Sign in

Katie Paxton-Fear

@insider.phd
5.4K followers 1.3K following 431 posts

Dr, apparently. Security Adovcate @semgrep & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her

PostsRepliesMedia
Katie Paxton-Fear @insider.phd · 22/10/2025
We’re hiring!!! Want to come work with and grow the coolest security research team? Come join us, we’re looking for someone to help lead our engineering efforts, influencing roadmap, research direction and improvements in breadth and depth of the product job-boards.greenhouse.io/semgrep/jobs...
job-boards.greenhouse.io
Job Application for Engineering Manager, Security Research Coverage at Semgrep
SF, NYC, Boston, Denver
031
Katie Paxton-Fear @insider.phd · 04/10/2025
Check out the latest Paged Out! Zine (page 22 under hardware) and you’ll find an article written by me about my little eink labelling project and the highs and lows of learning to CAD, solder and program an ESP32, how hard can it be?
080
Katie Paxton-Fear @insider.phd · 04/10/2025
I've spent a lot of time thinking about the best way to teach API security from the ground up for beginners. Today, I'm excited to launch the result: My brand new API Hacking course on JHT. It's built to give you a deep, foundational understanding of how to test modern APIs. 🧵
2152
Katie Paxton-Fear @insider.phd · 03/10/2025
I've spent a lot of time thinking about the best way to teach API security from the ground up for beginners. Today, I'm excited to launch the result: My brand new API Hacking course on JHT. It's built to give you a deep, foundational understanding of how to test modern APIs. 🧵
1101
Reposted by Katie Paxton-Fear
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 27/09/2025
I interviewed Farah Hawa at Diana Initiative in Las Vegas last month! twp.ai/9PVWh8
041
Reposted by Katie Paxton-Fear
Semgrep @semgrep.com · 18/09/2025
📅 Join @insider.phd as she explores the realities of AI’s impact on AppSec: 🔹 Moving past uncertainty to see where AI truly fits in. 🔹 Automating repetitive tasks and cutting false positives. 🔹 Strengthening security, improving accuracy, reducing risk. ➡️ semgrep.dev/events/doubt...
011
Katie Paxton-Fear @insider.phd · 03/09/2025
My favourite genre on YouTube is engineers making stuff no one asked them to make, how hard can it be? The struggle is the fun youtu.be/qy_9w_c2ub0
youtu.be
I built my own Phone... because innovation is sad rn
YouTube video by Marcin Plaza
0101
Katie Paxton-Fear @insider.phd · 02/09/2025
Tomorrow I'll be live on this webinar chatting about Hacker Summer Camp with my boss. We'll recap everything that happened and all the talks we did, share our top moments and our highlights from this year as well as share Jayson's experience at his first hacker con! 1/2
Security Rulez: I took my boss to Hacker Summer Camp and here’s what happened on September 3rd, 2025 at 10:00 AM PT
140
Katie Paxton-Fear @insider.phd · 29/08/2025
What if the AI agent designed to help you... decides to hack you instead? 🤯 That's the chilling reality I'll be exploring in my upcoming talk: AI Agents Gone Rogue? Hackbots, AI Agents and The Future of the AI Attack Surface
160
Katie Paxton-Fear @insider.phd · 28/08/2025
Ironically this video ended up in my eyeballs thanks to the YouTube algorithm but it is REALLY good and really speaks to some of my thoughts around algorithmic content being horrible for you, and I really recommend it 🔥🔥 youtu.be/Bdj14_jdumI
youtu.be
be your own algorithm
YouTube video by pagemelt
041
Katie Paxton-Fear @insider.phd · 18/08/2025
MCP is all anyone can talk about right now, but uhh what is it? And what do you actually need to know about the latest hyped AI thing? Join me tomorrow as I dig into it as we cover a TL;DR for security teams and perhaps why it might actually be industry changing
120
Katie Paxton-Fear @insider.phd · 18/08/2025
How to get rid of cash at DEFCON? Buy patches! Here are my DEFCON purchases (combined with a few I already had!
160
Katie Paxton-Fear @insider.phd · 16/08/2025
Officially booked flights to Australia! I’ll be in Melbourne, Brisbane and Sydney for YOW! Conference(s) 30 Nov - 6 Dec Melbourne 6 Dec - 10 Dec Brisbane 10 Dec - 14 Dec Sydney If you want to meet up let me know! This will be my first time in Australia (and flying this far!)
692
Katie Paxton-Fear @insider.phd · 13/08/2025
How do you find Reflected XSS in real programs? Well I'm glad you asked! This episode we're diving DOM-first into Javascript and covering how to find XSS in highly interactive applications like Angular!
