On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

From left: Air Vice Marshal A Suresh Kumar VSM (Retd), Consultant for CAG; Group Captain P. Aanand Naidu (Retd); Vijaykrishna Shetty, Co-Founder and CEO, BreachX; Air Chief Marshal R. K. S. Bhadauria, PVSM, AVSM, VM, ADC (Retd); Dr. Ranjana, Outstanding Scientist and Director, DFTM, DRDO; and Rajshekhar Pullabhatla, Founder, BreachX, at the Typhon launch at The Oberoi, New Delhi.
NEW DELHI, India, September 3, 2026: BreachX, an AI cybersecurity company and zero-day research lab, today unveiled Typhon, a family of sovereign cybersecurity AI models designed to discover previously unknown vulnerabilities, determine whether they can be exploited and generate protection, all within infrastructure controlled by the customer.
Built for government, defense, enterprises and critical infrastructure, Typhon can operate on-premises, in private clouds and in fully air-gapped environments. Source code, firmware, vulnerability findings and customer-specific security intelligence do not need to leave the organization's security boundary.
Typhon is built around a simple security sequence: Discover. Validate. Protect.
In eight weeks of live vulnerability research, Typhon identified more than 100 previously unknown vulnerabilities. BreachX has submitted 65 findings across approximately 50 products to vendors through coordinated disclosure. Five findings have received CVE identifiers, while another resulted in a public Flatpak security advisory.
Typhon works alongside BreachX PatchZero, which uses validated vulnerability evidence to generate protection before an official software vendor patch becomes available.
Most cybersecurity technologies focus on detecting known threats, identifying catalogued vulnerabilities or responding after malicious activity has begun. BreachX built Typhon to move security earlier in the lifecycle, to discovering weaknesses before they are known or exploited.
Typhon analyzes source code, binaries, mobile applications and firmware to identify potential vulnerabilities that have not previously been reported. It can reason across those weaknesses to construct plausible attack paths and validate findings by generating and executing proof-of-concept exploits in isolated environments rather than against production systems.
The result is evidence that security teams can use to distinguish theoretical weaknesses from vulnerabilities that represent credible real-world risk.
"Software has reached machine scale, but finding its weaknesses still depends heavily on scarce human expertise," said Rajshekhar Pullabhatla, Founder of BreachX. "Typhon enables security teams to examine code and systems at machine scale while keeping their most sensitive assets inside their own perimeter. The objective is simple: find the weakness before the attacker does, and start protecting against it first."

Typhon runs within infrastructure controlled by the customer. Source code, firmware, vulnerability information and other sensitive security data can remain within that environment throughout the discovery, validation and protection process.
Organizations can also further post-train Typhon using their own code, security findings and telemetry within their security boundary. Those adaptations remain with the customer and are not returned to BreachX.
Typhon is available in four mission-specific editions:
The editions vary in model size, deployment architecture, data-handling requirements and the cybersecurity research corpus used for specialization.
Typhon models are engineered and post-trained by BreachX in Bengaluru, India, using open base models specialized for cybersecurity, with BreachX-held model weights deployed inside customer environments.
Typhon's capabilities come from cybersecurity-specific post-training rather than relying solely on general-purpose model knowledge.
Its training and research corpus draws from three layers of security intelligence:
The corpus includes both successful vulnerability discoveries and abandoned research paths, enabling Typhon to learn from the reasoning process involved in vulnerability research, not simply from databases of previously known vulnerabilities.
"AI is going to change how vulnerabilities are found and how attacks are executed, on both sides," said Vijaykrishna Shetty, Co-Founder and CEO of BreachX. "Reacting faster will not be enough. Organizations need systems that continuously discover vulnerabilities, determine whether they are genuinely exploitable and then protect against them. We engineered Typhon and PatchZero in India with sovereignty, privacy and real-world deployment conditions designed in from the beginning."

