Log inOpen app
Log inOpen app
GMO Flatt Security Inc.
75 posts
GMO Flatt Security Inc. profile banner
@flatt_sec_en

GMO Flatt Security Inc.

@flatt_sec_en
Building AI that finds & fixes web security bugs — autonomously. SOTA in white-box bug hunting. Try Takumi: flatt.tech/en/takumi
Tokyo
flatt.tech/en
Joined May 2021
1 Following
931 Followers
RepliesRepliesRepostsRepostsMediaMedia
Get the full app experience
Unlock more features and see what people are talking about right now.
Open X
  • Pinned
    @flatt_sec_en
    GMO Flatt Security Inc.
    @flatt_sec_en
    Mar 24, 2025
    We're excited to announce the launch of our security AI agent, "Takumi"! It's already making waves in the security world, having reported over 10 vulnerabilities in OSS projects like Vim. Check it out!
    Takumi, the AI Security Engineer | GMO Flatt Security Inc.
    From flatt.tech
    1
    4
    27
    8.2K
  • @flatt_sec_en
    GMO Flatt Security Inc.
    @flatt_sec_en
    Oct 8
    🚨 We posted a initial response guidance blog for the software supply chain attack on the tensorlake npm package, which occurred today at 10/8. We are still researching the details of the campaign and sample, and will update the blog post as new details emerge.
    Software Supply Chain Attack on tensorlake: Overview and Response Guidance
    From flatt.tech
    4
    5
    646
  • @flatt_sec_en
    GMO Flatt Security Inc.
    @flatt_sec_en
    Oct 6
    We have published a new blog post covering a recent software supply chain attack on the @subql/common npm package. It covers technical details of the compromised package, as well as guidance on response if affected, as well as recommendations for users to protect against supply
    Software Supply Chain Attack on @subql/common: Overview and Response Guidance
    From flatt.tech
    3
    6
    856
  • @flatt_sec_en
    GMO Flatt Security Inc.
    @flatt_sec_en
    Jun 1
    We've published a new blog post by RyotaK @ryotkak. He discovered a vulnerability in Claude Code GitHub Actions that allows external attackers to bypass its permission controls via a GitHub issue and abuse the workflow's permissions, along with related misconfigurations. The
    Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
    From flatt.tech
    2
    14
    49
    2K
  • @flatt_sec_en
    GMO Flatt Security Inc.
    @flatt_sec_en
    Mar 23
    We've published a new blog post by RyotaK @ryotkak ! He exploited a directory deletion race condition in Google Cloud's Looker, leading to full RCE and K8s privilege escalation. Read the technical details here:
    flatt.tech
    Remote Command Execution in Google Cloud with Single Directory Deletion
    Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google....
    1
    29
    114
    46K
Edit with