The $6M AI Hack: A cautionary Story of How Hackers Found the Perfect Storm in DeepSeek's Infrastructure…
The most fascinating cyber attacks aren't about brute force - they're about finding the perfect intersection of technical vulnerabilities. Let me take you inside what might be the first of many to come AI security breaches.
🎯 The Target: DeepSeek AI
- Built a revolutionary AI model for $6M
- Topped Apple Store charts
- Matched performance of billion-dollar competitors
But here's where it gets interesting...
The attackers didn't just find a vulnerability - they found a whole new attack surface that exists only in AI infrastructure.
As a cyber security expert with 24 years in the industry I find it interesting how creative hackers really are and how new innovation creates new vulnerabilities.
Here's the brilliant (and terrifying) part of the attack:
But AI services need something entirely different. It's like putting a regular car's engine management system in a rocket - it's bound to fail spectacularly.
Rate Limiting Layer:
- Couldn't handle AI's unique burst patterns
- Failed to distinguish between legitimate ML requests and attacks
- Regional distribution bottlenecks
Authentication Systems:
- Collapsed under distributed request patterns
- Lacked AI-specific concurrent request handling
- Missing ML-optimized verification workflows
Scaling Architecture:
- Rigid autoscaling couldn't match attack patterns
- Registration services weren't properly distributed
- Resource allocation couldn't adapt fast enough
🎭 The Plot Twist:
The attackers weren't after the AI model (it was open source anyway!) - they targeted DeepSeek's growth potential. By overwhelming the registration system, they effectively put a chokehold on the company's viral moment.
💡 The Technical Lessons Every CTO Needs to Know:
AI Infrastructure needs:
- Adaptive rate limiting based on ML behavior patterns
- Distributed authentication with regional failover
- AI-specific anomaly detection
- Elastic scaling for ML model serving
- Smart request prioritization
New Security Paradigm:
- Traditional web security ≠ AI service security
- Growth vectors are the new attack surface
- Open source requires rethinking protection strategies
The question every tech leader should be asking: "Is our infrastructure ready for AI-scale attacks?"
This new breed of AI hacks is definitely going to keep my AI cybersecurity firm in business…
Credit: Gybrius
OpenAI CEO Sam Altman has set a bold goal for 2025: achieving artificial general intelligence (AGI), a level of AI that learns and understands like humans.
In a conversation with Y Combinator CEO Gary Tan, Altman made his excitement clear. When Tan asked, “What are you excited about in 2025?” Altman replied confidently, “AGI.” He sees this shift as a major milestone just around the corner.
As Altman pushes forward, two big questions remain: is AGI really that close, and can OpenAI manage its impact? If AGI arrives by 2025, Altman’s ambition may indeed launch a new era, ready or not.
