米内貴志(Takashi Yoneuchi)の登壇・メディア出演・コミュニティ活動の記録です。公開されている記事・動画・登壇資料へのリンクを掲載しています。プロフィール・経歴 と登壇資料一覧 もご覧ください。
登壇予定 · 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2013
登壇予定
Moderator / Scheduled to moderate the panel 「AIで攻撃が加速する今、どう『先に』守るか」 with speakers from Cloudflare Japan, Anthropic Japan and GMO Internet Group.
公式プログラム・登壇情報
2026
Talk / Gave a talk titled 「Web ブラウザの構造を捉えるたのしみ」 and joined an audience Q&A as the author of Web Browser Security.
イベント・登壇情報
TV / Interview and demonstration on AI and cybersecurity.
番組記事 · YouTube · 掲載告知
Talk / 新規パッケージを全量検査することで見える SSCA 脅威動向
イベント・登壇情報
Talk / セキュアなコンテナイメージをつくろう 〜CVE-free コンテナイメージ「Takumi Images」の概要と裏話〜
Slides
Web / Roundtable with GMO Cybersecurity by Ierae on AI, security engineering and our mission.
攻撃者優位の時代に問われる「使命感」
TV / Contributed to reporting for 「ミュトスの衝撃〜人間の限界を超える能力とは〜」.
NHK記事 · 取材協力の告知
Web / Interview on how defenders can keep pace with advances in AI.
インタビュー
Talk / Mastra ソフトウェアサプライチェーン攻撃の概要と対応指針
Slides
Talk / Delivered the closing session summary at an OSS security event with Yusuke Wada, azu and Kyohei.
イベント・登壇情報
Talk / エンジニアを狙う攻撃への備え — もし、うちのCTOが侵害されたら?を考察する
イベント・登壇情報
Panel / Discussed preparedness and incident response with 江頭輝 from freee.
イベント・登壇情報
Talk / axios, LiteLLM...不使用だったのでOK、ではない。「次に備える」ソフトウェアサプライチェーン侵害への対策
Slides · YouTube
Talk / Spoke at the GMO cybersecurity conference.
登壇情報
Talk / 2026年もソフトウェアサプライチェーンのリスクに立ち向かうために / Product Security Square #3
Slides
Talk / Joint sponsor session with Adachi from Findy.
登壇情報 · イベント
2025
Talk / Discussed security for independently developed web services and vibe coding, followed by an audience Q&A.
イベント・登壇情報
Talk / AIエージェントSaaSを安全に提供する技術 / Architecture Conference 2025
Slides
YouTube / Discussion of AI governance, vibe coding and automation for defenders.
番組を見る
Competition / Participated as team representative for GMO Flatt Security; the team placed third in the AppSec Village CTF and fifth in the Hardware Hacking Village CTF.
大会結果・コメント
Keynote / 実践 “Secure” Vibe Coding ― AIの速度で安全にソフトウェアを届けるために
講演情報
Moderator / Led a panel on secure adoption of AI coding agents with engineers from DMM.com, M3 and freee.
イベント・登壇情報
Talk / 診断AIエージェントによるセキュリティの未来 – 著名OSS向け0-dayリサーチを例に
Slides
Talk / セキュリティ診断AIエージェント「Takumi」の雇用によって実現する開発生産性の向上
Slides
Talk / AIエージェントの「作業場」としてのサンドボックス技術
Slides
Talk / セキュリティ診断AIエージェント Takumi がもたらす変化 - 著名OSS 向け0-dayリサーチを例に
Slides
Talk / Online lunchtime session on AI agents, MCP and security.
イベント・登壇情報
Talk / Joint session on AI-assisted development and security assessment.
イベント・登壇情報
Workshop / Presented Takumi at a hands-on event co-hosted with Findy.
イベント・登壇情報
Talk / 横断SREの立ち上げと、AWSセキュリティへの取り組みの軌跡
Joint sponsor session with Ryo Adachi from Findy.
公式プログラム
2024
Education / Co-produced the Product Security class with Naohiro Fujita.
プログラム・担当情報
Web / Interview with CEO Yasutaka Ide on joining GMO Internet Group and our plans for Flatt Security.
インタビュー
Web / Contributed to a survey of 13 development and security engineers.
記事
Gave a presentation on building ASM systems with Satoshi Tajima from Finatext Inc.
The session title was: セキュリティベンダー/ユーザー双方の視点で語る、Attack Surface Managementの実践
Talk / CAASM に学ぶ、低コストかつ継続的なWeb脆弱性診断の実現手法
イベント・登壇情報
Gave a 40min presentation on principles in designing a good security strategy as a conference sponsor.
The session title was: CNAPP・ASM・ASPM…またバズワードが移りゆく、2024 年もなお不変の脆弱性評価・管理の勘所
See this page for further information
Appeared in a panel discussion about careers in product security fields.
See this page for further information
Contributed an article to our tech blog.
Visit this page to read.
Gave a lightning talk on cloud security 101.
The session title was: AWS/GCPのセキュリティ、いつから・誰が・どう始める?