130
Katie Paxton-Fear @insider.phd · 09/08/2025
@blenster.com Kindly requesting the 2hr workshop version of your KiCAD talk 🙏🙏🙏🙏
280
Katie Paxton-Fear @insider.phd · 09/08/2025
Thank you everyone for coming to my DEEPLY unserious vibe coding talk, hopefully it inspires you to just learn how to program ESP32 rather than spend 4-5 hours trying to get it to produce working YAML
170
Katie Paxton-Fear @insider.phd · 07/08/2025
Looking for me at DEFCON? Here’s where I’ll be!
170
Katie Paxton-Fear @insider.phd · 04/08/2025
Here is everywhere I'll be in Vegas 2025, if you want to pop by say hi, meet up for coffee or listen to me waffle on about security... a thread 1/9
120
Katie Paxton-Fear @insider.phd · 21/07/2025
🥁🥁🥁🥁🥁 Pleased to announce that I have officially joined the team at @semgrep.com as a security advocate! I’m thrilled to be alongside my fellow Infosec content creators (aaaaaa 🫨) in helping organisations secure the next generation of applications the easy way!
7505
Katie Paxton-Fear @insider.phd · 21/07/2025
Recommended simply for the worlds weirdest souvenirs
050
Reposted by Katie Paxton-Fear
Semgrep @semgrep.com · 21/07/2025
🕵️‍♂️ Something strange is happening at Meow Wolf’s Omega Mart. Join Semgrep to challenge your perception of the limits of AppSec reality in the agentic era on Tuesday, August 5th from 6-9 pm. 🎟️ Register: semgrep.dev/events/omega... #HackerSummerCamp #Semgrep #OmegaMart #MeowWolf #AppSec #BlackHat
042
Katie Paxton-Fear @insider.phd · 17/07/2025
Wondering where I'll be speaking this Hacker Summer Camp? Well here's the official schedule! I'll be speaking at the @BugBountyDEFCON, @IoTvillage @ DEFCON on friday. Then on saturday I'll be delivering a 2hr workshop on everything API hacking at the @RedTeamVillage 1/2
152
Katie Paxton-Fear @insider.phd · 08/07/2025
What kind of Hackybara are you? Come find me at Hacker Summer Camp and say hi for one (or an entire set) of these little guys, I’ll be at BlackHat, BSidesLV and DEFCON
3213
Katie Paxton-Fear @insider.phd · 01/07/2025
I will be at Hacker Summer Camp this year and it’s going to be a busy one! 8/3 - 8/11 ✅In person free workshop ✅Talks (more info soooooon) ✅Booth Duty ✅Big announcement AND fun giveaway stuff PLEASE invite me to things I can’t wait to catch up with everyone!
031
Katie Paxton-Fear @insider.phd · 26/06/2025
I am delighted to be apart of this panel at the @RUSI_org on the 7th of July, we'll be exploring @joetidy's world of teenager cyber criminals and answer the key question, how do we prevent teenage boys down this path in the first place 1/2
1103
Katie Paxton-Fear @insider.phd · 21/06/2025
Today I am at @BSidesLeeds as a special guest no pressure 😅 I’ll be talking about AI, APIs and the four horsemen of the AI apocalypse
080
Katie Paxton-Fear @insider.phd · 13/06/2025
DEFCON slides ✅ See you in Vegas!
150
Katie Paxton-Fear @insider.phd · 13/06/2025
Check out these job interview tips! 🚀 Graduating students, listen up! I've been sharing loads of advice lately for my classes. Here's a quick summary of our chats to help you secure that first cyber security job. 💼 #JobInterview #CyberSecurity #mondaymentorship 1/21
151
Katie Paxton-Fear @insider.phd · 12/06/2025
I really like working with hardware because you get some FUN bugs: code only worked while spamming the serial port because otherwise the loop was running too fast 😂😂😂
030
Reposted by Katie Paxton-Fear
Ennie @anyuse.bsky.social · 09/06/2025
Sometimes I check on fiber-arts groups on Bluesky. I call it loom-scrolling.
1231
Katie Paxton-Fear @insider.phd · 08/06/2025
I am truely honoured to be a finalist in the volunteer of the year category for the Cyber Security Woman of the Year Award alongside such impactful women. I will be a bit cheeky though and kindly request your vote if you have a minute or 2 today! 1/2
190
Katie Paxton-Fear @insider.phd · 07/06/2025
The council of elders will decide your fate
1100
Katie Paxton-Fear @insider.phd · 07/06/2025
Oddly specific
240
Reposted by Katie Paxton-Fear
BSides Leeds @bsidesleeds.bsky.social · 30/05/2025
🎉 Speaker Announcement — Katie Paxton-Fear 🎉 We're excited that special guest @insider.phd will be at BSides Leeds to present 'Bad Vibes, Good job security? The future of security in an AI saturated world'. Catch Katie's talk at 10.30 on the 21st!
