!

SecuredyouadmSecuredyouadm—February 7, 20250
FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail
More stories

When Staying Open Is the Only Choice

September 4, 2025

Critical Infrastructure: The Playground of Nation-State Hackers

October 17, 2023

Malicious PyPI Packages Discovered Utilizing Sneaky Side-Loading Methods

February 20, 2024

Authorities Seize Lolek’s Bulletproof Hosting Servers and Arrest Five Key Operators

August 15, 2023



A recent audit of DeepSeek’s mobile app for Apple iOS has uncovered significant security vulnerabilities, with the most concerning issue being the transmission of sensitive data over the internet without encryption. NowSecure, the company behind the assessment, highlighted that this lack of encryption exposes the data to interception and manipulation attacks. Additionally, the app was found to collect extensive user and device data, raising further privacy concerns.

Further analysis of the DeepSeek iOS app revealed implementation weaknesses in applying encryption to user data. The app utilized an insecure symmetric encryption algorithm (3DES), a hardcoded encryption key, and the reuse of initialization vectors. These vulnerabilities could potentially compromise the security and confidentiality of user information, leaving it susceptible to exploitation by malicious actors.

The data transmitted by the app is sent to servers managed by Volcano Engine, a cloud compute and storage platform owned by ByteDance, the parent company of TikTok. NowSecure noted that the app globally disables App Transport Security (ATS), a protection mechanism on iOS that prevents sensitive data from being sent over unencrypted channels. This disabled protection allows the app to send unencrypted data over the internet, further exacerbating the security risks.

The concerns surrounding DeepSeek extend beyond security vulnerabilities, with reports indicating that threat actors have been leveraging AI engines from DeepSeek to develop malicious content such as information stealers and spam distribution scripts. As organizations face evolving threats from advanced techniques employed by cybercriminals, the need for proactive defenses against misuse of AI technologies becomes increasingly critical.

Amidst growing apprehensions about DeepSeek’s ties to China, various countries and government agencies have imposed bans on the app. The app’s connection to China Mobile and its potential to provide user information to Beijing have raised red flags, prompting calls for a nationwide ban. Furthermore, DeepSeek’s surge in popularity has attracted malicious attacks, including DDoS incidents originating from Mirai botnets. Cybercriminals have also capitalized on the app’s hype to launch fraudulent schemes and phishing attacks, underscoring the importance of vigilance in the face of cybersecurity threats.



Source link

FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail

Securedyouadm

Microsoft uncovers 3,000 leaked ASP.NET keys for dangerous code injection attacks

Zero Days Strike Back: Cyber Threat Resurgence

Related posts
  • Related posts
  • More from author
Industry News

5 Reasons AI-Driven Business Need Dedicated Servers – SmartData Collective

October 14, 20250
Industry News

The Future of Cyberthreat Sharing Post-CISA 2015: What’s Next?

October 1, 20250
Industry News

Meta Strikes $14.2B AI Deal with CoreWeave for Cutting-Edge Infrastructure

October 1, 20250
Load more
Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Read also
Careers

Cybersecurity Analyst

January 14, 20260
Careers

Lead Cybersecurity – SOX

January 14, 20260
Careers

Senior Cloud Security Engineer, AVP – BXTI Cybersecurity

January 14, 20260
Careers

Sr. Cybersecurity Analyst, Compliance

January 14, 20260
Careers

Cybersecurity Analyst

January 14, 20260
Careers

CYBERSECURITY ANLST SR

January 14, 20260
Load more
Stay Social!
192Likes
4,500Followers
13Subscribers
46Followers
Recent posts
  • Cybersecurity Analyst
  • Lead Cybersecurity – SOX
  • Senior Cloud Security Engineer, AVP – BXTI Cybersecurity
  • Sr. Cybersecurity Analyst, Compliance
  • Cybersecurity Analyst

    # TRENDING

    how old is my computerhow old is my dell laptophow old is my HP laptophow old is my laptophow old is my toshiba laptophow to find computer ageverify computer agestar wars theme wallpapersThe Best Hacking Bookswiresharkusb device not found windows 10/11usb device not recognized windows 10/11 errorWhat is AIGPUSnifferuTorrentvulnerability scanner downloadWifi Hacking SoftwareWifi Hacking Appsolved windows 10/11 usb device not recognizedstar wars windows 7 theme downloadTwitter Account Security
    © Copyright Mister Cybersecurity LLC 2023, All Rights Reserved
    • About
    • Contact
    • Privacy
    • ToS
    • Disclosures