米内貴志(Takashi Yoneuchi)の登壇・メディア出演・コミュニティ活動の記録です。公開されている記事・動画・登壇資料へのリンクを掲載しています。プロフィール・経歴と登壇資料一覧もご覧ください。

登壇予定

第4回GMO大会議・秋・フィジカルAI 2026

(登壇予定)
  • Moderator / Scheduled to moderate the panel 「AIで攻撃が加速する今、どう『先に』守るか」 with speakers from Cloudflare Japan, Anthropic Japan and GMO Internet Group.
  • 公式プログラム・登壇情報

2026

Webブラウザセキュリティ — Forkwell Library #132

  • Talk / Gave a talk titled 「Web ブラウザの構造を捉えるたのしみ」 and joined an audience Q&A as the author of Web Browser Security.
  • イベント・登壇情報

TBS「Nスタ」

2026年、AI時代のDevSecOpsを考える

CloudSec JP #006

Takumi Images Webinar

  • Talk / セキュアなコンテナイメージをつくろう 〜CVE-free コンテナイメージ「Takumi Images」の概要と裏話〜
  • Slides

GMO Developers — Engineering Journey(後編)

NHK「クローズアップ現代」

レバテックLAB — Mythosクラスの影響、セキュリティの専門家はどう見るか

日経クロステック — シャドーAIのリスク

Mastra Webinar

  • Talk / Mastra ソフトウェアサプライチェーン攻撃の概要と対応指針
  • Slides

OSS開発者は今何をするべきか?ソフトウェアサプライチェーン侵害対策を考える

Product Security Square #4

  • Talk / エンジニアを狙う攻撃への備え — もし、うちのCTOが侵害されたら?を考察する
  • イベント・登壇情報

NHK「サタデーウォッチ9」

日経クロステック — AI時代の脆弱性対応

Mini Shai-Hulud Webinar

  • Talk / 更なる npm パッケージ侵害事件「Mini Shai-Hulud」徹底解説
  • Slides · YouTube

Bitwarden Webinar

  • Talk / Bitwarden ソフトウェアサプライチェーン攻撃 詳細解説
  • Slides · YouTube

レバテックLAB — ソフトウェアサプライチェーン攻撃への「日々の備え」と「初動対応」

@IT — axios侵害の教訓

Software Supply Chain Security Webinar

  • Talk / axios, LiteLLM...不使用だったのでOK、ではない。「次に備える」ソフトウェアサプライチェーン侵害への対策
  • Slides · YouTube

GitHub Actions Security Webinar

  • Talk / GitHub Actions侵害 — 相次ぐ事例を振り返り、次なる脅威に備える
  • Slides · YouTube

第3回GMO大会議・春・サイバーセキュリティ2026

  • Talk / Spoke at the GMO cybersecurity conference.
  • 登壇情報

Product Security Square #3

  • Talk / 2026年もソフトウェアサプライチェーンのリスクに立ち向かうために / Product Security Square #3
  • Slides

SRE Kaigi 2026

Ultra Thinking #2

Ultra Thinking #1

2025

Findy — 個人開発におけるセキュリティの極意

  • Talk / Discussed security for independently developed web services and vibe coding, followed by an audience Q&A.
  • イベント・登壇情報

レバテックLAB — 「つくる」を守るためのセキュリティ

Internet Week 2025

日経クロステック — MCPとSaaSの変化

アーキテクチャConference 2025

  • Talk / AIエージェントSaaSを安全に提供する技術 / Architecture Conference 2025
  • Slides

日経クロステック — AIエージェントとMCP

NewBee — AI開発とセキュリティ

  • YouTube / Discussion of AI governance, vibe coding and automation for defenders.
  • 番組を見る

DEF CON 33

  • Competition / Participated as team representative for GMO Flatt Security; the team placed third in the AppSec Village CTF and fifth in the Hardware Hacking Village CTF.
  • 大会結果・コメント

GMO Developers Day 2025 -Security Night-

  • Keynote / 実践 “Secure” Vibe Coding ― AIの速度で安全にソフトウェアを届けるために
  • 講演情報

TechRAMEN 2025 Conference

レバテックLAB — Devin/Cursor/Cline全社導入 セキュリティリスクにどう対策した?

