Skip to main content
All Content

All Publications

Research, blog posts, and whitepapers from the Breachline Labs team.

Nebula: The Autonomous AI Penetration Testing Platform
Technical ArchitecturewhitepaperFeatured

Nebula: The Autonomous AI Penetration Testing Platform

How Breachline's Nebula runs continuous, autonomous penetration tests: a swarm of reasoning agents that chain real exploits, prove them, and report.

May 30, 202620 minBreachline Labs
Read
All articles
SSRF to Cloud Takeover: Anatomy of a Metadata Attack Chain
Vulnerability Researchresearch

SSRF to Cloud Takeover: Anatomy of a Metadata Attack Chain

How a single SSRF reaches the cloud metadata endpoint, steals IAM credentials, and pivots to full account takeover, plus the controls that stop it.

May 29, 202613 min
HumanBrowser: The Live Browser Nebula Uses to Pentest Like a Person
Productblog

HumanBrowser: The Live Browser Nebula Uses to Pentest Like a Person

Most AI browser tools script clicks and get flagged as bots. HumanBrowser gives Nebula a real Chromium it drives by sight, through an intercepting proxy.

May 29, 202611 min
TeamPCP: The Group Turning Your Security Tools Into Malware
Threat Intelligenceblog

TeamPCP: The Group Turning Your Security Tools Into Malware

TeamPCP poisoned Trivy, Checkmarx, and LiteLLM in a 2026 supply chain campaign (CVE-2026-33634). Who they are, what they hit, and how to stop them.

May 29, 202614 min
Advanced JWT Attack Chains: Algorithm Confusion and JWKS Poisoning
Vulnerability Researchresearch

Advanced JWT Attack Chains: Algorithm Confusion and JWKS Poisoning

The JWT attacks that bypass mature defenses: RS256-to-HS256 confusion, jku/x5u poisoning, kid injection, and cross-service token replay.

May 28, 202616 min
Securing the Software Supply Chain: A 2026 Defender's Playbook
Best Practiceswhitepaper

Securing the Software Supply Chain: A 2026 Defender's Playbook

A practical playbook for defending the software supply chain in 2026: the attack patterns behind the year's biggest incidents, and the controls that stop them.

May 27, 202613 min
Claude Mythos Didn't Kill Pentesting. Read Anthropic's Own Fine Print.
Industry Analysisblog

Claude Mythos Didn't Kill Pentesting. Read Anthropic's Own Fine Print.

Anthropic's Claude Mythos post claimed 181 Firefox exploits and an overnight FreeBSD RCE. The model card's fine print tells a far more careful story.

Apr 20, 20268 min
Every AI Pentest Tool Is #1 on a Leaderboard. Here's the Catch.
Industry Analysisblog

Every AI Pentest Tool Is #1 on a Leaderboard. Here's the Catch.

XBOW raised $120M, Claude Mythos writes exploits overnight, yet curl's maintainer has never seen a valid AI bug report. What actually works versus theatre.

Apr 20, 20269 min
The Vercel Breach: One Third-Party OAuth Token, Full Compromise
Threat Intelligenceblog

The Vercel Breach: One Third-Party OAuth Token, Full Compromise

Vercel's April 2026 breach traces to one compromised third-party OAuth token from Context.ai. The full attack chain, the IOCs, and the lessons for your team.

Apr 20, 202613 min
The Axios npm Supply Chain Attack: What Teams Need to Know
Threat Intelligenceblog

The Axios npm Supply Chain Attack: What Teams Need to Know

Attackers backdoored Axios on npm on March 31, 2026, deploying cross-platform RATs in under 3 hours. Here's what happened and how to protect your builds.

Mar 31, 202612 min
The LiteLLM Supply Chain Attack: What Every AI Team Needs to Know
Threat Intelligenceblog

The LiteLLM Supply Chain Attack: What Every AI Team Needs to Know

Attackers compromised LiteLLM on PyPI on March 24, 2026, stealing credentials from thousands of AI deployments. Here's what happened and how to respond.

Mar 27, 202611 min