Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

Subvocal launches under-chin wearable for silent computer control

Subvocal launches under-chin wearable for silent computer control
YcBrain Computer Interface+3
SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
SaaS iconSaaSJuly 6, 2026

YC's Archal Launches Verification Layer to Test AI Agents Before Production

YC's Archal Launches Verification Layer to Test AI Agents Before Production
YcAi Agents+3
SaaS iconSaaSJuly 6, 2026

MintMerchs Debuts AI Platform to Automate eCommerce Brand Creation

MintMerchs Debuts AI Platform to Automate eCommerce Brand Creation
Ai AgentsAi Automation+3

Founders Mentioned

Xiaochuan Yu

Nebula Security

saas icon
SaaS

Xiaochuan Yu

Nebula Security

saas icon
SaaS
SaaS iconSaaS
July 6, 2026
YcCybersecurityAiVulnerability DetectionBug Detection

Elite Hackers Launch AI Security Platform That Found 730+ Bugs

Nebula Security's YC S26 team—first to root Android 17 and crack nginx—deploys Vega, an AI vulnerability scanner competing with Anthropic and OpenAI in code security.

Elite Hackers Launch AI Security Platform That Found 730+ Bugs

The four engineers behind Nebula Security want you to know they were first. First to root Android 17—or so they claim, though that assertion remains unverified by major outlets—first to crack a critical NGINX bug, first to build an exploit chain that threads from browser to kernel on Google's latest mobile OS. Now they're betting that reputation will sell their product: an AI-powered vulnerability scanner called Vega that they say beats tools from Anthropic and OpenAI at finding security holes in some of the world's most scrutinized codebases.

It's a bold pitch in an increasingly noisy market. And it hinges almost entirely on the credentials of people you've probably never heard of.

Security Researchers as Founders

Walk through Nebula's founding team and the pedigree is undeniable, if specialized. CEO Eten Zou earned a PhD studying automated vulnerability research. Yuan Tan, who dropped out of a doctoral program to work on DARPA-funded program analysis, has spoken at Black Hat USA. Frank Wu shipped full exploit chains targeting Chrome, Firefox, Linux, and Android—plus led a DARPA AIxCC team on automated program repair. He's been a Black Hat speaker and a DEF CON finalist; his competitive hacking team, r3kapig, topped CTFTime rankings in 2025. Xiaochuan Yu has hacked iPhone, Chrome, Firefox, Safari, and QEMU. His Chrome bug bounties alone have reportedly netted around $200,000. Three consecutive years as a DEF CON finalist.

These aren't typical startup founders. They're the sort of people companies hire to stress-test infrastructure before launch—or after a breach.

The Vancouver, Washington–based startup went through Y Combinator and describes itself as a team of "world-class hackers" who were "first to build an nginx RCE"—specifically for nginx-poolslip (CVE-2026-9256), distinct from the more widely cited NGINX Rift vulnerability—and "first to root Android 17 through a full browser-to-kernel exploit chain." That last claim—about Android 17—has circulated in security circles but hasn't been independently verified by major outlets. Which is part of the tension here: in vulnerability research, being first matters. Proving it publicly is harder.

What Vega Promises

Nebula positions Vega as an "AI security pipeline for codebases where security work needs to be reproducible, evidence-backed, and trustworthy." The tool integrates with GitHub for pull request reviews, runs via CLI for local and continuous integration scans, and works with agent-based IDEs like Claude Code and Cursor through an MCP tool.

The platform automates vulnerability hunting, generates root-cause analyses, proposes patches, and produces proof-of-concept exploits. Nebula's product page lists 730 validated findings: 698 Linux kernel bugs, eight Chrome zero-days, and 90 public CVEs. The company maintains a continuously updated public bug list, though there's no explicit timestamp showing when entries were last refreshed.

In benchmark comparisons the company supplied—pitting Vega against Anthropic's Claude Code Security and OpenAI's Codex Security, both announced earlier this year—Nebula claims its tool found more vulnerabilities in Chrome and the Linux kernel, though no methodology details are available publicly to substantiate these findings. That opacity is typical for early-stage security products, but it leaves potential customers flying somewhat blind.

