Zero-Day Research Labs
Our philosophy

Discovery >> Detection

Somewhere in your systems, right now,there is a weakness you do not know about.

Someone may already know.

Where defence begins

For decades, most cyber defence has activated after exploitation begins.

Weakness exists
Attacker finds it
Attack begins
We notice
We respond
Defence begins here

Tonight, defence moves earlier.

Software has reachedmachine speed scale.

Finding its weaknesses has not.

Until now.

Control

Your source code.Your firmware.Your critical systems.Your undisclosed weaknesses.

Should any of this ever leave your control?

BreachX presents

India’s sovereign cybersecurity AI
FIND IT FIRST.   FIX IT FIRST.
What Typhon does

One continuous loop.

Discover
Chain
Validate
Mitigate
DiscoverFind the weaknessIncluding ones nobody has reported before.
ChainBuild the attack pathHow one weakness leads to the next, to the target.
ValidateProve it with a custom exploitNot a guess. A working demonstration, safely.
MitigateGenerate the protection patchProtection today, while the permanent fix is built.
What Typhon can test

Everything you actually run.

Source codethe software as it is written
Binary executablesthe software as it ships, no source needed
Mobile appsiOS and Android
Firmwarethe software inside the machine itself
Remote applicationslive web-facing systems
OT and IoT assetsindustrial controllers and connected devices
Where it runs

All insideyour own infrastructure.

No code. No findings. No customer data leaves your environment.
The gap

Complete protection from zero-days.

01Generate with Typhon
02Virtual patches at machine speed
03Validate and deploy directly
Proof

Years hidden.

An SSH dissector weakness in Wireshark, a leading network-analysis tool.
Publicly undisclosed. Typhon found it.

CVE-2026-76918  ·  Wireshark SSH dissector crash
Discovered by BreachX Zero Day Labs
NetworkManager

“Fixed” in 2025. An incomplete fix remained.

CVE-2026-19685 · High · Red Hat
SSSD

Three weaknesses in the login system of enterprise Linux.

3 CVEs · Red Hat · assigned within weeks
Flatpak

An active local user could bypass anti-downgrade controls.

Security advisory · credited to Typhon
Proof

It was not the only one.

Built in India.  ·  Runs in your environment.  ·  Remains under your control.
Proof

Independently assessedby CERT-In.

Zero-day discovery on seeded code
Evidence produced for every finding
August 2026
Assessment findings were addressed in the launch version.
6 seeded flaws  ·  6 detected
6/6
100% precision  ·  evidence for every finding
The evidence

Typhon: proven capabilities.

112+zero-day candidates identified65 submitted across ~50 products in eight weeks
6CVE-assignedVendor records credit BreachX. Plus a Flatpak advisory.
BreachX Zero-Day Labs  ·  R&D
The evidence

Stanford Cybench. The world’s top cybersecurity benchmark.

93.3%
in Cybench evaluation · ranked 3 globally
Professional-level cyber tasks. No defined pass threshold.
RankModelTasksUnguided % solvedTrials
1Claude Mythos Preview35100%5
2Claude Opus 4.73596%5
3Typhon-v1-Lite-09263593.3%3
4Claude Opus 4.63793%5
5Claude Opus 4.53982%5
6Muse Spark (1.0)4065.4%1/10
7Claude Sonnet 4.53960%5
Two families

One Typhon.Two families. Four editions.

Typhon SovereignFor the nation.
Typhon Gov

Government and national-scale deployments. Designed for multi-tenancy and tenant-level private training.

Typhon Mil

Defence. Fully disconnected, restricted operation. Exclusive access to Zero Day Labs findings.

Typhon BusinessFor the economy.
Typhon Enterprise

Private organisations, on their own infrastructure.

Typhon OT

Industrial and critical infrastructure. Firmware, protocols, safety.

The ask

Test Typhon in your environment.

We are not asking you to believe us.
01Select

one system you genuinely care about.

02Run

Typhon inside your own environment.

03Measure

what it finds, proves and protects.

Demo

Watch Typhon in action.

FIND IT FIRST.   FIX IT FIRST.

Backup

Q&A only
Backup

Public record, citable

CVE-2026-68742 / 68743 / 68744SSSD · Red Hat CNA · assigned 31 Jul, published 3 Aug 2026
CVE-2026-19685NetworkManager · Red Hat · High (7.1) · incomplete fix of CVE-2025-9615 · public 25 Aug
CVE-2026-76918Wireshark SSH dissector · CVSS 5.5 (Red Hat) · fixed in 4.4.18 / 4.6.8
GHSA-q4gr-vc25-57m5Flatpak anti-downgrade bypass · Moderate · published 11 Aug 2026 · no CVE
Vendor creditWireshark credits BreachX; Flatpak explicitly credits Typhon AI Mil v2.
Count5 CVEs + 1 advisory = 6 vendor-confirmed findings
Backup

Disclosure tracker, Jul to Aug 2026

Submissions65 rows, ~50 distinct products, 8 weeks
Status35 awaiting vendor response · 6 under triage · 6 vendor-confirmed
Categories (safe to say)Linux kernel, web servers, container platforms, browsers, VPN clients, login and packaging systems
Do NOT name on stageAny product with an unfixed, unpublished finding
Candidate findings65 submitted + 42 awaiting approval = 107 identified
Backup

CERT-In assessment, Aug 2026

Approved wording“Independently assessed by CERT-In”, never validated / certified / endorsed
Zero-day discovery (Git URL)6 of 6 seeded flaws detected · 100% precision · credible taint proofs
Dynamic testing6 of 12 seeds (75% of reachable) · 90.9% finding-level precision · verified exploit
Items raisedIsolation, pipeline supervision, severity calibration, fixed in the launch version
Firmware resultTest ran out of licensed credits before completion, being re-run
Instance testedShared cloud research instance; launch product is single-tenant, on-prem or disconnected
Backup

Deployment

ModelsBreachX-engineered cybersecurity configurations
Training dataBreachX physical cyber ranges; data from NSD security professionals
Where it runsOn-premise, fully disconnected (air-gapped), or sovereign cloud
Data movementNone. No telemetry, no sample egress
LearningCustomer data and adaptations remain within the customer boundary
EditionsGOV · MIL · ENT · OT. One core, configured per mission
Backup

The wider platform

TyphonThe intelligence engine: discover, validate, chain, fix
PatchZeroProtection before the vendor patch
RedXTAI-assisted offensive security
BASBreach and attack simulation, proving the defence works
GovernanceControl for AI-enabled security operations
Backup

How Typhon is built

Engineered by BreachXFully trained in India. Two configurations for different mission and compute requirements.
Our own researchBreachX research archives: findings, proofs and failed paths.
Physical cyber rangesInstrumented real systems and production-like environments.
India’s security professionalsSpecialised datasets from NSD security practitioners.
Public vulnerability knowledgeBroad public vulnerability and remediation knowledge.
BoundaryCustomer data and adaptations remain inside the customer boundary.
01 / 15
Click a slide · press C or Esc to close