Nebula Security is now backed by Y Combinator.
We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a url click can let attacker fully control your phone.
This is not only an Android root demo. We’re bringing you a full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 and all Linux distros in 15 years. "IonStack" demonstrates how bad actors can control your phone by sending a malicious URL, but good news, Nebula Security found it before attackers do.
Both 0-day were found by our code scanning agent, VEGA, overshadowing any vulnerabilities found by Mythos or any scanner you name it.
VEGA has demonstrated its extraordinary capability in finding critical bugs in the world’s most complicated software: operating systems and browsers. It can spot the same vulnerabilities in your codebase too.
VEGA support full scan and incremental scan that can integrated into your CI/CD flow. We launched VEGA within YC companies and received overwhelmingly positive feedback. Now it is open to all enterprise customers in private beta.
Book a demo with us: https://t.co/eXHKhnE8gC
Slides for our OffensiveCon talk (by me and @jmartijnb) https://t.co/F3yM2pIgwy:
A tiny mistake in a render config ➡️ corrupt a special GPU stack pointer register ➡️ GPU hardware “renders” pixels to the AP kernel directly ➡️ pwned
More presentations: https://t.co/0QOsr0uuTJ :)
Every calculation you have ever done uses a system India invented.
Before Indian mathematicians gave the world zero and the decimal place, Greek and Roman maths used letters for numbers. Try multiplying MXLVII by CCXCIV. Merchants, architects and astronomers across the ancient world were trapped.
Baghdad's Al-Khwarizmi (c.780–847) transmitted it west. His book on the Indian place system and algorithmic calculation laid the foundation of modern mathematics. The word "algorithm" is a corruption of his name. "Algebra" comes from his treatise title. Both are Arabic transmissions of Indian originals.
Abraham Seidenberg's History of Mathematics credits India's Sulba Sutras as the inspiration for all mathematics of the ancient world.
Lin Yutang, Chinese philosopher: "India was China's teacher in trigonometry, quadratic equations, grammar, phonetics."
Carl Sagan thought Vedic cosmology the only ancient system whose timescales correspond to modern scientific cosmology.
Every time a computer runs, it counts in a system India designed.
One of the best FREE Windows exploit development and security research blogs out there. Kernel pool exploitation. PTE overwrites. HVCI and kernel CFG bypass. XFG internals. Browser type confusion. Kernel shadow stacks. Secure kernel internals. ARM64 Pointer Authentication bypass. ETW and PPL research.
Covers everything from ROP fundamentals all the way to cutting edge ARM64 and VBS security research. Still actively publishing in 2026.
https://t.co/tyfevXiWOp
Author: @33y0re
#ExploitDevelopment #WindowsInternals #ReverseEngineering
Welp it's official, blogger started removing my posts as well, crazy how even google is hating me now.
Is that like supposed to make stop ? Kinda feeling even more motivated.
3-part series on Linux kernel bug hunting: KASAN, Syzkaller, and kernel fuzzing by @slava_moskvin_
Part 1: https://t.co/b61r4je69j
Part 2: https://t.co/DQ8j6YfN2C
Part 3: https://t.co/Myjt0BpsPy
#infosec
🚨 Introducing "ITScape" (CVE-2026-46316)
A Guest-to-Host Escape in KVM/arm64. Guest-side actions alone exploit a use-after-free to run root-privileged code in the host kernel.
Unlike the commonly published QEMU escapes, the bug lives in in-kernel KVM, not QEMU. On a successful exploit, commands run with host kernel privilege rather than the privilege of a user process, threatening the guest-host isolation of multi-tenant arm64 public clouds.
To the best of public knowledge, the first Guest-to-Host Escape Exploit targeting in-kernel KVM/arm64.
Details: https://t.co/CtZOQEzIdg
‼️ Nightmare Eclipse is back on GitHub under a new alias and has released a new Windows Defender vulnerability zero-day called RoguePlanet.
PoC: https://t.co/n0xF6uGt4u
New GitHub Account: https://t.co/qwU93VedpH