NEW DELHI, India, September 3, 2026: BreachX, an AI cybersecurity company and zero-day research lab, today unveiled Typhon, a family of sovereign cybersecurity AI models designed to discover previously unknown vulnerabilities, determine whether they can be exploited and generate protection, all within infrastructure controlled by the customer.
Built for government, defense, enterprises and critical infrastructure, Typhon can operate on-premises, in private clouds and in fully air-gapped environments. Source code, firmware, vulnerability findings and customer-specific security intelligence do not need to leave the organization's security boundary.
Typhon is built around a simple security sequence: Discover. Validate. Protect.
In eight weeks of live vulnerability research, Typhon identified more than 100 previously unknown vulnerabilities. BreachX has submitted 65 findings across approximately 50 products to vendors through coordinated disclosure. Five findings have received CVE identifiers, while another resulted in a public Flatpak security advisory.
Typhon works alongside BreachX PatchZero, which uses validated vulnerability evidence to generate protection before an official software vendor patch becomes available.
Moving Cybersecurity from Detection to Discovery
Most cybersecurity technologies focus on detecting known threats, identifying catalogued vulnerabilities or responding after malicious activity has begun. BreachX built Typhon to move security earlier in the lifecycle, to discovering weaknesses before they are known or exploited.
Typhon analyzes source code, binaries, mobile applications and firmware to identify potential vulnerabilities that have not previously been reported. It can reason across those weaknesses to construct plausible attack paths and validate findings by generating and executing proof-of-concept exploits in isolated environments rather than against production systems.
The result is evidence that security teams can use to distinguish theoretical weaknesses from vulnerabilities that represent credible real-world risk.
"Software has reached machine scale, but finding its weaknesses still depends heavily on scarce human expertise," said Rajshekhar Pullabhatla, Founder of BreachX. "Typhon enables security teams to examine code and systems at machine scale while keeping their most sensitive assets inside their own perimeter. The objective is simple: find the weakness before the attacker does, and start protecting against it first."

Sovereign AI Designed for Sensitive Environments
Typhon runs within infrastructure controlled by the customer. Source code, firmware, vulnerability information and other sensitive security data can remain within that environment throughout the discovery, validation and protection process.
Organizations can also further post-train Typhon using their own code, security findings and telemetry within their security boundary. Those adaptations remain with the customer and are not returned to BreachX.
Typhon is available in four mission-specific editions:
- Typhon Gov: Designed for government and national-scale environments where sovereignty, jurisdiction and control of security data are critical requirements.
- Typhon Mil: Designed for defense and restricted environments, including fully disconnected and air-gapped deployments.
- Typhon Enterprise: Designed to operate within an enterprise's existing infrastructure and security controls.
- Typhon OT: Designed for operational technology and critical infrastructure, including firmware, specialized protocols and industrial environments.
The editions vary in model size, deployment architecture, data-handling requirements and the cybersecurity research corpus used for specialization.
Typhon models are engineered and post-trained by BreachX in Bengaluru, India, using open base models specialized for cybersecurity, with BreachX-held model weights deployed inside customer environments.
Cybersecurity Intelligence Built Over Years
Typhon's capabilities come from cybersecurity-specific post-training rather than relying solely on general-purpose model knowledge.
Its training and research corpus draws from three layers of security intelligence:
- Public intelligence: CVEs, vulnerability research, security papers, malware samples, threat reports, remediation knowledge and open-source projects.
- Community intelligence: Security knowledge generated through the National Security Database (NSD), MalCon, cyber range environments, bug bounty programs and research collaborations.
- Proprietary intelligence: BreachX vulnerability research, digital forensics and incident-response investigations, physical cyber range exercises and internal security R&D.
The corpus includes both successful vulnerability discoveries and abandoned research paths, enabling Typhon to learn from the reasoning process involved in vulnerability research, not simply from databases of previously known vulnerabilities.
"AI is going to change how vulnerabilities are found and how attacks are executed, on both sides," said Vijaykrishna Shetty, Co-Founder and CEO of BreachX. "Reacting faster will not be enough. Organizations need systems that continuously discover vulnerabilities, determine whether they are genuinely exploitable and then protect against them. We engineered Typhon and PatchZero in India with sovereignty, privacy and real-world deployment conditions designed in from the beginning."

