flatt_sec_en's profile picture. Building AI that finds & fixes web security bugs — autonomously. SOTA in white-box bug hunting. Try Takumi: http://flatt.tech/en/takumi

GMO Flatt Security Inc.

@flatt_sec_en

Building AI that finds & fixes web security bugs — autonomously. SOTA in white-box bug hunting. Try Takumi: http://flatt.tech/en/takumi

Fijado

We're excited to announce the launch of our security AI agent, "Takumi"! It's already making waves in the security world, having reported over 10 vulnerabilities in OSS projects like Vim. Check it out! flatt.tech/en/takumi


Our researcher RyotaK @ryotkak found an Arbitrary Code Execution vulnerability in the Unity Runtime (CVE-2025-59489). We urge all Unity developers to download updated versions, recompile their projects, and republish immediately. flatt.tech/research/posts…


GMO Flatt Security Inc. reposteó

I reported an arbitrary code execution in Unity Runtime, which affects all versions starting from Unity 2017.1. As the vulnerability can be exploited without specific usage, I strongly encourage developers to patch. Technical details below: flatt.tech/research/posts…


GMO Flatt Security Inc. reposteó

Why XSS Persists in This Frameworks Era? an interesting analysis by @i_am_canalun flatt.tech/research/posts…


New blog out! Think XSS is a thing of the past with today's Web frameworks? Think again! Our new article by @i_am_canalun breaks down why this vulnerability persists and offers insights on how to stay secure. Read it here! flatt.tech/research/posts…


GMO Flatt Security Inc. reposteó

However, the requirement for this vulnerability to be exploitable is unlikely, which fairly reduces its impact. If your Next.js application fetches a third-party website server-side, I recommend upgrading to the latest version! github.com/vercel/next.js…


GMO Flatt Security Inc. reposteó

I recently reported a vulnerability to Next.js, which is a partial bypass of the middleware authentication bypass vulnerability (CVE-2025-29927) with Takumi (takumi-san.ai), an AI security engineer.


Loading...

Something went wrong.


Something went wrong.