Coin World News, H3C's "Lingxi AI Assistant" exposes a large number of large model API credentials in plaintext within the installation program. This tool, originally claimed to run on a local NPU, directly hardcoded valid keys for multiple cloud models such as Zhipu AI, Baidu Qianfan, and ByteDance Volcano Engine in its configuration file. Netizens discovered this vulnerability at the end of January this year and reported it to the H3C team, but it wasn't until early May that the official revoked all the leaked credentials. The three-month response period is unusual. Industry insiders speculate that the slow response may be because multiple internal H3C teams shared the same batch of API credentials, making the officials hesitant to cut off the leaked keys until a thorough investigation and replacement were completed. Fortunately, the product has a relatively small user base and did not trigger large-scale hacking and theft; otherwise, it could have resulted in astronomical bills.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin