Nebula Security is now backed by Y Combinator.
We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a url click can let attacker fully control your phone.
This is not only an Android root demo. We’re bringing you a full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 and all Linux distros in 15 years. "IonStack" demonstrates how bad actors can control your phone by sending a malicious URL, but good news, Nebula Security found it before attackers do.
Both 0-day were found by our code scanning agent, VEGA, overshadowing any vulnerabilities found by Mythos or any scanner you name it.
VEGA has demonstrated its extraordinary capability in finding critical bugs in the world’s most complicated software: operating systems and browsers. It can spot the same vulnerabilities in your codebase too.
VEGA support full scan and incremental scan that can integrated into your CI/CD flow. We launched VEGA within YC companies and received overwhelmingly positive feedback. Now it is open to all enterprise customers in private beta.
Book a demo with us: https://t.co/eXHKhnE8gC
Happy to share that I’ve been credited with CVE-2026-49141.
An authorization bypass vulnerability discovered during security research and responsibly disclosed.
https://t.co/d50oVCeBwV
#CVE#SecurityResearch#AppSec#CyberSecurity#InfoSec
Proud to share that I’ve achieved the Burp Suite Certified Practitioner (BSCP) certification ⚡
Certified. Caffeinated. Intercepting requests ⚡☕
Burp Suite Certified Practitioner achieved 💪
Thank you @PortSwigger 🧡
#BurpSuite#BSCP#AppSec#WebSecurity#CyberSecurity#Bug
Proud to share that I've earned the HTB CPTS certification from @hackthebox_eu .
First attempt failed due to reporting. Learned, improved, came back stronger.
Months of grind.
Brutally satisfying to get it done 💪
Thank you @hackthebox_eu 💜
#HackTheBox#HTB#CPTS
Introducing MSFTrecon -
MSFTRecon is a reconnaissance tool designed for red teamers and security professionals to map Microsoft 365 and Azure tenant infrastructure. It performs enumeration without requiring authentication, helping identify potential security misconfigurations and attack vectors.
https://t.co/LYXjnOGIoF
We’re sharing two papers on red teaming, which is an essential part of testing frontier AI models—a white paper on our approach for engaging external red teamers & a research study introducing a new automated red teaming method. https://t.co/JBS6hmRfw4
😈 Bypassing EDRs With EDR-Preloading
@MalwareTechBlog describes “EDR-Preloading,” which involves running malicious code before the EDR’s DLL is loaded into the process, enabling you to prevent it from running at all
🛠️ PoC: https://t.co/FMessXiRgc
https://t.co/yWKIRPrZeW
📦 Simulator: A Kubernetes security training platform
Creates a Kubernetes cluster in your AWS account; runs scenarios that misconfigure it and/or leave it vulnerable, trains you in mitigating them
→ 9 CTF scenarios
By @controlplaneio
https://t.co/w4v70q2AnY
Just released pdfrip v2.0.0! 🎉
A fast multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks.
GitHub: mufeedvh/pdfrip