Nebula Security — YC S26 Xiaochen Zou named CEO & Cofounder 90+ CVEs discovered Pwn2Own 2021 Austin winner $400K in bug bounties 100+ Linux kernel patches accepted First team to root Android 17 Nebula Security — YC S26 Xiaochen Zou named CEO & Cofounder 90+ CVEs discovered Pwn2Own 2021 Austin winner $400K in bug bounties 100+ Linux kernel patches accepted First team to root Android 17
Profile · Security & Founders

The Bug Hunter Who Taught Machines to Break the Kernel

Xiaochen Zou spent years teaching software to find Linux kernel bugs and prove they were real. Now that instinct has a name, a team, and a Y Combinator batch: Nebula Security.

Most people who work in security spend a career chasing a single good bug. Xiaochen Zou went the other direction. Instead of hunting bugs one at a time, he built tools that hunt them by the dozen, then went a step further and taught those tools to write the exploit that proves the bug is dangerous. That second step is the whole story. In his world, a crash on its own is a rumor. An exploit is a fact.

He publishes under the name Eten, goes by ETenal online, and signs a lot of his work with the Chinese characters for his given name, 笑尘 - roughly, "laughing dust." It is a small, self-aware joke from someone who spends his days deep inside the machinery of the Linux kernel, the layer of software that sits under nearly everything and forgives nothing. Today he is the CEO and cofounder of Nebula Security, a company in Y Combinator's Summer 2026 batch. The path there was not a leap. It was a slow, deliberate walk in one direction.

01 / THE LABLearning to find what nobody meant to leave behind

Zou earned a PhD in cybersecurity at the University of California, Riverside, working under Zhiyun Qian. His dissertation carries a title that reads less like academic throat-clearing and more like a table of contents for a career: "Navigating Linux Kernel Bugs: Discovery, Triage, and Exploitation." Those three words - discovery, triage, exploitation - are not just chapter headings. They are the exact sequence a defender has to master to stay ahead of an attacker, and they became the backbone of everything he built next.

His research leaned on techniques with intimidating names - symbolic execution, static taint analysis, fuzzing - but the goal underneath them was human and simple. Modern software throws off thousands of crashes. Most are noise. A few are the beginning of a break-in. The hard part is not producing crashes. It is telling which ones matter, and doing it faster than the people who would abuse them.

A bug you cannot exploit is a rumor. Zou spent years turning rumors into facts, on purpose, so the right ones could be fixed first.

The papers came at a steady clip. KOOBE, at USENIX Security in 2020, tackled the automatic generation of exploits for a nasty class of kernel out-of-bounds write bugs. SyzScope, in 2022, went looking for the high-risk security impact buried inside crashes that a fuzzer had already thrown away as low-priority - the quiet ones that turn out to be the dangerous ones. Then SyzBridge and K-LEAK at NDSS in 2024, and StepStone heading to IEEE S&P in 2026. Along the way the work drew a Google Research Scholar reward and a trail of named vulnerabilities with catalog numbers attached.

KOOBE
USENIX '20
SyzScope
USENIX '22
SyzBridge / K-LEAK
NDSS '24
StepStone
IEEE S&P '26

Selected publications, by venue and year. Each entry represents peer-reviewed kernel and systems security research.

02 / THE PROOFA router in Austin

Research earns respect. A live hack earns attention. In 2021, at Pwn2Own in Austin, Zou put the theory on a stage and broke into the LAN interface of a NETGEAR R6700v3 router in front of the people whose job is to notice these things. Pwn2Own is not a paper. There is no reviewer to persuade. Either the exploit fires and the device falls, or it does not. His did.

That is the tension that runs through his whole record. The academic side wants rigor and reproducibility. The competitive side wants a working weapon on a countdown. Zou kept a foot in both, and the two reinforced each other. The rigor made the exploits reliable. The exploits made the rigor real.

90+
CVEs discovered
100+
Kernel patches accepted
$400K
In bug bounties
2021
Pwn2Own Austin win

Figures reflect achievements credited to Zou and the founding Nebula Security team.

