# Philippe Caturegli

**Chief Hacking Officer at Seralys**

## About

Philippe started his hacking career in the 1990s with a multi-node hacking/phreaking BBS running from his parents' basement. Over the past 30 years, he has worked across all sides of security: defending large enterprise networks, advising financial institutions, and ultimately following his passion for breaking things as a penetration tester and vulnerability researcher.

## Connect

- [LinkedIn](https://www.linkedin.com/in/caturegli/)

## Sessions

### Domain Collisions 2.0

**What you will learn:** What happens when your internal domain name is actually registered and operated by someone else? You start leaking credentials, email gets misrouted, deployment pipelines pull code from untrusted places, and most of the time you don’t even notice for years.

With over 1,200 new TLDs introduced over the past decade, many organizations are unknowingly using internal domain names that now exist as valid, publicly registerable FQDNs that they don’t own and never thought to claim. From police departments to major cities, airports to enterprise platforms, no sector is immune.

This talk presents original research into the resurgence of internal domain name collisions, a vulnerability that was documented years ago and ignored, because nobody measured what it was actually worth to an attacker. This is the first research (that we know of) to do that at scale. We registered and operated hundreds of colliding domains, and we will show what came back. We will also cover the disclosure side, which ranged from complete silence to legal threats.

## Speaking At

- [RBLN West 2026 - San Francisco](https://www.rbln.com/events/2026/west)

---
*Source: [RBLN (Rebellion) Cybersecurity Conference – Technical Security Event for Hackers, AI Builders & Operators](https://www.rbln.com/speakers/philippe-caturegli)*