From Discovery to Protection
Typhon and PatchZero operate as a continuous workflow.
Typhon identifies a potential vulnerability, analyzes how it could be reached and validates the finding through controlled testing. PatchZero then uses that evidence to generate protection within the customer's environment, helping reduce the exposure window between vulnerability discovery and the availability and deployment of an official vendor patch.
Both systems can operate entirely on customer-controlled infrastructure.
More Than 100 Previously Unknown Vulnerabilities Identified
BreachX has tested Typhon against widely deployed production software as part of its coordinated vulnerability disclosure program.
During an eight-week research period, Typhon identified more than 100 previously unknown vulnerabilities.
Of these, 65 findings across approximately 50 products have been submitted to software vendors under coordinated disclosure, with many still undergoing remediation. Additional findings involving defense-sensitive systems remain under restricted review and are not being publicly disclosed.
Five findings have received Common Vulnerabilities and Exposures (CVE) identifiers, while another resulted in a public Flatpak security advisory. Published findings affect widely deployed technologies including Wireshark, NetworkManager and SSSD.
The Wireshark advisory for CVE-2026-76918 credits BreachX Zero Day Labs with discovering a heap overflow in the SSH protocol dissector. The vulnerable code had been present in the codebase since 2020.
A separate Flatpak security advisory credits BreachX Zero Day Labs and identifies Typhon AI Mil v2 as the system used in the discovery.
Independent Assessment and Benchmarking
In August 2026, the Indian Computer Emergency Response Team (CERT-In) independently assessed Typhon in a seeded zero-day discovery exercise.
According to the assessment provided to BreachX, Typhon identified all six seeded flaws and achieved 100% precision in that exercise, while producing supporting evidence for each finding. The assessment also identified areas for improvement, which BreachX says have been addressed in the release announced today.
In BreachX's evaluation on CyBench, a public benchmark covering professional-level cybersecurity tasks, Typhon achieved a 93.3% solve rate, placing it No. 3 in the evaluated leaderboard configuration.
The AI Security Race Is Moving Upstream
AI is accelerating both software development and offensive security research. As vulnerability research becomes increasingly machine-assisted, the time between the creation or discovery of a software weakness and attempts to exploit it is expected to shrink.
That changes the security equation.
Detection remains essential, but BreachX believes the next frontier of cybersecurity will increasingly move upstream: using AI to discover vulnerabilities before attackers exploit them, validate whether those weaknesses form credible attack paths, and generate protection before an official patch is available.
Industry Perspective
"BreachX Typhon is exactly the kind of leap security needs right now: zero-day discovery, kill-chain generation, exploit validation and patch creation, all at machine speed," said Sudhir Prasad, Director, Software Supply Chain Security at IBM-Red Hat. "In a world where AI-driven attacks can strike within hours, that speed isn't optional anymore, it's essential. And doing it all on-premises, without crown-jewel data leaving the organization's environment, addresses one of the most important barriers to enterprise adoption of cybersecurity AI."
Unveiled Live in New Delhi
BreachX unveiled Typhon at The Oberoi, New Delhi, before an invited audience from government, defense, cybersecurity, industry and media.
Rather than presenting a recorded demonstration, BreachX demonstrated Typhon live, using the system to discover and validate vulnerabilities in code during the event.
Air Chief Marshal R. K. S. Bhadauria, PVSM, AVSM, VM, ADC (Retd.), former Chief of the Air Staff of the Indian Air Force, attended as Chief Guest and delivered the keynote address.

Describing BreachX's decision to demonstrate the technology live, Air Chief Marshal Bhadauria called it "a gutsy demonstration of the capability, given the risks."
"It is a huge achievement," he said. "This is the first time I have seen the result of a product that can go into service."
Dr. Ranjana, Outstanding Scientist and Director of the Directorate of Futuristic Technology Management (DFTM), Defence Research and Development Organisation (DRDO), attended as Guest of Honour.

"When I was CISO there were too many sleepless nights," said Dr. Ranjana. "But probably this makes me think, why did I even leave that role? Now I can sleep much more peacefully with this kind of thing. That is the promise you have made today."
"As the Air Chief Marshal said, it was a very gutsy decision from you," she added. "It is very encouraging that Indians have taken this bull by the horns, and I think we will not miss this bus, thanks to people like you."
The event included BreachX's vision for sovereign cybersecurity AI and a 45-minute live demonstration led by Product Head Alok Tripathi, with opening remarks by Group Captain P. Aanand Naidu (Retd.).
Availability
Typhon is available now for deployment across government, defense, enterprise and critical-infrastructure environments. BreachX PatchZero is available with Typhon deployments.
Prospective customers can evaluate Typhon against a system of their own choosing, allowing their security teams to directly measure what the technology discovers, validates and helps protect.
More information is available at breachx.ai.
About BreachX
BreachX is an AI cybersecurity company and zero-day research lab building security technology in India for organizations worldwide.
The company engineers and post-trains cybersecurity-specialized AI models for zero-day vulnerability discovery, attack-path analysis, exploit validation and automated security testing. BreachX also develops PatchZero, which generates protection against newly discovered vulnerabilities before an official vendor patch becomes available.
BreachX combines proprietary vulnerability research, public and community security intelligence, physical cyber ranges, incident-response experience and security researcher expertise. Its technology is designed for customer-controlled deployment across on-premises, private-cloud and air-gapped environments.
BreachX is backed by Shastra VC, the founders of Quick Heal Technologies, and Information Security Media Group.
Media contact: media@breachx.ai
Note to Editors
Public vendor advisories related to BreachX vulnerability research include:
- Red Hat: CVE-2026-19685, CVE-2026-68742, CVE-2026-68743 and CVE-2026-68744
- Wireshark: CVE-2026-76918
- Flatpak: Security Advisory GHSA-q4gr-vc25-57m5
Additional vulnerability findings remain under coordinated disclosure or restricted review and are not being publicly disclosed at this time.






