Nebula Security

Services · Security audit

Audits
from the kernel up.

We audit the stacks we spend our days breaking — operating systems, browsers, agentic infrastructure, and the web infrastructure that ties them together. Every engagement pairs senior researchers with Vega, our AI vulnerability research pipeline, so coverage scales without losing depth.

What we audit

Six practices, one standard.

01

Operating System

Kernel and platform review: memory corruption, race conditions, and privilege-escalation paths in the subsystems where they hide — network stacks, filesystems, drivers, and syscall surfaces.

  • Linux kernel
  • Windows
  • Embedded & firmware

Track record

897 Linux kernel bugs reported upstream.

Multiple KernelCTF wins.

15-year-old GhostLock — the world first Android 17 root exploit.

02

Browser

JavaScript engines and the sandboxes around them: JIT miscompilations, type confusions, renderer-to-browser escapes, and the IPC boundaries in between.

  • Chrome / V8
  • Firefox
  • QuickJS

Track record

Chrome VRP Top 20.

Multiple Chrome zero-days and counting — from Maglev miscompiles to a single bug piercing both the renderer and the V8 sandbox.

03

Agentic Infrastructure

The newest attack surface: MCP servers, tool sandboxes, agent frameworks, and model-facing APIs. We chase prompt-injection-to-code-execution chains, tool-permission bypasses, and data-exfiltration paths.

  • MCP servers
  • Agentic browser
  • Agentic sandbox

Track record

Multiple vulnerabilities found in major agentic sandbox and browser.

04

Web Infrastructure

Classic surface, modern depth: authentication and session logic, injection, SSRF, deserialization, and business-logic flaws. White-box first, validated with working proofs of concept.

  • WordPress
  • nginx
  • Custom backends

Track record

Findings across WordPress, nginx, curl, and research platforms — every report ships with a PoC.

05

Solidity

Source-level smart contract review: reentrancy, access control, price-oracle manipulation, upgradeability pitfalls, and the business-logic flaws that drain protocols.

  • DeFi protocols
  • Token contracts
  • Upgradeable proxies

Track record

The same exploit-first standard, applied to code that moves funds.

06

EVM (Ethereum Virtual Machine)

The execution layer itself: bytecode-level review, compiler-introduced bugs, gas and storage-layout semantics, and the places where source-level intuition and on-chain behavior diverge.

  • EVM bytecode
  • Compiler output
  • L2 / EVM-equivalent chains

Track record

Bytecode-level findings that source review alone misses.

How we work

Exploit first, write second.

The report is the artifact, but the exploit is the evidence. Nothing lands in a deliverable that we haven't proven.

  1. 01

    Scope

    A short call to map targets, threat model, and timeline. Fixed quote, no surprises.

  2. 02

    Recon

    Attack-surface enumeration: entry points, trust boundaries, and the code paths that actually matter.

  3. 03

    Hunt

    Senior researchers and Vega work the same codebase — manual review for logic, the AI pipeline for scale, fuzzing where it pays.

  4. 04

    Validate

    Every finding is exploited or reproduced before it is written down. No speculative severity.

  5. 05

    Report & retest

    Root cause, impact, and fix guidance your engineers can act on — plus a retest window after patches land.

By the numbers

0

bugs found and reported

0

CVEs assigned

0

Chrome zero-days

$0K+

in bug bounties earned

Don't let a data breach be your first security audit.