Nebula Security is a cybersecurity research firm that discovered the GhostLock vulnerability (CVE-2026-43499) using their AI-driven bug-hunting tool VEGA. They developed a working exploit and demonstrated the IonStack chain combining Firefox and kernel exploits for remote compromise.