Sign in

Katie Paxton-Fear

@insider.phd
5.4K followers 1.3K following 431 posts

Dr, apparently. Security Adovcate @semgrep & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her

PostsRepliesMedia
Katie Paxton-Fear @insider.phd · 22/10/2025
We’re hiring!!! Want to come work with and grow the coolest security research team? Come join us, we’re looking for someone to help lead our engineering efforts, influencing roadmap, research direction and improvements in breadth and depth of the product job-boards.greenhouse.io/semgrep/jobs...
job-boards.greenhouse.io
Job Application for Engineering Manager, Security Research Coverage at Semgrep
SF, NYC, Boston, Denver
031
Katie Paxton-Fear @insider.phd · 04/10/2025
Check out the latest Paged Out! Zine (page 22 under hardware) and you’ll find an article written by me about my little eink labelling project and the highs and lows of learning to CAD, solder and program an ESP32, how hard can it be?
080
Katie Paxton-Fear @insider.phd · 04/10/2025
Link is here www.justhacking.com/... want to try before you buy? I've made 3 modules free so you can get a feel for what you're buying!
justhacking.com
API Hacking - Just Hacking Training (JHT)
Dr. Katie Paxton-Fear's hands-on course is the ultimate guide to API Hacking! Covers the entire OWASP API Top 10 from entry point to exploit.
040
Katie Paxton-Fear @insider.phd · 04/10/2025
⚠️ IMPORTANT: This is NOT a "bug bounty" course and won't make you rich. If you're just looking for a magic methodology to find a bug and get paid tomorrow, do not buy this course. This is about building deep, foundational API hacking skills, not about bug bounty hunting.
250
Katie Paxton-Fear @insider.phd · 04/10/2025
Everyone learns differently. The course comes packed with: ✅ In-depth Videos, A LOT of Videos tbh ✅ Written Content & Guides ✅ Quizzes ✅ Demos ✅ Hands-on Exercises ✅ Lab ✅ Q+A and Support From Me
120
Katie Paxton-Fear @insider.phd · 04/10/2025
This course is 100% new content, designed for all skill levels. We start with "What is an API?" and go all the way from recon to reporting. It includes videos, written guides, exercises, and a new, realistic lab environment to practice in. The hands-on lab is free on GitHub!
120
Katie Paxton-Fear @insider.phd · 04/10/2025
I've spent a lot of time thinking about the best way to teach API security from the ground up for beginners. Today, I'm excited to launch the result: My brand new API Hacking course on JHT. It's built to give you a deep, foundational understanding of how to test modern APIs. 🧵
2152
Katie Paxton-Fear @insider.phd · 03/10/2025
Link is here www.justhacking.com/... want to try before you buy? I've made 3 modules free so you can get a feel for what you're buying!
justhacking.com
API Hacking - Just Hacking Training (JHT)
Dr. Katie Paxton-Fear's hands-on course is the ultimate guide to API Hacking! Covers the entire OWASP API Top 10 from entry point to exploit.
040
Katie Paxton-Fear @insider.phd · 03/10/2025
⚠️ IMPORTANT: This is NOT a "bug bounty" course and won't make you rich. If you're just looking for a magic methodology to find a bug and get paid tomorrow, do not buy this course. This is about building deep, foundational API hacking skills, not about bug bounty hunting.
150
Katie Paxton-Fear @insider.phd · 03/10/2025
Everyone learns differently. The course comes packed with: ✅ In-depth Videos, A LOT of Videos tbh ✅ Written Content & Guides ✅ Quizzes ✅ Demos ✅ Hands-on Exercises ✅ Lab ✅ Q+A and Support From Me
120
Katie Paxton-Fear @insider.phd · 03/10/2025
This course is 100% new content, designed for all skill levels. We start with "What is an API?" and go all the way from recon to reporting. It includes videos, written guides, exercises, and a new, realistic lab environment to practice in. The hands-on lab is free on GitHub!
120
Katie Paxton-Fear @insider.phd · 03/10/2025
I've spent a lot of time thinking about the best way to teach API security from the ground up for beginners. Today, I'm excited to launch the result: My brand new API Hacking course on JHT. It's built to give you a deep, foundational understanding of how to test modern APIs. 🧵
1101
Reposted by Katie Paxton-Fear
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 27/09/2025
I interviewed Farah Hawa at Diana Initiative in Las Vegas last month! twp.ai/9PVWh8
041
Reposted by Katie Paxton-Fear
Semgrep @semgrep.com · 18/09/2025
📅 Join @insider.phd as she explores the realities of AI’s impact on AppSec: 🔹 Moving past uncertainty to see where AI truly fits in. 🔹 Automating repetitive tasks and cutting false positives. 🔹 Strengthening security, improving accuracy, reducing risk. ➡️ semgrep.dev/events/doubt...
