Our research
At Seralys, we investigate emerging threats, uncover overlooked vulnerabilities, and contribute practical knowledge to the security community. Our team actively engages in original security research—from DNS misconfigurations to cloud and web vulnerabilities—with the goal of sharing actionable insights and improving digital defenses.
-
Lost in the .cloud: Internal Domain Collisions in SoftLayer/IBM Cloud
IBM Domain Collision WPAD DNSThis research highlights internal domain name collisions caused by SoftLayer’s use of unregistered .cloud TLDs, resulting in data leaks and NTLM hash exposures..
12 June 2025 -
BSides Buffalo 2025
Domain Collision Bsides DNSWe presented real-world findings from our research on internal domain name collisions, including leaked traffic, and shared the challenges we faced during the disclosure process.
7 June 2025 -
RVASec 2025
Domain Collision Rvasec DNSThis talk covered the technical and operational risks of internal domain name collisions, including several real-world examples uncovered during our year-long research. It also highlighted the challenges encountered while disclosing our findings to affected vendors and organizations.
3 June 2025 -
xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs
XAI Leaks LLM SpaceXSeralys discovered a leaked API key from an xAI developer that granted access to xAI, SpaceX, and Tesla internal LLMs.
May 1, 2025 -
Mastercard DNS Error Went Unnoticed for Years
DNS Mastercard Misconfiguration Responsible DisclosureWhile researching DNS misconfigurations, we identified a critical issue in Mastercard’s infrastructure. The misconfigured domain went unnoticed and remained exploitable for years, raising concerns about systemic DNS hygiene.
Jan 22, 2025 -
Hack.lu 2024
HAKLU Domain Collision TLDs AuthenticationPresented in Luxembourg, this talk shared our preliminary findings on internal domain name collisions, focusing on how unregistered domains under newly delegated TLDs can lead to data leaks, authentication attempts, and traffic exposure.
Oct 25, 2024 -
xAI Dev Leaks API Key for Private SpaceX, Tesla LLMs
XAI Leaks LLM SpaceXSeralys discovered a leaked API key from an xAI developer that granted access to xAI, SpaceX, and Tesla internal LLMs.
Aug 23, 2024