See this page for further information
2023
Web / Team interview about ICC 2023, where I served as Team Asia’s head captain.
インタビュー
Web / Contributed comments on product security in 2023.
記事
Web / Contributed comments on Shisho Cloud and customizable cloud security checks.
記事
Talk / AWSのセキュリティ管理をPolicy as Codeで加速する ― 最高のCSPM体験を目指して
イベント・登壇情報
Gave a 30min presentation on early/seed startups.
Gave a short talk on how to build a strong culture on product security.
Appeared in the panel discussion on security engineer careers.
See this post for feeling the vibe!
Gave a short talk on the intersection of Site Reliability Engineering (SRE) and Security Engineering.
See this page for further information
YouTube recording
Appeared on the interview-styled page.
Visit this page for further information.
Contributed an article to our tech blog.
Visit this page to read.
Gave a short talk on CSPM 101.
See this page for further information
Served as a producer to design the whole class.
Gave a 2-hour training named "Webプロダクトセキュリティへのいざない" by myself as well.
See this page for further information
Won 18th in ACSC 2023, by which I was selected as finalists of ICC 2023.
Gave a talk titled "開発者体験をむしろ向上させるセキュリティ施策のイロハ ― Policy as Code の理論と実践".
See this page for further information
The transcription is available here .
Appeared at a panel discussion about software supply chain security.
See this page for further information
Gave a talk titled "Eliminating ReDoS with Ruby 3.2".
See this page for further information
2022
Talk / 実践 SpiceDB — クラウドネイティブ時代をサバイブできるパーミッション管理の実装を目指して
セッション · Slides
Appeared at a panel discussion about software supply chain security.
See this page for further information
Contributed a really small part of the translation project.
Check out this page to order the book!
Conducted a 6-hour training named "ソフトウェサプライチェーンセキュリティのこれから".
Served as a producer to design the whole class.
See this page for further information
Related: Web セキュリティクラスのプロデュース後日談
Appeared at a panel discussion about next-generation security operations.
See this page for further information
Appeared at a panel discussion on career stratergy of security engineers.
See the event page for further information.
2021
Talked about Shisho and what it was like becoming the CTO of a Japanese cyber security company.
Click here to read the interview!
Appeared at a Q&A session about developer experience.
See this page for further information
Gave a talk about developer-first security.
See this page for further information
Conducted a 4-hour training named "ちいさな Web ブラウザを作ってみよう".
Here's an online book for this event: "ちいさな Web ブラウザを作ってみよう" .
See this page for further information
Contributed some parts to a book describing all about CTF written by some specialists.
Check out this Amazon page to order the book!
Organized some parts of the project.
Provided a Web challenge named osoba.
Discussed the future of Web security with great security engineers.
See here to check the detail of the event!
Gave a short seminar on Web-related modern security aspects.
See the event page for further information.
Contributed an article explaining how to deal with anxiety about cyber security for NISC 's website.
You can read the article from here (Wayback Machine ).
Appeared in an interview article in Japanese: 前編 , 後編 .
Published a book on security features of web browsers.
See this page for further information of this book.
2020
Conducted a 4-hour training named "Web Security from the Macro Perspective: Understanding Modern Hacking Techniques with Web Infrastructure and Side-channels" (日: 「マクロな視点から捉える Web セキュリティ: Web インフラストラクチャを利用した攻撃とサイドチャネル攻撃の実践と評価」).
Reference: event page
Appeared in a panel discussion named "Why organize a CTF -This is the way-" (日: 「我々はなぜCTFを運営するのか?」).
Reference: event page
Gave a presentation about CTFs and how to learn security stuffs related to them.
Reference: event page
Gave a presentation to introduce activities of Security Camp Committee.
Reference: event page
Did a online & long-term course on Web security.
Reference: event page .
Talked about issues related to ReDoS and show a new attack vector.
Reference: event page
Organized the whole project.
Provided two challenges: unzip and somen.
2019
Did an eight-hour workshop on web security in collaboration with Information-technology Promotion Agency.
Provided a challenge named "Snippet".
Did an eight-hour workshop on web security at National Institute of Information and Communications Technology (NICT) Innovation Center.
Reference: event page
Conducted a 4-hour training named "体系的に学ぶモダン Web セキュリティ" (Learn Modern Web Security Systematically).
Reference: event page
Contributed an article to JNSA (Japan Network Security Association) e-zine.
Reference: article
Participated as a volunteer staff.
Gave a presentation to introduce activities of Security Camp Committee.
Reference: event page
Provided three challenges: Ramen, Secure Meyasubako, and Himitsu.
Gave a presentation on hot topics on XS-Leaks and advanced CSS Injection.
Reference: event page
Provided two challenges: RECON and BADNONCE.
2018
Conducted a 4-hour introduction-level class on Web security.
Reference: event page
Gave a small presentations on hot topics on Web security at the time.
Reference: event page
Talked on the complexity of Web and its security from the viewpoint of attackers.
Reference: event page
Provided three challenges: Gimme your comment, SECCON Goods, Gimme your comment Revenge.