011
Katie Paxton-Fear @insider.phd · 03/09/2025
My favourite genre on YouTube is engineers making stuff no one asked them to make, how hard can it be? The struggle is the fun youtu.be/qy_9w_c2ub0
youtu.be
I built my own Phone... because innovation is sad rn
YouTube video by Marcin Plaza
0101
Katie Paxton-Fear @insider.phd · 02/09/2025
Link to register semgrep.dev/events/s... should be available on YouTube later this week! 2/2
semgrep.dev
Security Rulez: I took my boss to Hacker Summer Camp and here’s what happened
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.
030
Katie Paxton-Fear @insider.phd · 02/09/2025
Tomorrow I'll be live on this webinar chatting about Hacker Summer Camp with my boss. We'll recap everything that happened and all the talks we did, share our top moments and our highlights from this year as well as share Jayson's experience at his first hacker con! 1/2
Security Rulez: I took my boss to Hacker Summer Camp and here’s what happened on September 3rd, 2025 at 10:00 AM PT
140
Katie Paxton-Fear @insider.phd · 29/08/2025
Check out the Packt conference with my link (gives you 20% off) below, or perhaps just get your agent to come and give you the cliff notes 😉 Hope to see you (or your AI note takers) there on September 13th!
eventbrite.com
Next-Gen Cyber AI
We’re back with another high‑impact day of AI defense. Unlock hands-on sessions for AI security. Walk away with field‑tested playbooks.
010
Katie Paxton-Fear @insider.phd · 29/08/2025
We'll move beyond the hype and look at the real, emerging threats: Agents making hallucinated (but effective!) API calls. "Hackbots" chaining unauthorized actions to breach systems. Insecure frameworks that give attackers the keys to the kingdom.
120
Katie Paxton-Fear @insider.phd · 29/08/2025
What if the AI agent designed to help you... decides to hack you instead? 🤯 That's the chilling reality I'll be exploring in my upcoming talk: AI Agents Gone Rogue? Hackbots, AI Agents and The Future of the AI Attack Surface
160
Katie Paxton-Fear @insider.phd · 28/08/2025
Ironically this video ended up in my eyeballs thanks to the YouTube algorithm but it is REALLY good and really speaks to some of my thoughts around algorithmic content being horrible for you, and I really recommend it 🔥🔥 youtu.be/Bdj14_jdumI
youtu.be
be your own algorithm
YouTube video by pagemelt
041
Katie Paxton-Fear @insider.phd · 18/08/2025
Register here: semgrep.dev/events/m... PS: This is my first official Semgrep webinar, so you better all attend so I look good! 😂 😂 😂 😂
semgrep.dev
MCP: Model, Context… Propaganda? What security teams need to know about the latest hyped up AI tech
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.
061
Katie Paxton-Fear @insider.phd · 18/08/2025
MCP is all anyone can talk about right now, but uhh what is it? And what do you actually need to know about the latest hyped AI thing? Join me tomorrow as I dig into it as we cover a TL;DR for security teams and perhaps why it might actually be industry changing
120
Katie Paxton-Fear @insider.phd · 18/08/2025
media.tenor.com
a woman in a pink top says yes yes yes in front of a microphone
ALT: a woman in a pink top says yes yes yes in front of a microphone
000
Katie Paxton-Fear @insider.phd · 18/08/2025
If you’re in the market for a bag, the bag is a Patchaholic from CTactical originally they sent me the wrong one but fixed it 2days later despite being in Vietnam so I really rate their customer service not to shill for them but I know folks might be interested ctactical.vn/products/ct1...
ctactical.vn
CT15 V3.0 Backpack - PATCHAHOLIC N420D RS
(This is the version WITHOUT Water Bottle Pockets) We don't know when Patches originating from military activities became popular and became a bridge between the Carry, EDC, and Outdoor communities. N...
020
Katie Paxton-Fear @insider.phd · 18/08/2025
How to get rid of cash at DEFCON? Buy patches! Here are my DEFCON purchases (combined with a few I already had!
160
Katie Paxton-Fear @insider.phd · 17/08/2025
I did but it took me a while to update my LinkedIn, I’ll ping them to update it ty for letting me know
110
Katie Paxton-Fear @insider.phd · 16/08/2025
Link for conference info: yowcon.com
yowcon.com
YOW! Australia
120
Katie Paxton-Fear @insider.phd · 16/08/2025
Officially booked flights to Australia! I’ll be in Melbourne, Brisbane and Sydney for YOW! Conference(s) 30 Nov - 6 Dec Melbourne 6 Dec - 10 Dec Brisbane 10 Dec - 14 Dec Sydney If you want to meet up let me know! This will be my first time in Australia (and flying this far!)
