
NebuSec
@nebusecurity • 7,160 subscribers
An AI defense system for cyber attack | YC S26
Shorts
Videos

Nebula Security is now backed by Y Combinator. We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a url click can let attacker fully control your phone. This is not only an Android root demo. We’re bringing you a full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 and all Linux distros in 15 years. "IonStack" demonstrates how bad actors can control your phone by sending a malicious URL, but good news, Nebula Security found it before attackers do. Both 0-day were found by our code scanning agent, VEGA, overshadowing any vulnerabilities found by Mythos or any scanner you name it. VEGA has demonstrated its extraordinary capability in finding critical bugs in the world’s most complicated software: operating systems and browsers. It can spot the same vulnerabilities in your codebase too. VEGA support full scan and incremental scan that can integrated into your CI/CD flow. We launched VEGA within YC companies and received overwhelmingly positive feedback. Now it is open to all enterprise customers in private beta. Book a demo with us:
NebuSec225,352 görüntüleme • 2 ay önce

Watch us open the camera and uncover the anonymous identity behind Tor browser: We published the writeup for the browser RCE in IonStack. Mythos reported 271 bugs in Firefox 150 but still missed this one. And the Tor Browser is also affected by CVE-2026-10702. Update your Tor!
NebuSec73,584 görüntüleme • 1 ay önce

Here goes nginx-quicburst (CVE-2026-42530), a new RCE in Nginx discovered by our security agent VEGA and demonstrated by Nebula Security. This is only the third NGINX vulnerability since 2014 to receive NGINX’s “major” severity rating. If you use Nginx 1.31 with QUIC enabled, we recommend upgrading to the latest version. This bug has been patched in the latest Nginx release. We will publish the technical writeup, including the ASLR bypass, on July 18 together with the previous nginx-poolslip writeup.
NebuSec106,081 görüntüleme • 2 ay önce

When the attackers have AI, how do you prevent the next HuggingFace incident from happening to your product? Today, we launch VEGA with Y Combinator , a beyond Mythos level cybersecurity agent that finds critical vulnerabilities before your product ships. VEGA reviews your source code, identifies vulnerabilities before release, monitors infrastructure and supply-chain risks, investigates attack paths, and fixes issues before attackers find them. AI makes you fast. VEGA makes you secure. Learn more at
NebuSec36,022 görüntüleme • 1 ay önce
Daha fazla içerik yok.