Close Menu
5gantennas.org5gantennas.org
  • Home
  • 5G
    • 5G Technology
  • 6G
  • AI
  • Data
    • Global 5G
  • Internet
  • WIFI
  • 5G Antennas
  • Legacy

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
5gantennas.org5gantennas.org
  • Home
  • 5G
    1. 5G Technology
    2. View All

    Deutsche Telekom to operate 12,500 5G antennas over 3.6 GHz band

    August 28, 2024

    URCA Releases Draft “Roadmap” for 5G Rollout in the Bahamas – Eye Witness News

    August 23, 2024

    Smart Launches Smart ZTE Blade A75 5G » YugaTech

    August 22, 2024

    5G Drone Integration Denmark – DRONELIFE

    August 21, 2024

    Hughes praises successful private 5G demo for U.S. Navy

    August 29, 2024

    GSA survey reveals 5G FWA has become “mainstream”

    August 29, 2024

    China Mobile expands 5G Advanced, Chunghwa Telecom enters Europe

    August 29, 2024

    Ateme and ORS Boost 5G Broadcast Capacity with “World’s First Trial of IP-Based Statmux over 5G Broadcast” | TV Tech

    August 29, 2024
  • 6G

    India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

    August 29, 2024

    Vodafonewatch Weekly: Rural 4G, Industrial 5G, 6G Patents | Weekly Briefing

    August 29, 2024

    Southeast Asia steps up efforts to build 6G standards

    August 29, 2024

    Energy efficiency as an inherent attribute of 6G networks

    August 29, 2024

    Finnish working group launches push for 6G technology

    August 28, 2024
  • AI

    Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

    August 29, 2024

    Why Honeywell is betting big on Gen AI

    August 29, 2024

    Ethically questionable or creative genius? How artists are engaging with AI in their work | Art and Design

    August 29, 2024

    “Elon Musk and Trump” arrested for burglary in disturbing AI video

    August 29, 2024

    Nvidia CFO says ‘enterprise AI wave’ has begun and Fortune 100 companies are leading the way

    August 29, 2024
  • Data
    1. Global 5G
    2. View All

    Global 5G Enterprise Market is expected to be valued at USD 34.4 Billion by 2032

    August 12, 2024

    Counterpoint predicts 5G will dominate the smartphone market in early 2024

    August 5, 2024

    Qualcomm’s new chipsets will power affordable 5G smartphones

    July 31, 2024

    Best Super Fast Download Companies — TradingView

    July 31, 2024

    Crypto Markets Rise on Strong US Economic Data

    August 29, 2024

    Microsoft approves construction of third section of Mount Pleasant data center campus

    August 29, 2024

    China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

    August 29, 2024

    What is the size of the clinical data analysis solutions market?

    August 29, 2024
  • Internet

    NATO believes Russia poses a threat to Western internet and GPS services

    August 29, 2024

    Mpeppe grows fast, building traction among Internet computer owners

    August 29, 2024

    Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

    August 29, 2024

    Long-term internet computer investor adds PEPE rival to holdings

    August 29, 2024

    Biden-Harris Administration Approves Initial Internet for All Proposals in Mississippi and South Dakota

    August 29, 2024
  • WIFI

    4 Best Wi-Fi Mesh Networking Systems in 2024

    September 6, 2024

    Best WiFi deal: Save $200 on the Starlink Standard Kit AX

    August 29, 2024

    Sonos Roam 2 review | Good Housekeeping UK

    August 29, 2024

    Popular WiFi extender that eliminates dead zones in your home costs just $12

    August 29, 2024

    North American WiFi 6 Mesh Router Market Size, Share, Forecast, [2030] – அக்னி செய்திகள்

    August 29, 2024
  • 5G Antennas

    Nokia and Claro bring 5G to Argentina

    August 27, 2024

    Nokia expands FWA portfolio with new 5G devices – SatNews

    July 25, 2024

    Deutsche Telekom to operate 12,150 5G antennas over 3.6 GHz band

    July 24, 2024

    Vodafone and Ericsson develop a compact 5G antenna in Germany

    July 12, 2024

    Vodafone and Ericsson unveil new small antennas to power Germany’s 5G network

    July 11, 2024
  • Legacy
5gantennas.org5gantennas.org
Home»Data»Hundreds of LLM servers publish business, health and other online data
Data

Hundreds of LLM servers publish business, health and other online data

5gantennas.orgBy 5gantennas.orgAugust 28, 2024No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


Hundreds of open-source large-scale language model (LLM) builder servers and dozens of vector databases are leaking highly sensitive information onto the open web.

