Tag
high
advisory
Chamilo LMS REST API Key Brute-Force Vulnerability (CVE-2026-33710)
2 rules 1 TTP 1 CVEChamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3 generate predictable REST API keys, allowing attackers with knowledge of a username and approximate key creation time to brute-force access.
cve-2026-33710
chamilo
api-key
brute-force
webserver
2r
1t
1c
high
advisory
Unscoped API Keys in AI Agent Frameworks
2 rules 1 TTP 2 IOCsA research report auditing popular AI agent projects found that 93% rely on unscoped API keys as the only authentication mechanism, leading to potential credential exposure, privilege escalation, and lateral movement within multi-agent systems.
ai-agent
api-key
authorization
credential-theft
2r
1t
2i
medium
advisory
Algolia Admin Keys Exposed in Open Source Documentation
2 rules 2 TTPs 1 IOCA security researcher discovered 39 Algolia admin keys exposed across various open source documentation websites, potentially allowing unauthorized access and modification of search indices.
Algolia DocSearch
algolia
api-key
data-breach
information-disclosure
2r
2t
1i