After the PhD came a stint as a security researcher at Microsoft, near Bellevue - one of the largest attack surfaces on the planet, and a place where the difference between a theoretical bug and a shipped one is measured in millions of machines. It was the kind of vantage point that reframes a researcher's questions. Not just "can this be exploited?" but "who is going to find this first, and can I get there before them?"

笑尘 — "laughing dust." A physicist-sized joke about how small we are, chosen by a man who spends his days inside the largest attack surfaces ever built.On the name he signs his work with

03 / THE COMPANYCloning the instinct

Nebula Security is the answer to a problem Zou watched from the inside for years. The best security engineers are rare, expensive, and can only be in one place at a time. Most teams shipping code have never had one read their work. The company's bet is that you can take the instincts of a world-class hacking team and pour them into an autonomous agent - one that reads code the way Zou reads a kernel, at three in the morning, without getting tired or bored.

The agent is called VEGA. It watches a codebase around the clock, finds vulnerabilities, generates a proof of concept to show the bug is real, and proposes a patch. That structure should look familiar. It is discovery, triage, and exploitation - the exact spine of his dissertation - rebuilt as a product instead of a paper. The thesis turned out to be the roadmap.

A security engineer in your team.Nebula Security's one-line pitch

He did not build it alone. His three cofounders come out of the same elite corner of the hacking world - r3kapig, one of the top competitive CTF teams anywhere, and DARPA's AI Cyber Challenge, where machines are pitted against machines to find and fix bugs at scale. Between them the team claims a set of firsts that read like a dare: the first to build a remote code execution exploit against nginx, the first to root Android 17. In a team full of PhD dropouts who left the academy to hack full time, Zou is the one who stayed to finish the doctorate - the researcher's researcher among a crew of operators.

04 / THE PRODUCT IS TRUSTWhat "Audited by Nebula" is really selling

Here is the part that separates Nebula from a hundred other security tools. The most interesting thing the company is building is not the exploit. It is the trust. The idea is that "Audited by Nebula Security" becomes a badge a company can point to - a signal that customers and investors actually believe, because they know the people behind it can genuinely break things. The hacking is the evidence. The credibility is the product.

It is a subtle reframe, and a very founder-brained one. Anyone can run a scanner and hand over a PDF full of warnings. Far fewer can look at your architecture and tell you, with receipts, exactly how someone would get in - and then prove it, and then help you close it. Zou spent a decade earning the standing to make that claim. Now the company is trying to package that standing so other teams can borrow it.

05 / THE PERSONLaughing dust

For someone whose work is this adversarial, Zou wears it lightly. The online handle is plummm. The alias is ETenal. The name he signs, 笑尘, is the sort of thing you choose when you find the whole enterprise a little absurd and a little wonderful at once - dust that laughs. It fits a person who chose one of the least forgiving subjects in computing and then made a habit of automating the parts everyone else finds tedious.

The through-line of his story is not a dramatic pivot or a lucky break. It is patience pointed in a single direction. Discovery. Triage. Exploitation. He learned it in a lab, proved it on a stage, sharpened it inside one of the biggest software companies in the world, and is now betting that he can hand it to a machine and give it to everyone. If that works, the quietest founder in a loud field will have built something that never sleeps - and it will be looking for your bugs before anyone with worse intentions does.

2020
KOOBE published at USENIX Security - automated exploit generation for kernel out-of-bounds writes.
2021
Pwn2Own Austin win against the NETGEAR R6700v3 router LAN interface.
2022
SyzScope at USENIX Security surfaces high-risk impact hidden inside fuzzer-discarded bugs.
2023
Google Research Scholar reward for the SyzScope work.
2024
SyzBridge & K-LEAK published at NDSS on exploitability assessment and infoleak exploits.
2025
PhD defended at UC Riverside; security researcher at Microsoft near Bellevue.
2026
Nebula Security founded; joins Y Combinator's Summer 2026 batch as CEO.
CybersecurityLinux KernelVulnerability ResearchAI SecurityNebula SecurityYC S26Pwn2OwnFounderFuzzing