  • Moderator / Led a panel on secure adoption of AI coding agents with engineers from DMM.com, M3 and freee.
  • イベント・登壇情報

Deep Security Conference 2025

  • Talk / 診断AIエージェントによるセキュリティの未来 – 著名OSS向け0-dayリサーチを例に
  • Slides

開発生産性Conference 2025

  • Talk / セキュリティ診断AIエージェント「Takumi」の雇用によって実現する開発生産性の向上
  • Slides

AIエージェント開発Night

  • Talk / AIエージェントの「作業場」としてのサンドボックス技術
  • Slides

AI Engineering Summit

  • Talk / セキュリティ診断AIエージェント Takumi がもたらす変化 - 著名OSS 向け0-dayリサーチを例に
  • Slides

AIとセキュリティ — MCP/エージェントの到来で変わったこと、変わらないこと

Flatt Security Magazine — AI時代のセキュリティエンジニア

AIエージェント対決!Devinの堅牢開発 vs Takumiの脆弱性診断【矛・盾】

セキュリティ診断AIエージェント「Takumi」世界最速体験会

日本経済新聞 — Takumiの紹介

SRE Kaigi 2025

  • Talk / 横断SREの立ち上げと、AWSセキュリティへの取り組みの軌跡
  • Joint sponsor session with Ryo Adachi from Findy.
  • 公式プログラム

2024

セキュリティ・キャンプ2024 全国大会

ScanNetSecurity — GMOインターネットグループへの参画

  • Web / Interview with CEO Yasutaka Ide on joining GMO Internet Group and our plans for Flatt Security.
  • インタビュー

Flatt Security Magazine — 2024年のセキュリティトレンド大予想

  • Web / Contributed to a survey of 13 development and security engineers.
  • 記事

アーキテクチャConference 2024

  • Gave a presentation on building ASM systems with Satoshi Tajima from Finatext Inc.
  • The session title was: セキュリティベンダー/ユーザー双方の視点で語る、Attack Surface Managementの実践

Security Days Fall 2024 東京

Security Days Spring 2024 東京

  • Gave a 40min presentation on principles in designing a good security strategy as a conference sponsor.
  • The session title was: CNAPP・ASM・ASPM…またバズワードが移りゆく、2024 年もなお不変の脆弱性評価・管理の勘所
  • See this page for further information

P3NFEST Conf 2024 (by IssueHunt Inc)

  • Appeared in a panel discussion about careers in product security fields.
  • See this page for further information

Flatt Securityの事業のこれから

  • Contributed an article to our tech blog.
  • Visit this page to read.

クラウドセキュリティの脅威を整理、優先すべき対策は何なのか? ~デジタル寺田+4社が解説~

  • Gave a lightning talk on cloud security 101.
  • The session title was: AWS/GCPのセキュリティ、いつから・誰が・どう始める?
  • See this page for further information

2023

@IT — International Cybersecurity Challenge 2023

  • Web / Team interview about ICC 2023, where I served as Team Asia’s head captain.
  • インタビュー

Flatt Security Magazine — 2023年のプロダクトセキュリティを振り返る

  • Web / Contributed comments on product security in 2023.
  • 記事

Google Cloud — Flatt Security導入事例

ScanNetSecurity — Shisho Cloud正式版

  • Web / Contributed comments on Shisho Cloud and customizable cloud security checks.
  • 記事

Security-JAWS DAYS

  • Talk / AWSのセキュリティ管理をPolicy as Codeで加速する ― 最高のCSPM体験を目指して
  • イベント・登壇情報

LayerX 松本勇気 × クックパッド 星北斗 × Flatt Security 米内貴志(後編)

LayerX 松本勇気 × クックパッド 星北斗 × Flatt Security 米内貴志(前編)

東洋大学情報連携学部 講義「ICT社会応用」

  • Gave a 30min presentation on early/seed startups.

【日経×Flatt Security×IssueHunt】プロダクトセキュリティの民主化と協調

  • Gave a short talk on how to build a strong culture on product security.

init.g workshop (by Google VRP)

  • Appeared in the panel discussion on security engineer careers.
  • See this post for feeling the vibe!