የምዝገባ መርሃ ግብራቹህን ያጠናቀቃቹ ሆናቹ ወደ ዋናው የክላስ ግሩፕ add ያልተደረጋቹ ካላቹ ወይም ከፍላቹ ያልተመዘገባቹህ ካላቹህ ነገ ሰኞ ህዳር 02 ክላስ ስለሚጀመር በአስቸኳይ በውስጥ አናግሩንና add እናድርጋቹህ።
ወይንም በኢሜይላችን አግኙን።
✉️ [email protected]
**ተጨማሪ የምዝገባ ክፍት ቦታዎችን እናሳውቃችሁ።
ብዙዎቻችሁ እስከ ዛሬ ሲሰጥ የነበረው የ1 ወር የመመዝገቢያ ቀነ ገደብ በዚህ ዙር በአንድ ሳምንት ውስጥ ስለተጠናቀቀ መመዝገብ አለመቻላችሁን አሳውቃችሁናል። ከፊል የኮርስ ቦታዎች ቀድመው የሞሉ ቢሆንም የቅበላ አቅማችንን በማስፋት ያሉ ውስን ክፍት የመመዝገቢያ አማራጮችን እናሳውቃችሁ።
በኦንላይን መማር ለምትፈልጉ በሁሉም ኮርሶች ያልተገደበ ክፍት ቦታ አለን።
1️⃣**) ግራፊክ ዲዛይን:
በመደበኛ: 7 ቦታዎች
በማታ: 12 ቦታዎች
በሳምንታዊ ቅዳሜና እሁድ: 10 ቦታዎች
2️⃣) ፉል ስታክ (MERN) ድረ ገፅ ማበልፀግ፡
መደበኛ፡ 2 ቦታዎች
በቅዳሜና እሁድ: 5 ክፍት ቦታዎች
በማታ: 3 ቦታዎች
3️⃣) ዲጂታል ማርኬቲንግ፡
በመደበኛ: 4 ቦታዎች
በማታ: 6 ቦታዎች
በቅዳሜና እሁድ: 5 ቦታዎች
4️⃣) ፓይተን፡
ሸመደበኛ: 10 ቦታ
በማታ: 8 ቦታዎች
በቅዳሜና እሁድ: 7 ቦታዎች
5️⃣) ሞባይል አፕ ማበልፀግ:
በመደበኛ 12 ቦታዎች
በማታ: 8 ቦታዎች
በቅዳሜና እሁድ: 10 ቦታዎች
6️⃣) ደታ ሳይንስ:
በመደበኛ 10 ቦታዎች
በማታ: 8 ቦታዎች
በቅዳሜና እሁድ: 10 ቦታዎች
7️⃣) ሳይበር ሴኩሪቲ:
በመደበኛ 11 ቦታዎች
በማታ: 15 ቦታዎች
በቅዳሜና እሁድ: 15 ቦታዎች
8️⃣) ቪድዮ ኤዲቲንግ:
በመደበኛ 12 ቦታዎች
በማታ: 12 ቦታዎች
በቅዳሜና እሁድ: 9 ቦታዎች
የክፍል መርሃ ግብሮች ዝርዝር ሰአት:
መደበኛ ማለት፡ ከጠዋት 3፡00-5፡00 ወይም ከሰአት 7፡30-9፡30 የሚሰጥ ነው።
የማታ ማለት፡ ከቀኑ 11፡00-1፡00 የሚሰጥ ነው።
የቅዳሜና እሁድ ፕሮግራም: ለግማሽ ቀን የሚሰጥ ነው። (ከጠዋት 3:00–6:00 ወይም ከሰአት 7:30–10:30)
ማስታወሻ፡ የማሽን ለርኒንግ፣ AI፣ DL እና Robotics ክላሶች በሁሉም ክፍለ-ጊዜዎች ሙሉ በሙሉ ተይዘዋል።
ክላስ የሚጀመረው ሰኞ ነው እድሉ ሳያልፋችሁ ፈጥናችሁ አሁኑኑ ተመዝገቡ፡
ለማንኛውም ጥያቄ በቴሌግራም፡ ወይም በኢሜል [email protected] ወይም 0987143030 ላይ አግኙን።
የኛን ምርጥ ምርጥ ኮርሶች ለመቀላቀል የመጨረሻውን እድል ተጠቀሙበት።
ነገር ግን ከመመዝገባቹህ በፊት የሞላ ኮርስ ካለ ቀድማቹህ ጠይቁን✉️?
ማይክሮሶፍት ዊንዶውስ 11 22H2 ሥሪት ከ60 ቀናት በኋላ አገልግሎቱ እንደሚያበቃ ገለጸ።
ማይክሮሶፍት የዊንዶውስ 11 21H2 እና 22H2 ስሪቶች አገልግሎት በ60 ቀናት ውስጥ ማለትም በፈረንጆቹ ጥቅምት 8/2024 እንደሚያበቃ አስታወቀ።
ማስታወቂያው በ Windows 11 22H2 Home, Pro, Pro Education, Pro for Workstations, and SE ሥሪቶች መስከረም 20 ቀን 2022 ላይ መለቀቃቸውን አስታውሶ በተመሳሳይ ቀን Windows 11 21H2 Enterprise, Education, and IoT Enterprise ሥሪቶች ተለቀው እንደነበር እና የአገልግሎት ጊዜያቸው ማብቂያ እንደደረሰ አስታውቋል።
ለእነዚህ ምርቶች በመጪው ጥቅምት 8/2024 የሚለቀቀው የደህንነት ዝማኔ የመጨረሻው እንደሚሆን ማይክሮሶፍት ገልጿል፡፡ ከዚህ ቀን በኋላ እነዚህን ምርቶች የሚጠቀሙ ዲቫይሶች ወርሃዊ የደህንነት ዝመናን ወይም ጥገናን እንደማያገኙ እና የዝመና ማስታወሻዎችን እንደማይመለከቱ ማይክሮሶፍት አስጠንቅቋል፡፡
ደንበኞች ስለ ሌሎች የዊንዶውስ ምርቶች የአገልግሎት ማብቂያ ቀናት በዊንዶውስ የህይወት ኡደት ተደጋግመው የሚጠየቁ ጥያቄዎችና መልሶች (Windows Lifecycle FAQ) ገጽ እና የህይወት ኡደት ፖሊሲ መፈለጊያን በመጠቀም ዝርዝሮችን ማግኘት ይችላሉ።
AI working as a dental doctor
For the first time in history, an AI-controlled dental robot has successfully performed a dental procedure on a human
The company's representatives note that this high-tech robot not only performs the work with exceptional accuracy but also does it eight times faster than traditional dentists.
This achievement promises to revolutionise dentistry, making procedures faster, more efficient and more comfortable for patients.
Exciting news for Ethiopia's tech future! The 5 Million Ethiopian Coders Initiative has been launched, offering free online courses in Programming Fundamentals, Data Science Fundamentals, and Android Kotlin Development. This joint initiative between the…
