Nebula Security
A security engineer in your team
About Nebula Security
Nebula Security is an AI-native cybersecurity company founded by world-class hackers. Nebula Security provides Mythos-level cybersecurity reviews and product security auditing, conducted by our state-of-the-art AI agent and world-class hackers themselves, covering everything from code-level vulnerabilities to architectural weak points. We were the first team to build an nginx RCE and the first to root Android 17. Our co-founders include members of the world’s No. 1 CTF team, DEF CON winners, Black Hat speakers, and PhD in cybersecurity. We have won $400K in bug bounties by exploiting the Linux kernel and Chrome browser. “Audited by Nebula Security” is a mark of serious security credibility: a signal to customers, investors, and partners that your product has been reviewed by the world’s best hackers.
Public traction evidence
Each signal links to the public source used for attribution.
- GitHub
NebuSec/CyberMeowfia
NebuSec/CyberMeowfia. YC S26 snapshot lists Nebula Security with official GitHub org https://github.com/NebuSec; repo lives under that org.
- X
Nebula Security is now backed by Y Combinator. We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a ur…
Nebula Security is now backed by Y Combinator. We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a url click can let attacker fully control your phone. This is not only an Android root demo. We’re bringing you a full chain browser-to-kernel...
- X
When the attackers have AI, how do you prevent the next HuggingFace incident from happening to your product? Today, we launch VEGA with @ycombinator , a beyond Mythos level cybersecurity agent that finds critical vulnerabilities before your product ships. VEGA reviews your
When the attackers have AI, how do you prevent the next HuggingFace incident from happening to your product? Today, we launch VEGA with @ycombinator , a beyond Mythos level cybersecurity agent that finds critical vulnerabilities before your product ships. VEGA reviews your
- X
IIRC, this was the last LTS and one of the two COS slots before Google changed kernelCTF's rules and removed the COS target. Under the n...
IIRC, this was the last LTS and one of the two COS slots before Google changed kernelCTF's rules and removed the COS target. Under the new rules, this bug would worth $101,337.
- X
I am so proud that I am now driving the ultimate pwning machine at Nebula Security. Btw our team will be at Y Combinator Dogpatch site to...
I am so proud that I am now driving the ultimate pwning machine at Nebula Security. Btw our team will be at Y Combinator Dogpatch site tomorrow, feel free to talk with us if you are interested in Vega (and probably more 0days?)
- X
Some people say that a goldfish's memory lasts only 7 seconds, so can a goldfish fully remember the process of our exploitation?
Some people say that a goldfish's memory lasts only 7 seconds, so can a goldfish fully remember the process of our exploitation?
- X
We spent a long time on this writeup. Hope you like it. One interesting thing is our human research team finishing the d8 shell exploit ...
We spent a long time on this writeup. Hope you like it. One interesting thing is our human research team finishing the d8 shell exploit in <10min after Vega found this vulnerability. https://nebusec.ai/research/v8-cve-2026-6307-writeup/?p
- X
Extremely brilliant, especially when security is full of AI shit.
Extremely brilliant, especially when security is full of AI shit.