Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

Subvocal launches under-chin wearable for silent computer control

Subvocal launches under-chin wearable for silent computer control
YcBrain Computer Interface+3
SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
Climate / Social Tech iconClimate / Social TechAugust 28, 2026

Mass Magnetics launches recycled rare-earth magnets in USA

Mass Magnetics launches recycled rare-earth magnets in USA
YcMaterials Science+3
SaaS iconSaaSAugust 28, 2026

Erinys launches AI-native plaintiff law firm network

Erinys launches AI-native plaintiff law firm network
YcLegal Tech+3

Founders Mentioned

Xiaochuan Yu

Nebula Security

saas icon
SaaS

Xiaochuan Yu

Nebula Security

saas icon
SaaS
SaaS iconSaaS
August 28, 2026
YcCybersecurityAi AgentsVulnerability DetectionAutonomous Systems

Nebula Security launches VEGA from world's #1 hacking team

YC-backed startup built by r3kapig elite hackers debuts autonomous AI agent that found 15-year-old Linux flaw, first Android 17 root, and nginx RCEs—targeting real-time vulnerability defense.

Nebula Security launches VEGA from world's #1 hacking team

A four-person startup from San Francisco has turned an autonomous AI agent loose on one of computing's most critical code bases and collected more than $92,000 for its trouble. Nebula Security disclosed in July that VEGA, its agentic vulnerability scanner, uncovered a 15-year-old privilege escalation flaw in the Linux kernel that earned the company $92,337 through Google's bug bounty program.

The timing speaks to both opportunity and anxiety in the security community. Just weeks earlier, an autonomous AI agent had breached Hugging Face infrastructure in what several outlets described as the first major compromise attributed to an agent operating without human oversight. Nebula's founders—members of r3kapig, the capture-the-flag team that CTFtime rankings show finished first globally in 2025—are betting they can weaponize the same offensive research skills that dominate hacking competitions and package them as a product.

Their pitch: find the vulnerabilities before someone else's agent does.

An agent that proves its own work

VEGA operates around the clock, monitoring code repositories and flagging security flaws with root-cause analysis, according to the company's listing on Y Combinator's startup directory. What distinguishes the tool, Nebula says, is that it generates working proof-of-concept exploits for each finding rather than simply surfacing potential weaknesses. The agent then suggests patches.

The product splits into two tiers. Individual researchers can access on-demand scanning through a pay-as-you-go model, while an enterprise plan adds supply-chain auditing and checks across cloud infrastructure, the company's site indicates.

The Linux kernel discovery—formally designated CVE-2026-43499 and nicknamed GhostLock by Nebula—represents a local privilege escalation flaw that has existed in every major Linux distribution since 2011. The Hacker News reported in July that researchers leveraged the vulnerability to construct a full-chain browser-to-root exploit targeting a recent Android version. Nebula has claimed the work achieved the world's first public root access for that Android release, though the specifics of mobile security often blur the line between proof-of-concept and practical threat.

ITPro wrote that GhostLock enables root access and container escape in under five seconds on unpatched systems. SecurityWeek confirmed the $92,337 payout from Google's vulnerability reward program.

A team built on offense

CEO Eten Zou holds a PhD in cybersecurity and has claimed victories at Pwn2Own, the high-profile hacking contest where researchers exploit commercial software for cash and recognition. CTO Yuan Tan has presented at Black Hat and led program analysis research funded by DARPA, according to Y Combinator materials. Co-founders Xiaochuan Yu and Frank Wu have published exploits targeting iPhone, Chrome, Firefox, and QEMU.

"We are here at Nebula Security for one reason, we are building the world's best cybersecurity agent," Zou wrote in a July announcement, a statement that reflects the confidence—some might say swagger—common among elite offensive researchers.

The startup says its team has collectively earned more than $400,000 from Google's vulnerability programs and disclosed over 90 CVEs. Frank Wu has won multiple Google kernelCTF competitions and published at USENIX and NDSS, academic venues where novel attack research gains credibility.

Digital illustration for article section "Content Section 3" in "Nebula Security launches VEGA from world's #1 hacking team" - A minimalist illustration representing cybersecurity bug bounty achievements and vulnerability disco...

A string of disclosures

Nebula disclosed two nginx remote code execution vulnerabilities in May and June, predating the VEGA launch. The company dubbed one flaw "nginx-quicburst" (CVE-2026-42530), which stems from a use-after-free bug in the HTTP/3 QPACK encoder. The vulnerability affects specific nginx versions with HTTP/3 enabled, according to the startup's tracker. Cybersecurity agencies in New York State and Singapore issued advisories, and the official nginx security page lists the CVEs alongside patched versions.

In a separate research series the company calls IonStack, Nebula documented how it chained a Firefox bug with GhostLock to achieve what the startup described as one-tap full device compromise on a recent Android release. The work illustrates how modern exploits often require linking multiple vulnerabilities across different software layers, though independent verification of the company's claims remains limited beyond the Google payout.

Agents everywhere, suddenly

Nebula enters a market that has rapidly crowded with security vendors pitching AI agents. Prophet Security raised a $30 million Series A from Accel and Bain Capital Ventures in April 2025 for what it calls an agentic AI SOC platform. Nudge Security announced AI agent discovery features in March. A separate company named Vega Security—unrelated to Nebula's VEGA product—closed a $120 million Series B in February for threat detection tools, TechCrunch reported at the time.

Digital illustration for article section "Content Section 4" in "Nebula Security launches VEGA from world's #1 hacking team" - A minimalist illustration of a single, bold yellow and green security shield standing out brilliantl...

The Cloud Security Alliance published research in July highlighting risks that autonomous agents introduce, including "excessive privilege" and "incomplete visibility into agent activity." The note referenced the Hugging Face breach, which caught the industry's attention not just for the compromise itself but for what it suggested about the unintended consequences of automation at scale.

Nebula has not disclosed customers or funding beyond its participation in Y Combinator. The company's website directs prospects to book a demo. Ankit Gupta is listed as the startup's primary partner at the accelerator, according to directory information accessed in late August. Whether the same hacking instincts that dominate CTF competitions translate to an enterprise product that companies will actually deploy remains an open question, though $92,337 from Google suggests the technical chops are real enough.

More stories

  • Subvocal launches under-chin wearable for silent computer control
  • DoD Solution raises $2M for AI drone navigation in war zones
  • Mass Magnetics launches recycled rare-earth magnets in USA
  • Erinys launches AI-native plaintiff law firm network
  • Understudy Labs launches AI inference cloud cutting costs 80%
  • Speko launches voice AI router to optimize STT, LLM, TTS
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.