# Nebula Security

> Nebula Security is an AI-native cybersecurity company from Y Combinator's Summer 2026 batch. Founded by world-class hackers - members of the world's #1 CTF team r3kapig, DEF CON finalists, Black Hat speakers, and a cybersecurity PhD - it pairs an autonomous code-scanning agent called VEGA with human expertise to audit software for vulnerabilities, from code-level bugs to architectural weaknesses. The team has earned $400K+ in bug bounties exploiting the Linux kernel and Chrome, and reported over a thousand vulnerabilities. Its pitch: 'Attackers already have AI. Get VEGA now.'

- **Founded:** 2026
- **Headquarters:** Bellevue, Washington, USA
- **Founders:** Xiaochen (Eten) Zou (CEO & Cofounder - PhD in Cybersecurity, automated vulnerability research, former Microsoft), Yuan Tan (CTO & Cofounder - Black Hat USA speaker, PhD in System Security, DARPA-funded research), Frank Wu (Research Lead & Cofounder - r3kapig member, Black Hat speaker, DEF CON finalist, DARPA AIxCC repair team lead), Xiaochuan Yu (Research Lead & Cofounder - r3kapig core member, three-time DEF CON finalist, $200K+ Chrome bug bounty)
- **Team size:** 3-4 employees
- **Products:** VEGA (Vega Code Scan), Security Audit
- **Notable:** Earned $400K+ in bug bounties exploiting the Linux kernel and Chrome browser, Founders are members of r3kapig, ranked the world's #1 hacking/CTF team in 2025, Reported 1,000+ vulnerabilities across major software systems; 90+ CVEs assigned

## Products & services

- **VEGA (Vega Code Scan)** — An AI-native code-scanning agent that autonomously discovers bugs in codebases, monitors code changes continuously, analyzes root causes, generates proof-of-concept exploits, provides ready-to-use patches, and assesses overall code health. Marketed as 'Mythos-level protection to everyone.'
- **Security Audit** — Product security auditing conducted by Nebula's AI agent alongside world-class hackers, covering everything from code-level vulnerabilities to architectural weak points. Tagline: 'Don't let a data breach be your first security audit.'

## Achievements

- Earned $400K+ in bug bounties exploiting the Linux kernel and Chrome browser
- Founders are members of r3kapig, ranked the world's #1 hacking/CTF team in 2025
- Reported 1,000+ vulnerabilities across major software systems; 90+ CVEs assigned
- VEGA found 600+ vulnerabilities in a single scan and the team sent 100+ patches (demonstrated at a Linux netdev conference)
- Discovered IonStack - a browser-to-kernel exploit chain with two 0-days affecting Firefox and Linux, spanning 15 years
- First to build a remote-code-execution exploit for Nginx (nginx-poolslip, nginx-quicburst) and among first to root Android 17
- Accepted into Y Combinator Summer 2026
- Founders include DEF CON finalists, Black Hat USA speakers, and a Pwn2Own winner

## Latest updates

- **2026-07** — Nebula Security publicly launched as part of Y Combinator's Summer 2026 batch.
- **2026-07** — Featured among the standout YC S26 startups in early press coverage.
- **2026** — Demonstrated VEGA finding 600+ vulnerabilities in a single scan and submitting 100+ patches; unveiled the IonStack exploit chain.

## Links

- Website: https://nebusec.ai
- LinkedIn: https://www.linkedin.com/company/nebula-security/
- Twitter/X: https://x.com/nebusecurity
- GitHub: https://github.com/NebuSec

---

Profile page: https://yespress.io/nebula-security-yc-s26
Published by YesPress — https://yespress.io
Last updated: 2026-07-30
