YC Summer 2026 (S26) company

Nebula Security

Autonomous AI defense system for cyber attack

b2bsecuritycybersecurityenterpriseaiindustrial88 public signals

About Nebula Security

Nebula Security is founded by the world’s #1 hacking team. We were the first team to build an nginx RCE and the first to root Android 17. Our co-founders include members of the world’s No. 1 CTF team, DEF CON winners, Black Hat speakers, and PhD in cybersecurity. We have won $400K in bug bounties by exploiting the Linux kernel and Chrome browser. “Audited by Nebula Security” is a mark of serious security credibility: a signal to customers, investors, and partners that your product has been reviewed by the world’s best hackers.

Public traction evidence

Each signal links to the public source used for attribution.

  1. X

    Merry Christmas! Jailbreak for all arm64 iOS 16.0 to iOS 16.5 devices! https://t.co/Hg5sGK0Iwy

    Merry Christmas! Jailbreak for all arm64 iOS 16.0 to iOS 16.5 devices! https://t.co/Hg5sGK0Iwy

  2. X

    Nebula Security is now backed by Y Combinator. We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a ur…

    Nebula Security is now backed by Y Combinator. We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a url click can let attacker fully control your phone. This is not only an Android root demo. We’re bringing you a full chain browser-to-kernel...

  3. X

    Here goes nginx-quicburst (CVE-2026-42530), a new RCE in Nginx discovered by our security agent VEGA and demonstrated by Nebula Security.

    Here goes nginx-quicburst (CVE-2026-42530), a new RCE in Nginx discovered by our security agent VEGA and demonstrated by Nebula Security. This is only the third NGINX vulnerability since 2014 to receive NGINX’s “major” severity rating. If you use Nginx 1.31 with QUIC enabled,...

  4. X

    Watch us open the camera and uncover the anonymous identity behind Tor browser: We published the writeup for the browser RCE in IonStack.

    Watch us open the camera and uncover the anonymous identity behind Tor browser: We published the writeup for the browser RCE in IonStack. Mythos reported 271 bugs in Firefox 150 but still missed this one. And the Tor Browser is also affected by CVE-2026-10702. Update your Tor!...

  5. X

    We won kernelCTF again with a new 0-day vulnerability and eligible for another $100k bounty

    We won kernelCTF again with a new 0-day vulnerability and eligible for another $100k bounty

  6. X

    After the Hugging Face incident, have you wondered how easy it is to escape a modern agent sandbox? We benchmarked eight open-source agent sandboxes to show how vulnerable they can be, and why frontier models can break out so easily.

    After the Hugging Face incident, have you wondered how easy it is to escape a modern agent sandbox? We benchmarked eight open-source agent sandboxes to show how vulnerable they can be, and why frontier models can break out so easily. https://t.co/gkwdNz0wKT

  7. X

    25 elite hacking teams raced in the final kernelCTF.

    25 elite hacking teams raced in the final kernelCTF. NebuSec closed out the history of the classic kernelCTF with 99% exploit stability, 0.1s exploit time, and 0.000461s submission time. We’ll soon open-source our kernelCTF infra and a walkthrough of how we won every kCTF we

  8. X

    When the attackers have AI, how do you prevent the next HuggingFace incident from happening to your product? Today, we launch VEGA with @ycombinator , a beyond Mythos level cybersecurity agent that finds critical vulnerabilities before your product ships.

    When the attackers have AI, how do you prevent the next HuggingFace incident from happening to your product? Today, we launch VEGA with @ycombinator , a beyond Mythos level cybersecurity agent that finds critical vulnerabilities before your product ships. VEGA reviews your...