Xiaochen Zou, who publishes as Eten (ETenal) and signs his work with the Chinese name 笑尘, is a Linux kernel security researcher turned founder. He earned a PhD in cybersecurity at UC Riverside under Zhiyun Qian, building automated tools that discovered dozens of kernel vulnerabilities, then worked as a security researcher at Microsoft before co-founding Nebula Security (YC S26), an AI-native cybersecurity company where he serves as CEO. Nebula pairs elite human hackers with an autonomous agent, VEGA, that finds bugs, writes proofs of concept, and proposes patches.
Nebula Security is an AI-native cybersecurity company from Y Combinator's Summer 2026 batch. Founded by world-class hackers - members of the world's #1 CTF team r3kapig, DEF CON finalists, Black Hat speakers, and a cybersecurity PhD - it pairs an autonomous code-scanning agent called VEGA with human expertise to audit software for vulnerabilities, from code-level bugs to architectural weaknesses. The team has earned $400K+ in bug bounties exploiting the Linux kernel and Chrome, and reported over a thousand vulnerabilities. Its pitch: 'Attackers already have AI. Get VEGA now.'
watchTowr is a Singapore-based cybersecurity company that builds a real-time attacker's view of an organization's external attack surface, then continuously discovers and validates exploitable vulnerabilities before adversaries can use them. Founded in 2021 by offensive-security specialist Benjamin Harris, its platform blends external attack surface management, continuous automated red teaming, AI-driven rapid reaction to emerging threats, and autonomous edge mitigation. watchTowr is also known for watchTowr Labs, a research team whose public disclosures on Citrix, Fortinet, Ivanti, SonicWall and other enterprise software regularly make headlines. The company serves Fortune 500 firms and critical-infrastructure operators and has raised roughly $29-30 million, including a $19M Series A led by Peak XV.
Ivan Novikov is the founder and CEO of Wallarm, an AI-powered API security platform that has raised over $70 million in funding including a $55M Series C in 2025. With 24+ years in cybersecurity, he is recognized as the inventor of memcached injection attacks and a pioneer of SSRF research, having earned bug bounty awards from Google, Facebook, Twitter, Tesla, and Yandex. A Y Combinator S16 alumnus with a physics background from Moscow State University, Novikov transformed hands-on offensive security expertise into a company protecting APIs for enterprises worldwide.