LIVE · cybersecurity feed
Live wire
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update releaseAttackers exploit zero-days in consistently besieged SonicWall productIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
ai

BreachX Launches Typhon, India-Built Sovereign Cybersecurity AI for Zero-Day Discovery and Defense

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

zeroday.news ·

From left: Air Vice Marshal A Suresh Kumar VSM (Retd), Consultant for CAG; Group Captain P. Aanand Naidu (Retd); Vijaykrishna Shetty, Co-Founder and CEO, BreachX; Air Chief Marshal R. K. S. Bhadauria, PVSM, AVSM, VM, ADC (Retd); Dr. Ranjana, Outstanding Scientist and Director, DFTM, DRDO; and Rajshekhar Pullabhatla, Founder, BreachX, at the Typhon launch at The Oberoi, New Delhi.

NEW DELHI, India, September 3, 2026: BreachX, an AI cybersecurity company and zero-day research lab, today unveiled Typhon, a family of sovereign cybersecurity AI models designed to discover previously unknown vulnerabilities, determine whether they can be exploited and generate protection, all within infrastructure controlled by the customer.

Built for government, defense, enterprises and critical infrastructure, Typhon can operate on-premises, in private clouds and in fully air-gapped environments. Source code, firmware, vulnerability findings and customer-specific security intelligence do not need to leave the organization's security boundary.

Typhon is built around a simple security sequence: Discover. Validate. Protect.

In eight weeks of live vulnerability research, Typhon identified more than 100 previously unknown vulnerabilities. BreachX has submitted 65 findings across approximately 50 products to vendors through coordinated disclosure. Five findings have received CVE identifiers, while another resulted in a public Flatpak security advisory.

Typhon works alongside BreachX PatchZero, which uses validated vulnerability evidence to generate protection before an official software vendor patch becomes available.

Moving Cybersecurity from Detection to Discovery

Most cybersecurity technologies focus on detecting known threats, identifying catalogued vulnerabilities or responding after malicious activity has begun. BreachX built Typhon to move security earlier in the lifecycle, to discovering weaknesses before they are known or exploited.

Typhon analyzes source code, binaries, mobile applications and firmware to identify potential vulnerabilities that have not previously been reported. It can reason across those weaknesses to construct plausible attack paths and validate findings by generating and executing proof-of-concept exploits in isolated environments rather than against production systems.

The result is evidence that security teams can use to distinguish theoretical weaknesses from vulnerabilities that represent credible real-world risk.

"Software has reached machine scale, but finding its weaknesses still depends heavily on scarce human expertise," said Rajshekhar Pullabhatla, Founder of BreachX. "Typhon enables security teams to examine code and systems at machine scale while keeping their most sensitive assets inside their own perimeter. The objective is simple: find the weakness before the attacker does, and start protecting against it first."

Rajshekhar Pullabhatla, Founder of BreachX, with the Typhon Inside module.
Rajshekhar Pullabhatla, Founder of BreachX, with the Typhon Inside module.

Sovereign AI Designed for Sensitive Environments

Typhon runs within infrastructure controlled by the customer. Source code, firmware, vulnerability information and other sensitive security data can remain within that environment throughout the discovery, validation and protection process.

Organizations can also further post-train Typhon using their own code, security findings and telemetry within their security boundary. Those adaptations remain with the customer and are not returned to BreachX.

Typhon is available in four mission-specific editions:

The editions vary in model size, deployment architecture, data-handling requirements and the cybersecurity research corpus used for specialization.

Typhon models are engineered and post-trained by BreachX in Bengaluru, India, using open base models specialized for cybersecurity, with BreachX-held model weights deployed inside customer environments.

Cybersecurity Intelligence Built Over Years

Typhon's capabilities come from cybersecurity-specific post-training rather than relying solely on general-purpose model knowledge.

Its training and research corpus draws from three layers of security intelligence:

The corpus includes both successful vulnerability discoveries and abandoned research paths, enabling Typhon to learn from the reasoning process involved in vulnerability research, not simply from databases of previously known vulnerabilities.

"AI is going to change how vulnerabilities are found and how attacks are executed, on both sides," said Vijaykrishna Shetty, Co-Founder and CEO of BreachX. "Reacting faster will not be enough. Organizations need systems that continuously discover vulnerabilities, determine whether they are genuinely exploitable and then protect against them. We engineered Typhon and PatchZero in India with sovereignty, privacy and real-world deployment conditions designed in from the beginning."

Vijaykrishna Shetty, Co-Founder and CEO of BreachX, with the Typhon Inside module at the launch in New Delhi.
Vijaykrishna Shetty, Co-Founder and CEO of BreachX, with the Typhon Inside module at the launch in New Delhi.

From Discovery to Protection

Typhon and PatchZero operate as a continuous workflow.

Typhon identifies a potential vulnerability, analyzes how it could be reached and validates the finding through controlled testing. PatchZero then uses that evidence to generate protection within the customer's environment, helping reduce the exposure window between vulnerability discovery and the availability and deployment of an official vendor patch.

Both systems can operate entirely on customer-controlled infrastructure.

More Than 100 Previously Unknown Vulnerabilities Identified

BreachX has tested Typhon against widely deployed production software as part of its coordinated vulnerability disclosure program.

During an eight-week research period, Typhon identified more than 100 previously unknown vulnerabilities.

Of these, 65 findings across approximately 50 products have been submitted to software vendors under coordinated disclosure, with many still undergoing remediation. Additional findings involving defense-sensitive systems remain under restricted review and are not being publicly disclosed.

Five findings have received Common Vulnerabilities and Exposures (CVE) identifiers, while another resulted in a public Flatpak security advisory. Published findings affect widely deployed technologies including Wireshark, NetworkManager and SSSD.

