winfunc research · Jul 2026
Winfunc described six public NGINX findings, including five CVE identifiers, and framed the work as evidence that model-driven vulnerability research can surface real issues in mature infrastructure code.
Public company, workplace, funding, and market signals
Updated Jul 30, 2026
winfunc, formerly Asterisk, is a YC S24-backed AI-native security engineering platform that audits codebases to find, verify, triage, and patch vulnerabilities with executable proof-of-concepts and automated remediation pull requests.
Primary product
AI-native security engineering platform for codebase vulnerability detection, verification, triage, and patch generation
Founded
2024
Headquarters
San Francisco, California, United States
Team size
1-10
Work style
Remote
Industry
Data Security Software Products
Sub-industry
AI-native application security / security engineering
Business model
0 jobs at winfunc
Check back later for new openings
Stage
Pre-Seed
Total raised
$500K
Latest round
Pre Seed Round · Sep 2024
Latest amount
$500K
Sep 2024 · Y Combinator
Founders
Co-founder & COO
Investors
Research-heavy and security-research/CTF-oriented, with a strong emphasis on executable evidence, low-noise findings, and continuous disclosures/public writeups.
Work style
Remote
Pricing
Not publicly listed; appears demo-led / sales-led
Differentiators
Technology
Competitors
winfunc research · Jul 2026
Winfunc described six public NGINX findings, including five CVE identifiers, and framed the work as evidence that model-driven vulnerability research can surface real issues in mature infrastructure code.
winfunc research · Mar 2026
Winfunc reported 13 confirmed issues across nine projects, including Node.js, React, NGINX, Mattermost, Supabase, Bun, Gumroad, Anthropic's MCP SDK, and Better-Auth, with seven CVEs and all findings patched or fixed upstream.
LinkedIn · Jan 2026
Mufeed VH said one React Server Components denial-of-service vector was discovered with help from a winfunc AI agent, referencing CVE-2026-23864.
LinkedIn · Jan 2026
The company announced a Node.js permission model bypass via unchecked Unix domain socket connections (CVE-2026-21636) and said its system had also found issues in MCP, Supabase, Bun, Gumroad, Cal.com, and Better-Auth.
Y Combinator · Aug 2024
YC launch post introducing Asterisk/winfunc as an AI security team that automatically finds, exploits, and patches vulnerabilities with zero false positives.