Typhon and PatchZero operate as a continuous workflow.
Typhon identifies a potential vulnerability, analyzes how it could be reached and validates the finding through controlled testing. PatchZero then uses that evidence to generate protection within the customer's environment, helping reduce the exposure window between vulnerability discovery and the availability and deployment of an official vendor patch.
Both systems can operate entirely on customer-controlled infrastructure.
BreachX has tested Typhon against widely deployed production software as part of its coordinated vulnerability disclosure program.
During an eight-week research period, Typhon identified more than 100 previously unknown vulnerabilities.
Of these, 65 findings across approximately 50 products have been submitted to software vendors under coordinated disclosure, with many still undergoing remediation. Additional findings involving defense-sensitive systems remain under restricted review and are not being publicly disclosed.
Five findings have received Common Vulnerabilities and Exposures (CVE) identifiers, while another resulted in a public Flatpak security advisory. Published findings affect widely deployed technologies including Wireshark, NetworkManager and SSSD.
The Wireshark advisory for CVE-2026-76918 credits BreachX Zero Day Labs with discovering a heap overflow in the SSH protocol dissector. The vulnerable code had been present in the codebase since 2020.
A separate Flatpak security advisory credits BreachX Zero Day Labs and identifies Typhon AI Mil v2 as the system used in the discovery.
In August 2026, the Indian Computer Emergency Response Team (CERT-In) independently assessed Typhon in a seeded zero-day discovery exercise.
According to the assessment provided to BreachX, Typhon identified all six seeded flaws and achieved 100% precision in that exercise, while producing supporting evidence for each finding. The assessment also identified areas for improvement, which BreachX says have been addressed in the release announced today.
In BreachX's evaluation on CyBench, a public benchmark covering professional-level cybersecurity tasks, Typhon achieved a 93.3% solve rate, placing it No. 3 in the evaluated leaderboard configuration.
AI is accelerating both software development and offensive security research. As vulnerability research becomes increasingly machine-assisted, the time between the creation or discovery of a software weakness and attempts to exploit it is expected to shrink.
That changes the security equation.
Detection remains essential, but BreachX believes the next frontier of cybersecurity will increasingly move upstream: using AI to discover vulnerabilities before attackers exploit them, validate whether those weaknesses form credible attack paths, and generate protection before an official patch is available.
"BreachX Typhon is exactly the kind of leap security needs right now: zero-day discovery, kill-chain generation, exploit validation and patch creation, all at machine speed," said Sudhir Prasad, Director, Software Supply Chain Security at IBM-Red Hat. "In a world where AI-driven attacks can strike within hours, that speed isn't optional anymore, it's essential. And doing it all on-premises, without crown-jewel data leaving the organization's environment, addresses one of the most important barriers to enterprise adoption of cybersecurity AI."
BreachX unveiled Typhon at The Oberoi, New Delhi, before an invited audience from government, defense, cybersecurity, industry and media.
Rather than presenting a recorded demonstration, BreachX demonstrated Typhon live, using the system to discover and validate vulnerabilities in code during the event.
Air Chief Marshal R. K. S. Bhadauria, PVSM, AVSM, VM, ADC (Retd.), former Chief of the Air Staff of the Indian Air Force, attended as Chief Guest and delivered the keynote address.

Describing BreachX's decision to demonstrate the technology live, Air Chief Marshal Bhadauria called it "a gutsy demonstration of the capability, given the risks."
"It is a huge achievement," he said. "This is the first time I have seen the result of a product that can go into service."
Dr. Ranjana, Outstanding Scientist and Director of the Directorate of Futuristic Technology Management (DFTM), Defence Research and Development Organisation (DRDO), attended as Guest of Honour.

"When I was CISO there were too many sleepless nights," said Dr. Ranjana. "But probably this makes me think, why did I even leave that role? Now I can sleep much more peacefully with this kind of thing. That is the promise you have made today."
"As the Air Chief Marshal said, it was a very gutsy decision from you," she added. "It is very encouraging that Indians have taken this bull by the horns, and I think we will not miss this bus, thanks to people like you."
The event included BreachX's vision for sovereign cybersecurity AI and a 45-minute live demonstration led by Product Head Alok Tripathi, with opening remarks by Group Captain P. Aanand Naidu (Retd.).
Typhon is available now for deployment across government, defense, enterprise and critical-infrastructure environments. BreachX PatchZero is available with Typhon deployments.
Prospective customers can evaluate Typhon against a system of their own choosing, allowing their security teams to directly measure what the technology discovers, validates and helps protect.
More information is available at breachx.ai.
BreachX is an AI cybersecurity company and zero-day research lab building security technology in India for organizations worldwide.
The company engineers and post-trains cybersecurity-specialized AI models for zero-day vulnerability discovery, attack-path analysis, exploit validation and automated security testing. BreachX also develops PatchZero, which generates protection against newly discovered vulnerabilities before an official vendor patch becomes available.
BreachX combines proprietary vulnerability research, public and community security intelligence, physical cyber ranges, incident-response experience and security researcher expertise. Its technology is designed for customer-controlled deployment across on-premises, private-cloud and air-gapped environments.
BreachX is backed by Shastra VC, the founders of Quick Heal Technologies, and Information Security Media Group.
Media contact: media@breachx.ai
Public vendor advisories related to BreachX vulnerability research include:
Additional vulnerability findings remain under coordinated disclosure or restricted review and are not being publicly disclosed at this time.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.