692
Katie Paxton-Fear @insider.phd · 13/08/2025
We’re just VERY keen lol enjoy your vacation
110
Katie Paxton-Fear @insider.phd · 13/08/2025
You can find the full video here, thank you very much to Bugcrowd for once again sponsoring this content and for telling me what their top first bugs are <3 youtu.be/CpV3XDqzYyE
youtu.be
Analysing the DOM to find Reflected XSS
YouTube video by InsiderPhD
010
Katie Paxton-Fear @insider.phd · 13/08/2025
How do you find Reflected XSS in real programs? Well I'm glad you asked! This episode we're diving DOM-first into Javascript and covering how to find XSS in highly interactive applications like Angular!
130
Katie Paxton-Fear @insider.phd · 09/08/2025
@blenster.com Kindly requesting the 2hr workshop version of your KiCAD talk 🙏🙏🙏🙏
280
Katie Paxton-Fear @insider.phd · 09/08/2025
Thank you everyone for coming to my DEEPLY unserious vibe coding talk, hopefully it inspires you to just learn how to program ESP32 rather than spend 4-5 hours trying to get it to produce working YAML
170
Katie Paxton-Fear @insider.phd · 07/08/2025
Sun 10th Aug @ 11:50am I’ll be handing out the CTF prize for the AppSec Village CTF very official!
010
Katie Paxton-Fear @insider.phd · 07/08/2025
Sun 10th Aug @ 9:30am I will once again be in the @AppSec_Village (starting to see a theme?) come say hi!
110
Katie Paxton-Fear @insider.phd · 07/08/2025
Sat 9th Aug @ 3pm Ill be sharing my brand new API hacking 2hour workshop at the Red Team Village, new labs, new methodologies and new content, it’s a one-stop-shop for API hacking!
100
Katie Paxton-Fear @insider.phd · 07/08/2025
Sat 9th Aug @ 2pm I’ll be running an interactive experience at the Blue Team Village Nook, part RPG, part improv show and part fun making threat modelling fun! Come join us
110
Katie Paxton-Fear @insider.phd · 07/08/2025
Sat 9th Aug @ 9:30am I will be back at the @AppSec_Village once again greeting all you lovely folks, helping you find where you need to go and answering questions!
110
Katie Paxton-Fear @insider.phd · 07/08/2025
Fri 8th Aug @ 5:30pm I’ll be doing a talk about vibe eletronics-ing, and vibe coding and sharing some of my forays into the world of hardware hacking as a noob!
120
Katie Paxton-Fear @insider.phd · 07/08/2025
Fri 8th August @ 1:30pm I will be chatting about bug bounty + content creation with fellow creators NahamSec and Rhynorater at the Bug Bounty Village talking all things content, education and hacking (and how to balance the 3!)
110
Katie Paxton-Fear @insider.phd · 07/08/2025
Fri 8th Aug @ 12:30pm my colleague Eaton will be presenting his API hack that allowed him to remotely start a car, check it out at the Car Hacking Village on creator stage 3 (I’ll be in the audience)
110
Katie Paxton-Fear @insider.phd · 07/08/2025
Fri 8th Aug @ 9:30am I’ll be at the @AppSec_Village at DEFCON, welcoming you to the village and helping answer any questions, we have coffee so why not come for a chat and a brew!
110
Katie Paxton-Fear @insider.phd · 07/08/2025
Also on Thurs 7th Aug @ 8pm I’ll be at the Semgrep party at Level Up @ the MGM Grand, registration is still open and we should have space for those who register on the day semgrep.dev/events/l...
110
Katie Paxton-Fear @insider.phd · 07/08/2025
Thurs 7th Aug @ 4pm I’ll be at the MSRC Researcher Party before I head off for dinner with some creator friends
110
Katie Paxton-Fear @insider.phd · 07/08/2025
Looking for me at DEFCON? Here’s where I’ll be!
170
Katie Paxton-Fear @insider.phd · 04/08/2025
On Thursday you’ll find me catching a short break before the MSRC VIP party and the Semgrep party at Level Up 9/9
000
Katie Paxton-Fear @insider.phd · 04/08/2025
Also on Wednesday 6th Aug, I will be at the Semgrep booth on and off, so if you pop by you might see me there! 8/9
100
Katie Paxton-Fear @insider.phd · 04/08/2025
Also on Wednesday 6th Aug, I will be on a panel at BlackHat: Bug Bounty Group Therapy: Confessions, Concerns, and Community Solutions at 1:30 pm located at Lagoon G, Level 2 to chat about what works (and doesn't) for bug bounty hunters www.blackhat.com/us-... 7/9
110
Katie Paxton-Fear @insider.phd · 04/08/2025
On Wednesday 6th Aug, I will be joining my colleague @shehackspurple for her coffee meet and greet, please do swing by 8:00 am - 10:00 am at the big Starbucks, Mandalay Bay, the big one, right next to the convention center! 6/9
251