Marketing Through Exploits

Digital illustration for article section "Marketing Through Exploits" in "Elite Hackers Launch AI Security Platform That Found 730+ Bugs" - A clean, minimal, and dynamic neo-cartoon pop illustration representing cybersecurity vulnerability ...

Since April, Nebula has been publishing vulnerability research with the cadence of a consultancy establishing credibility. On April 14, the team disclosed a Linux netfilter bug (CVE-2026-23274) that earned a $10,050 kernelCTF bounty. The writeup noted the company's pipeline had already found more than 300 kernel bugs by that point. On May 7 came analysis of a Chrome V8 remote code execution flaw (CVE-2026-5865). In June, the homepage teased "Longinus," referencing Chrome CVE-2026-6307.

The splashiest demonstration is IonStack, a public exploit page claiming to showcase "the first browser-to-kernel full-chain RCE on Android 17." The demo includes a vulnerable Firefox 151 APK and a "Live PWN" link, with source code promised after a countdown timer. It's the kind of thing that gets shared on Reddit and Hacker News. Whether it moves enterprise buyers is another question.

Then there's NGINX. Nebula's Y Combinator profile states the team was "first to build an nginx RCE." The widely cited NGINX Rift discovery (CVE-2026-42945)—an 18-year-old heap buffer overflow disclosed in May—credits DepthFirst and F5. Nebula's claim centers on a separate bug: nginx-poolslip (CVE-2026-9256), announced by the company on May 21. Third-party mirrors of F5's advisory list Mufeed VH of Winfunc Research, Nebula Security, and Vexera AI as co-discoverers. The distinction, parsing the language carefully, seems to be between finding a vulnerability and building an exploit for it. Meaningful to practitioners, perhaps less so to the uninitiated.

A Suddenly Crowded Space

Digital illustration for article section "A Suddenly Crowded Space" in "Elite Hackers Launch AI Security Platform That Found 730+ Bugs" - A conceptual, modern illustration depicting a "crowded space" and competitive "land grab" in the sof...

Nebula is hardly alone in this land grab.

Anthropic announced Claude Code Security on February 20. OpenAI launched Codex Security in research preview on March 6. GitHub added a dedicated "Copilot security review" command to its CLI in June. SonarSource rolled out MCP Server hooks and OWASP LLM reporting in its 2026.1 LTA release. Snyk positioned itself as an "AI Security Fabric" in May, introducing governance tooling for AI coding agents the following month.

Larger vendors have made their moves, too. Vectra AI launched a platform to "secure the AI enterprise" on February 21. Netskope unveiled Netskope One AI Security on March 11. Menlo Security announced a browser security platform for AI agents on March 18. Arctic Wolf introduced the Aurora Superintelligence Platform on March 23. Cisco and NVIDIA both announced joint AI defense initiatives—Cisco in mid-March, NVIDIA in late May.

The urgency isn't theoretical. A GitGuardian report cited by TechRadar Pro in April noted that over 29 million secrets leaked on GitHub in 2025 alone, with AI-generated code contributing to the problem. Everyone, it seems, is racing to sell the antidote.

Pricing (Such As It Is)

Nebula offers two tiers, neither with published pricing. Vega Scan is self-serve and automated, billed by usage based on repository size and complexity. It includes root-cause analysis, patch generation, proof-of-concept creation, and pull request review. The Premium Audit tier pairs a senior security engineer with Vega AI for architecture reviews, threat modeling, and on-premises audits. Both require you to sign up or reach out for a quote.

The company hasn't disclosed customers or partners publicly. Its Y Combinator profile lists no open job postings. Demo Day for YC's Summer 2026 batch is scheduled for September 10.

For now, Nebula's edge is founder credibility and a lengthening roster of high-profile bugs allegedly found by the tool they're selling. Whether that pedigree translates into paying customers—in a market already dense with billion-dollar incumbents and well-funded AI labs—is the open question.

Hacker bona fides are useful. They're rarely enough.

More stories

  • Subvocal launches under-chin wearable for silent computer control
  • DoD Solution raises $2M for AI drone navigation in war zones
  • YC's Archal Launches Verification Layer to Test AI Agents Before Production
  • MintMerchs Debuts AI Platform to Automate eCommerce Brand Creation
  • Bluetail's AI Takes On Aviation's $80B Paper Records Problem
  • Immigify Raises $1M to Automate US Immigration with AI Workflow
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.