Poging GOUD - Vrij
CROWDSTRIKE RESEARCH: SECURITY FLAWS IN DEEPSEEK-GENERATED CODE LINKED TO POLITICAL TRIGGERS
Enterprise IT World
|November 2025
CrowdStrike Counter Adversary Operations identifies innocuous trigger words that lead DeepSeek to produce more vulnerable code.
-
In January 2025, China-based AI startup DeepSeek released DeepSeek-R1, a high-quality large language model (LLM) that allegedly cost much less to develop and operate than Western competitors' alternatives.
CrowdStrike Counter Adversary Operations conducted independent tests on DeepSeek-R1 and confirmed that in many cases, it could provide coding output of quality comparable to other market-leading LLMs of the time. However, we found that when DeepSeek-R1 receives prompts containing topics the Chinese Communist Party (CCP) likely considers politically sensitive, the likelihood of it producing code with severe security vulnerabilities increases by up to 50%.
This research reveals a new, subtle vulnerability surface for AI coding assistants. Given that up to 90% of developers already used thes tools in 2025,1 often with access to high-value source code, any systemic security issue in AI coding assistants is both high-impact and high-prevalence.
CrowdStrike's research contrasts with previous public research, which largely focused on either traditional jailbreaks, like trying to get DeepSeek to produce recipes for illegal substances or endorse criminal activities, or on prompting it with overtly political statements or questions to provoke it to respond with a pro-CCP bias.2
Since the initial release of DeepSeek-R1 in January 2025, a plethora of other LLMs by Chinese companies has been released (several other DeepSeek LLMs, the collection of Alibabas latest Qwen3 models, and MoonshotAI's Kimi K2, to name a few). While our research specifically focuses on the biases intrinsic to DeepSeek-R1, these kinds of biases could affect any LLM, especially those suspected to have been trained to adhere to certain ideological values.
We hope by publishing our findings we can help spark a new research direction into the effects that political or societal biases in LLMs can have on writing code and other tasks.
Disambiguation
Dit verhaal komt uit de November 2025-editie van Enterprise IT World.
Abonneer u op Magzter GOLD voor toegang tot duizenden zorgvuldig samengestelde premiumverhalen en meer dan 9000 tijdschriften en kranten.
Bent u al abonnee? Aanmelden
MEER VERHALEN VAN Enterprise IT World
Enterprise IT World
SecurityScorecard Exposes Global ASUS Router Hijack "WrtHug" With Suspected China Links
SecurityScorecard's STRIKE threat intelligence team, working with ASUS, has uncovered Operation WrtHug- a sophisticated global espionage campaign hijacking thousands of ASUS home and SOHO routers to create covert relay nodes across Asia, the US, and Europe.
1 min
November 2025
Enterprise IT World
Armis Raises $435 Million Pre-IPO Funding, Valued at $6.1 Billion
Armis, the global leader in cyber exposure management, has secured US$435 million in pre-IPO funding, boosting its valuation to US$6.1 billion.
1 min
November 2025
Enterprise IT World
Paytm Bets on AI in Travel with Launch of 'Paytm Checkin'
Paytm (One 97 Communications Limited), India's leading digital payments and financial services company, has unveiled Paytm Checkin, an Al-powered travel app designed to transform trip planning and booking through conversational intelligence and personalization.
1 min
November 2025
Enterprise IT World
FROM AGENTIC AI TO INCLUSIVE GROWTH: IFTA UNVEILS FINTECH TRENDS 2026 AHEAD OF 10TH ANNUAL INDIA FINTECH FORUM
The 10th edition of the India FinTech Forum (IFTA) spotlights Agentic AI, embedded finance, democratization of wealth, cyber resilience, and fintech for Bharat as the key trends shaping India's financial future. The event, to be held on December 10, 2025, in Mumbai, will also honour disruptive fintech startups transforming the BFSI landscape.
4 mins
November 2025
Enterprise IT World
INDIA'S DPDP ACT: A NEW ERA FOR DATA PRIVACY AND DIGITAL TRUST
The Digital Personal Data Protection Act, 2025 sets a clear framework for consent, accountability, and governance-reshaping how businesses handle personal data in an Al-driven economy.
3 mins
November 2025
Enterprise IT World
TIRED OF SPAM CALLS? HOW THE DPDP RULES, 2025 PUT YOU BACK IN CONTROL. THE DAILY NUISANCE WE ALL KNOW
The Digital Personal Data Protection Act, 2025 sets a clear framework for consent, accountability, and governance-reshaping how businesses handle personal data in an Al-driven economy.
4 mins
November 2025
Enterprise IT World
CyberArk Launches Free TLS Certificate Scan Tools to Help Businesses Prevent Outages and Rising Labor Costs
CyberArk has unveiled two free tools -the TLS Certificate Renewal Impact Calculator and TLS Certificate Discovery Scan to help organizations prepare for a seismic shift in certificate management.
1 min
November 2025
Enterprise IT World
Consistent Infosystems to Showcase Advanced Surveillance Technologies at IFSEC India 2025
Consistent Infosystems, one of India's fastest-growing IT hardware and security technology brands, is gearing up for a strong presence at IFSEC India 2025, scheduled from 11-13 December at Pragati Maidan, New Delhi.
1 min
November 2025
Enterprise IT World
Lenovo India Surges to USD 1.2 Billion Quarterly Revenue, Fueled by Al and Digita Infrastructure Demand
Lenovo India has delivered a landmark performance in Q2 FY25/26, posting USD 1.2 billion in revenue-an impressive 23% year-on-year growth-marking one of its strongest quarters to date.
1 min
November 2025
Enterprise IT World
CyberArk's New TLS Tools Signal a Turning Point in Automation and Risk Management
As TLS certificate lifespans shrink dramatically-from 398 days today to just 47 days by 2029-automation is no longer optional; it's mission-critical for business continuity.
1 min
November 2025
Listen
Translate
Change font size