The Wireshark advisory for CVE-2026-76918 credits BreachX Zero Day Labs with discovering a heap overflow in the SSH protocol dissector. The vulnerable code had been present in the codebase since 2020.

A separate Flatpak security advisory credits BreachX Zero Day Labs and identifies Typhon AI Mil v2 as the system used in the discovery.

Independent Assessment and Benchmarking

In August 2026, the Indian Computer Emergency Response Team (CERT-In) independently assessed Typhon in a seeded zero-day discovery exercise.

According to the assessment provided to BreachX, Typhon identified all six seeded flaws and achieved 100% precision in that exercise, while producing supporting evidence for each finding. The assessment also identified areas for improvement, which BreachX says have been addressed in the release announced today.

In BreachX's evaluation on CyBench, a public benchmark covering professional-level cybersecurity tasks, Typhon achieved a 93.3% solve rate, placing it No. 3 in the evaluated leaderboard configuration.

The AI Security Race Is Moving Upstream

AI is accelerating both software development and offensive security research. As vulnerability research becomes increasingly machine-assisted, the time between the creation or discovery of a software weakness and attempts to exploit it is expected to shrink.

That changes the security equation.

Detection remains essential, but BreachX believes the next frontier of cybersecurity will increasingly move upstream: using AI to discover vulnerabilities before attackers exploit them, validate whether those weaknesses form credible attack paths, and generate protection before an official patch is available.

Industry Perspective

"BreachX Typhon is exactly the kind of leap security needs right now: zero-day discovery, kill-chain generation, exploit validation and patch creation, all at machine speed," said Sudhir Prasad, Director, Software Supply Chain Security at IBM-Red Hat. "In a world where AI-driven attacks can strike within hours, that speed isn't optional anymore, it's essential. And doing it all on-premises, without crown-jewel data leaving the organization's environment, addresses one of the most important barriers to enterprise adoption of cybersecurity AI."

Unveiled Live in New Delhi

BreachX unveiled Typhon at The Oberoi, New Delhi, before an invited audience from government, defense, cybersecurity, industry and media.

Rather than presenting a recorded demonstration, BreachX demonstrated Typhon live, using the system to discover and validate vulnerabilities in code during the event.

Air Chief Marshal R. K. S. Bhadauria, PVSM, AVSM, VM, ADC (Retd.), former Chief of the Air Staff of the Indian Air Force, attended as Chief Guest and delivered the keynote address.

Air Chief Marshal R. K. S. Bhadauria, PVSM, AVSM, VM, ADC (Retd), former Chief of the Air Staff, delivering the keynote as Chief Guest.
Air Chief Marshal R. K. S. Bhadauria, PVSM, AVSM, VM, ADC (Retd), former Chief of the Air Staff, delivering the keynote as Chief Guest.

Describing BreachX's decision to demonstrate the technology live, Air Chief Marshal Bhadauria called it "a gutsy demonstration of the capability, given the risks."

"It is a huge achievement," he said. "This is the first time I have seen the result of a product that can go into service."

Dr. Ranjana, Outstanding Scientist and Director of the Directorate of Futuristic Technology Management (DFTM), Defence Research and Development Organisation (DRDO), attended as Guest of Honour.

Dr. Ranjana, Outstanding Scientist and Director of the Directorate of Futuristic Technology Management (DFTM), DRDO, who attended as Guest of Honour.
Dr. Ranjana, Outstanding Scientist and Director of the Directorate of Futuristic Technology Management (DFTM), DRDO, who attended as Guest of Honour.

"When I was CISO there were too many sleepless nights," said Dr. Ranjana. "But probably this makes me think, why did I even leave that role? Now I can sleep much more peacefully with this kind of thing. That is the promise you have made today."

"As the Air Chief Marshal said, it was a very gutsy decision from you," she added. "It is very encouraging that Indians have taken this bull by the horns, and I think we will not miss this bus, thanks to people like you."

The event included BreachX's vision for sovereign cybersecurity AI and a 45-minute live demonstration led by Product Head Alok Tripathi, with opening remarks by Group Captain P. Aanand Naidu (Retd.).

Availability

Typhon is available now for deployment across government, defense, enterprise and critical-infrastructure environments. BreachX PatchZero is available with Typhon deployments.

Prospective customers can evaluate Typhon against a system of their own choosing, allowing their security teams to directly measure what the technology discovers, validates and helps protect.

More information is available at breachx.ai.

About BreachX

BreachX is an AI cybersecurity company and zero-day research lab building security technology in India for organizations worldwide.

The company engineers and post-trains cybersecurity-specialized AI models for zero-day vulnerability discovery, attack-path analysis, exploit validation and automated security testing. BreachX also develops PatchZero, which generates protection against newly discovered vulnerabilities before an official vendor patch becomes available.

BreachX combines proprietary vulnerability research, public and community security intelligence, physical cyber ranges, incident-response experience and security researcher expertise. Its technology is designed for customer-controlled deployment across on-premises, private-cloud and air-gapped environments.

BreachX is backed by Shastra VC, the founders of Quick Heal Technologies, and Information Security Media Group.

Media contact: media@breachx.ai

Note to Editors

Public vendor advisories related to BreachX vulnerability research include:

Additional vulnerability findings remain under coordinated disclosure or restricted review and are not being publicly disclosed at this time.

aibreachxtyphonzero-daysovereign aiindia
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

ai

OpenAI Agents Hacked Another Website

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

nation-state

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

ai

numbat - AI agent observability, (Fri, Sep 4th)



CVE-2026-81578

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

vulnerabilitycritical

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a