In their rush to integrate AI into business workflows, companies may not pay enough attention to securing these tools and the information they entrust to them, and in a new report, Legit security researcher Naphtali Deutsch demonstrates this by scanning the web for two types of threats. Potentially Vulnerable Open Source (OSS) AI ServicesA vector database to store data for AI tools and an LLM application builder, specifically the open source program Flowise. Sensitive personal and corporate dataThey are unwittingly put at risk by organisations striving to join the generative AI revolution.

“A lot of programmers see these tools on the Internet and try to implement them in their environments,” Deutsch says, but they don’t consider security.

Hundreds of unpatched Flowwise servers

Flowise is a low-code tool for building any kind of LLM application. It’s backed by Y Combinator and has tens of thousands of stars on GitHub.

The programs that developers build with Flowise, whether they’re customer support bots or tools that generate and extract data for downstream programming or other tasks, tend to access and manage large amounts of data, so it’s no surprise that the majority of Flowise servers are password protected.

But passwords alone are not enough security. Earlier this year, an Indian researcher discovered an authentication bypass vulnerability in Flowise version 1.6.2 and earlier versions that could be triggered by simply capitalizing a few characters in the program’s API endpoint. The issue is tracked as CVE-2024-31621 and received a “high” score of 7.6 on the CVSS version 3 scale.

Legit’s Deutsch exploited CVE-2024-31621 to crack 438 Flowise servers, including GitHub access tokens. OpenAI API keyyour plaintext Flowise password and API key, configurations and prompts associated with your Flowise app, etc.

“GitHub API tokens allow access to private repositories,” Deutsch emphasizes. This is just one example of the additional attacks that such data can enable. “We also found API keys to other vector databases, such as Pinecone, a very popular SaaS platform. These can be used to break into the databases and dump all the data found, which is probably private and sensitive data.”

Dozens of unsecured vector databases

In fact, vector databases store all kinds of data that AI apps need to retrieve, and any data accessible from the wider web could be attacked directly.

Using a scanning tool, Deutsch found about 30 Vector database servers running online without any authentication checks. These servers contained apparently sensitive information, such as private email conversations from an engineering services vendor, documents from a fashion company, and PII and financial information from clients of an industrial equipment company. Other databases included real estate data, product documentation and data sheets, and patient information used by a medical chatbot.

Leaky vector databases are even more dangerous than leaky LLM builders because they can be tampered with in ways that don’t alert users of the AI ​​tools that rely on them. For example, hackers can not only steal information from a public vector database, but can also delete or corrupt that data to manipulate the results. They could also plant malware within a vector database that would be pulled in when an LLM program runs a query.

To mitigate the risks from exposed AI tools, Deutsch recommends organizations limit access to the AI ​​services they rely on, monitor and log activity related to those services, protect any sensitive data trafficked by LLM apps, and apply software updates whenever possible.

“[These tools] “It’s new, and people don’t have a lot of knowledge about how to set it up,” he warns. “And it’s getting easier to set up. A lot of these vector databases can be set up in Docker or in an AWS Azure environment with two clicks.”Security is more cumbersome and can lag behind.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChinese Cyber ​​Espionage Group Attacks Internet and IT Service Providers in the U.S. and India, Setting the Stage for Future Wars: What is “Bolt Typhoon”?
Next Article Best dash cams with WiFi for extended safety while driving, these picks will keep you guarded
5gantennas.org
  • Website

Related Posts

Crypto Markets Rise on Strong US Economic Data

August 29, 2024

Microsoft approves construction of third section of Mount Pleasant data center campus

August 29, 2024

China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

August 29, 2024

Comments are closed.

Latest Posts

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024

Crypto Markets Rise on Strong US Economic Data

August 29, 2024
Don't Miss

Business News | Communications Minister Scindia promotes 6G leadership and nationwide broadband in meeting with telecom operators

By 5gantennas.orgAugust 24, 2024

New Delhi [India]August 24 (ANI): Union Telecom Minister Jyotiraditya Scindia along with Minister of State…

SingTel and SK Telecom prepare for the 6G future

July 8, 2024

Apple focuses on 6G for future iPhones

December 11, 2023

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to 5GAntennas.org, your reliable source for comprehensive information on 5G technology, artificial intelligence (AI), and data-related advancements. We are passionate about staying at the forefront of these cutting-edge fields and bringing you the latest insights, trends, and developments.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Most Popular

Will 5G make 2024 the most connected year in the industry?

December 1, 2023

The current state of 5G in the US and how it can improve

September 28, 2023

How 5G technology will transform gaming on the go

January 31, 2024
© 2025 5gantennas. Designed by 5gantennas.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • About Creator

Type above and press Enter to search. Press Esc to cancel.