SRE NEXT 2023 (Sponsored Session)

  • Gave a short talk on the intersection of Site Reliability Engineering (SRE) and Security Engineering.
  • See this page for further information
  • YouTube recording

”次世代のものづくり”を担う組織に寄り添い、サポートするセキュリティSaaS「Shisho Cloud」の開発秘話と私たちが目指すもの

  • Appeared on the interview-styled page.
  • Visit this page for further information.

セキュリティ SaaS を「プログラマブル」に再設計した話 ― Shisho Cloud の正式リリースによせて

  • Contributed an article to our tech blog.
  • Visit this page to read.

Security JAWS 30th

  • Gave a short talk on CSPM 101.
  • See this page for further information

Security Camp 2023

  • Served as a producer to design the whole class.
  • Gave a 2-hour training named "Webプロダクトセキュリティへのいざない" by myself as well.
  • See this page for further information

International Cybersecurity Challenge (ICC) 2023

Asian Cyber Security Challenge (ACSC) 2023

  • Won 18th in ACSC 2023, by which I was selected as finalists of ICC 2023.

Developer eXperience Day 2023

  • Gave a talk titled "開発者体験をむしろ向上させるセキュリティ施策のイロハ ― Policy as Code の理論と実践".
  • See this page for further information
  • The transcription is available here.

Rust Panel Discussion vol.1 #blastengine

  • Appeared at a panel discussion about software supply chain security.
  • See this page for further information

RubyKaigi 2023

  • Gave a talk titled "Eliminating ReDoS with Ruby 3.2".
  • See this page for further information

2022

LayerX 名村卓 × Ms. Engineer 齋藤匠 × Flatt Security 米内貴志(後編)

LayerX 名村卓 × Ms. Engineer 齋藤匠 × Flatt Security 米内貴志(前編)

CloudNative Security Conference 2022

  • Talk / 実践 SpiceDB — クラウドネイティブ時代をサバイブできるパーミッション管理の実装を目指して
  • セッション · Slides

Hardening Designers Conference 2022

  • Appeared at a panel discussion about software supply chain security.
  • See this page for further information

ハンズオンWebAssembly

  • Contributed a really small part of the translation project.
  • Check out this page to order the book!

Security Camp 2022

たのしくなるカンファレンス (株式会社LayerX主催)

  • Appeared at a panel discussion about next-generation security operations.
  • See this page for further information

Security Mini Camp in Osaka 2022 / セキュリティ・ミニキャンプ in 大阪 2022

  • Appeared at a panel discussion on career stratergy of security engineers.
  • See the event page for further information.

2021

Console Weekly #82

  • Talked about Shisho and what it was like becoming the CTO of a Japanese cyber security company.
  • Click here to read the interview!

NoMaps Conference 2021

  • Appeared at a Q&A session about developer experience.
  • See this page for further information

LOCAL Developer Day Online ’21 /Security

  • Gave a talk about developer-first security.
  • See this page for further information

Security Camp 2021

詳解セキュリティコンテスト

  • Contributed some parts to a book describing all about CTF written by some specialists.
  • Check out this Amazon page to order the book!

MITOU Target Program

SECCON Beginners CTF 2021

  • Organized some parts of the project.
  • Provided a Web challenge named osoba.

Web24 (Online)

  • Discussed the future of Web security with great security engineers.
  • See here to check the detail of the event!

Go Conference Tokyo 2021 Spring (Online)

Security Mini Camp in Osaka 2021 / セキュリティ・ミニキャンプ in 大阪 2021

  • Gave a short seminar on Web-related modern security aspects.
  • See the event page for further information.

漠然とした不安との素敵な付き合い方

  • Contributed an article explaining how to deal with anxiety about cyber security for NISC's website.
  • You can read the article from here (Wayback Machine).

#139​ 書籍「Webブラウザセキュリティ」と、2011年の釧路でつながったぼくらの縁

書籍「Webブラウザセキュリティ」発刊記念 著者&レビュアー対談

  • Appeared in an interview article in Japanese: 前編, 後編.

