Xiaochen Zou spent years teaching software to find Linux kernel bugs and prove they were real. Now that instinct has a name, a team, and a Y Combinator batch: Nebula Security.
Most people who work in security spend a career chasing a single good bug. Xiaochen Zou went the other direction. Instead of hunting bugs one at a time, he built tools that hunt them by the dozen, then went a step further and taught those tools to write the exploit that proves the bug is dangerous. That second step is the whole story. In his world, a crash on its own is a rumor. An exploit is a fact.
He publishes under the name Eten, goes by ETenal online, and signs a lot of his work with the Chinese characters for his given name, 笑尘 - roughly, "laughing dust." It is a small, self-aware joke from someone who spends his days deep inside the machinery of the Linux kernel, the layer of software that sits under nearly everything and forgives nothing. Today he is the CEO and cofounder of Nebula Security, a company in Y Combinator's Summer 2026 batch. The path there was not a leap. It was a slow, deliberate walk in one direction.
Zou earned a PhD in cybersecurity at the University of California, Riverside, working under Zhiyun Qian. His dissertation carries a title that reads less like academic throat-clearing and more like a table of contents for a career: "Navigating Linux Kernel Bugs: Discovery, Triage, and Exploitation." Those three words - discovery, triage, exploitation - are not just chapter headings. They are the exact sequence a defender has to master to stay ahead of an attacker, and they became the backbone of everything he built next.
His research leaned on techniques with intimidating names - symbolic execution, static taint analysis, fuzzing - but the goal underneath them was human and simple. Modern software throws off thousands of crashes. Most are noise. A few are the beginning of a break-in. The hard part is not producing crashes. It is telling which ones matter, and doing it faster than the people who would abuse them.
The papers came at a steady clip. KOOBE, at USENIX Security in 2020, tackled the automatic generation of exploits for a nasty class of kernel out-of-bounds write bugs. SyzScope, in 2022, went looking for the high-risk security impact buried inside crashes that a fuzzer had already thrown away as low-priority - the quiet ones that turn out to be the dangerous ones. Then SyzBridge and K-LEAK at NDSS in 2024, and StepStone heading to IEEE S&P in 2026. Along the way the work drew a Google Research Scholar reward and a trail of named vulnerabilities with catalog numbers attached.
Research earns respect. A live hack earns attention. In 2021, at Pwn2Own in Austin, Zou put the theory on a stage and broke into the LAN interface of a NETGEAR R6700v3 router in front of the people whose job is to notice these things. Pwn2Own is not a paper. There is no reviewer to persuade. Either the exploit fires and the device falls, or it does not. His did.
That is the tension that runs through his whole record. The academic side wants rigor and reproducibility. The competitive side wants a working weapon on a countdown. Zou kept a foot in both, and the two reinforced each other. The rigor made the exploits reliable. The exploits made the rigor real.
Figures reflect achievements credited to Zou and the founding Nebula Security team.
After the PhD came a stint as a security researcher at Microsoft, near Bellevue - one of the largest attack surfaces on the planet, and a place where the difference between a theoretical bug and a shipped one is measured in millions of machines. It was the kind of vantage point that reframes a researcher's questions. Not just "can this be exploited?" but "who is going to find this first, and can I get there before them?"
Nebula Security is the answer to a problem Zou watched from the inside for years. The best security engineers are rare, expensive, and can only be in one place at a time. Most teams shipping code have never had one read their work. The company's bet is that you can take the instincts of a world-class hacking team and pour them into an autonomous agent - one that reads code the way Zou reads a kernel, at three in the morning, without getting tired or bored.
The agent is called VEGA. It watches a codebase around the clock, finds vulnerabilities, generates a proof of concept to show the bug is real, and proposes a patch. That structure should look familiar. It is discovery, triage, and exploitation - the exact spine of his dissertation - rebuilt as a product instead of a paper. The thesis turned out to be the roadmap.
He did not build it alone. His three cofounders come out of the same elite corner of the hacking world - r3kapig, one of the top competitive CTF teams anywhere, and DARPA's AI Cyber Challenge, where machines are pitted against machines to find and fix bugs at scale. Between them the team claims a set of firsts that read like a dare: the first to build a remote code execution exploit against nginx, the first to root Android 17. In a team full of PhD dropouts who left the academy to hack full time, Zou is the one who stayed to finish the doctorate - the researcher's researcher among a crew of operators.
Here is the part that separates Nebula from a hundred other security tools. The most interesting thing the company is building is not the exploit. It is the trust. The idea is that "Audited by Nebula Security" becomes a badge a company can point to - a signal that customers and investors actually believe, because they know the people behind it can genuinely break things. The hacking is the evidence. The credibility is the product.
It is a subtle reframe, and a very founder-brained one. Anyone can run a scanner and hand over a PDF full of warnings. Far fewer can look at your architecture and tell you, with receipts, exactly how someone would get in - and then prove it, and then help you close it. Zou spent a decade earning the standing to make that claim. Now the company is trying to package that standing so other teams can borrow it.
For someone whose work is this adversarial, Zou wears it lightly. The online handle is plummm. The alias is ETenal. The name he signs, 笑尘, is the sort of thing you choose when you find the whole enterprise a little absurd and a little wonderful at once - dust that laughs. It fits a person who chose one of the least forgiving subjects in computing and then made a habit of automating the parts everyone else finds tedious.
The through-line of his story is not a dramatic pivot or a lucky break. It is patience pointed in a single direction. Discovery. Triage. Exploitation. He learned it in a lab, proved it on a stage, sharpened it inside one of the biggest software companies in the world, and is now betting that he can hand it to a machine and give it to everyone. If that works, the quietest founder in a loud field will have built something that never sleeps - and it will be looking for your bugs before anyone with worse intentions does.