Speaker card for Katie Paxton-Fear
095
Katie Paxton-Fear @insider.phd · 29/05/2025
Vibe coding is all AI Twitter is talking about, but what is it? If you've ever wondered how to let AI do the coding so you can focus on the vibes today's video is for you. Create the recon tools you've always dreamed of using even if your code isn't quite production ready 1/3
Sad robots in a sweatshop programming RESTful APIs. Text: Forcing AI to make me RESTful APIs
110
Katie Paxton-Fear @insider.phd · 10/05/2025
Is this a really dumb idea or a genius idea I have no idea
070
Katie Paxton-Fear @insider.phd · 03/05/2025
Fun day out in Liverpool!
Sign showing: HM Passport Office Customer Main Entrance
050
Katie Paxton-Fear @insider.phd · 01/05/2025
Pleased to announce I will be keynoting the first ever Hacking APIs Con at @apidays NYC! It's everything you wanted to know about hacking GraphQL (but didn't know how to Query)
160
Reposted by Katie Paxton-Fear
maaaaaaay @mayverywellbe.bsky.social · 27/04/2025
@insider.phd teaching API hacking at the bug bounty village at #bsidessf
031
Katie Paxton-Fear @insider.phd · 30/04/2025
Had a blast at the API security happy hour, and not just 'cause it was in a pub!🍻 Big thanks to all who shared how my content helped you - your stories mean the world to me!😊 #APIsecurity #RSAC2025
060
Katie Paxton-Fear @insider.phd · 29/04/2025
And I am on the floor at RSA! Want to pick up some InsiderPhD stickers or just come say hi 👋 I’ll be at the Traceable by Harness Booth 3202 (between the two halls by the escalators!)
030
Reposted by Katie Paxton-Fear
Gareth Heyes @garethheyes.co.uk · 25/04/2025
Firefox treats multipart/x-mixed-replace like HTML. Chrome doesn’t. That tiny difference? It can turn a "non-exploitable" XSS into a real one. Abuse boundary handling, bypass filters, and make your payload land. thespanner.co.uk/making-the-u...
thespanner.co.uk
Making the Unexploitable Exploitable with X-Mixed-Replace on Firefox - The Spanner
In this post, we’ll look at an interesting difference in how Firefox and Chrome handle the multipart/x-mixed-replace content type. While Chrome treats it as an image, Firefox renders it as HTML - some...
0188
Katie Paxton-Fear @insider.phd · 26/04/2025
Want to level up your API Hacking? I’m doing a Hands On API Hacking workshop tomorrow at 1pm at the Bug Bounty Village @BsidesSF if you’re feeling stuck with API hacking this is the workshop for you
052
Katie Paxton-Fear @insider.phd · 26/04/2025
Hanging out at the Bug Bounty Village @bsidessf listening to @jhaddix talk about how to approach hacking AI using real approaches from his pen tests ✍️✍️✍️
080
Katie Paxton-Fear @insider.phd · 26/04/2025
Has infosec had you feeling a bit off? A bit uncomfortable? Bit of a weird vibe? Why not relish those ominous feelings with some bad vibes of your own? Come say hi at @bsidessf and revel (or find a sticker on the outside tables)
040
Katie Paxton-Fear @insider.phd · 26/04/2025
Has infosec had you feeling a bit off? A bit uncomfortable? Bit of a weird vibe? Why not relish those ominous feelings with some bad vibes of your own? Come say hi at @bsidessf and revel (or find a sticker on the outside tables)
010
Katie Paxton-Fear @insider.phd · 15/04/2025
Wanted to share the final product of my eink project (going to do a full video or maybe a few… this week), but heres a spoiler for the curious
180
Katie Paxton-Fear @insider.phd · 09/04/2025
In December Eaton set his sights on McDonald’s, and he cooked up an interesting menu of vulnerabilities, from essentially free food, to massive PII leaks. Curious how he did it? What to know how he pivoted once he got access? What about his API hacking toolkit? 1/2
160
Katie Paxton-Fear @insider.phd · 08/04/2025
Here is where I am with my ESP32 labelling project, you can scan an NFC tag and have it populate the label with filament details
1100
Katie Paxton-Fear @insider.phd · 07/04/2025
One of the most difficult things for me ethically in hacking is jailbreaking physical hardware you own. One the one hand they are security vulnerabilities, and pretty serious RCEs at that and therefore you need to report them to the vendor because they can be abused by attackers
182