セキュアにGoを書くための「ガードレール」を置こう - 安全なGoプロダクト開発に向けた持続可能なアプローチ

Proxy-Wasm + Rust による Envoy の拡張 ―― 独自メトリクスの追加を例に

Webブラウザセキュリティ ― Webアプリケーションの安全性を支える仕組みを整理する

  • Published a book on security features of web browsers.
  • See this page for further information of this book.

2020

日経クロステック — KENRO

ScanNetSecurity — セキュリティの本質的課題

Security Camp 2020

  • Conducted a 4-hour training named "Web Security from the Macro Perspective: Understanding Modern Hacking Techniques with Web Infrastructure and Side-channels" (日: 「マクロな視点から捉える Web セキュリティ: Web インフラストラクチャを利用した攻撃とサイドチャネル攻撃の実践と評価」).
  • Reference: event page

CODE BLUE 2020

  • Appeared in a panel discussion named "Why organize a CTF -This is the way-" (日: 「我々はなぜCTFを運営するのか?」).
  • Reference: event page

SECCON Beginners Live

  • Gave a presentation about CTFs and how to learn security stuffs related to them.
  • Reference: event page

SECCON CTF 2020

Security Mini Camp in Yamanashi 2020 / セキュリティ・ミニキャンプ in 山梨 2020

  • Gave a presentation to introduce activities of Security Camp Committee.
  • Reference: event page

OWASP Kansai - 体系的に学ぶモダン Web セキュリティ @ 京都 (Learning Modern Web Security @ Kyoto)

  • Did a online & long-term course on Web security.
  • Reference: event page.

OWASP Night 2020/02 (by OWASP Japan)

  • Talked about issues related to ReDoS and show a new attack vector.
  • Reference: event page

SECCON Beginners CTF 2020

  • Organized the whole project.
  • Provided two challenges: unzip and somen.

2019

IPA Workshop - Learning Modern Web Security / IPA ワークショップ 体系的に学ぶモダン Web セキュリティ

  • Did an eight-hour workshop on web security in collaboration with Information-technology Promotion Agency.

CODE BLUE CTF 2019

  • Provided a challenge named "Snippet".

#websecjp: Learning Modern Web Security / #websecjp: 体系的に学ぶモダン Web セキュリティ

  • Did an eight-hour workshop on web security at National Institute of Information and Communications Technology (NICT) Innovation Center.
  • Reference: event page

Security Camp 2019

  • Conducted a 4-hour training named "体系的に学ぶモダン Web セキュリティ" (Learn Modern Web Security Systematically).
  • Reference: event page

JNSA e-zine ("BlackHat USA 2019 参加記")

  • Contributed an article to JNSA (Japan Network Security Association) e-zine.
  • Reference: article

Packet Hacking Village of DEFCON 2019

  • Participated as a volunteer staff.

Security Mini Camp in Yamanashi 2019 / セキュリティ・ミニキャンプ in 山梨 2019

  • Gave a presentation to introduce activities of Security Camp Committee.
  • Reference: event page

SECCON Beginners CTF 2019

  • Provided three challenges: Ramen, Secure Meyasubako, and Himitsu.

Shibuya.XSS techtalk #11

  • Gave a presentation on hot topics on XS-Leaks and advanced CSS Injection.
  • Reference: event page

TSG CTF 2019

  • Provided two challenges: RECON and BADNONCE.

2018

Security Mini Camp in Okayama 2018 / セキュリティ・ミニキャンプ in 岡山 2018

  • Conducted a 4-hour introduction-level class on Web security.
  • Reference: event page

第 14, 15, 19, 22 回 ゼロから始めるセキュリティ入門 勉強会

  • Gave a small presentations on hot topics on Web security at the time.
  • Reference: event page

第21 回 セキュリティさくら (Security Sakura, a Japanese seminar on security)

  • Talked on the complexity of Web and its security from the viewpoint of attackers.
  • Reference: event page

SECCON Beginners CTF 2017

  • Provided three challenges: Gimme your comment, SECCON Goods, Gimme your comment Revenge.

2013

OSC Hokkaido 2013 #osc13do

  • Gave a small presentation.
  • Reference: event page