BreachX puts AI-driven vulnerability discovery to the test
BreachX has launched Typhon, an AI model family designed to discover, validate and help protect against previously unknown vulnerabilities inside customer-controlled environments.
BreachX has launched Typhon, a family of cybersecurity AI models designed to find previously unknown software vulnerabilities, test whether they can actually be exploited, and generate protection before an official vendor patch is available.
BreachX said it had identified more than 100 previously unknown vulnerabilities during eight weeks of live research. Of these, 65 findings across approximately 50 products were submitted to vendors through coordinated disclosure, while five received CVE identifiers, the standard reference system for publicly documented vulnerabilities.
There is independent evidence behind some of those claims. Wireshark credits BreachX Zero Day Labs with discovering a vulnerability in its SSH protocol dissector, while Red Hat credits BreachX researcher Vivek Parikh for reporting a NetworkManager flaw. Flatpak’s security advisory also says the issue was discovered by BreachX using Typhon AI Mil v2.
“Software has reached machine scale, but finding its weaknesses still depends heavily on scarce human expertise. Typhon enables security teams to examine code and systems at machine scale while keeping their most sensitive assets inside their own perimeter,” said Founder Rajshekhar Pullabhatla, describing the rationale in terms of scale.
The emphasis on keeping data inside the organisation is central to Typhon as the models can operate on-premises, in private clouds and in air-gapped environments, meaning systems deliberately disconnected from external networks.
BreachX said source code, firmware and vulnerability information can remain within the customer’s security boundary. Its four editions are aimed at government, defence, enterprise and operational technology environments.
Typhon is also intended to work with BreachX’s PatchZero system. After a potential vulnerability is found, Typhon can generate and run a proof-of-concept exploit in an isolated environment to establish whether it is genuinely exploitable. PatchZero then uses that evidence to generate protection while organisations wait for an official vendor fix.
The timing highlights a wider shift in cybersecurity. The UK’s National Cyber Security Centre said AI-assisted vulnerability research and exploit development is likely to be the most significant near-term development in AI-enabled cyber operations, while warning that AI could further reduce the time between vulnerability disclosure and exploitation.
Meanwhile, the commercial market is moving in the same direction. OpenAI has developed Codex Security, an application security agent that analyses code, validates potential vulnerabilities in isolated environments and proposes fixes. Microsoft has introduced AI agents for security operations, while its Security Copilot platform is designed to automate parts of investigation and response.
BreachX’s co-founder Vijaykrishna Shetty argues that conventional response will increasingly be insufficient. “Reacting faster will not be enough. Organizations need systems that continuously discover vulnerabilities, determine whether they are genuinely exploitable and then protect against them,” he noted.
There are reasons for caution, however. BreachX said CERT-In found all six seeded flaws in one August exercise and recorded 100% precision, but explicitly noted this should not be treated as a general accuracy rate. Its 93.3% CyBench result was also a BreachX evaluation rather than an independently verified public ranking.


