Katie Paxton-Fear

@insider.phd

Dr, apparently. Security Adovcate @semgrep & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her

Check out the latest Paged Out! Zine (page 22 under hardware) and you’ll find an article written by me about my little eink labelling project and the highs and lows of learning to CAD, solder and program an ESP32, how hard can it be?

Bild

I've spent a lot of time thinking about the best way to teach API security from the ground up for beginners. Today, I'm excited to launch the result: My brand new API Hacking course on JHT. It's built to give you a deep, foundational understanding of how to test modern APIs. 🧵

BildBild

I've spent a lot of time thinking about the best way to teach API security from the ground up for beginners. Today, I'm excited to launch the result: My brand new API Hacking course on JHT. It's built to give you a deep, foundational understanding of how to test modern APIs. 🧵

BildBild

Tomorrow I'll be live on this webinar chatting about Hacker Summer Camp with my boss. We'll recap everything that happened and all the talks we did, share our top moments and our highlights from this year as well as share Jayson's experience at his first hacker con! 1/2

Security Rulez: I took my boss to Hacker Summer Camp and here’s what happened on September 3rd, 2025 at 10:00 AM PT

What if the AI agent designed to help you... decides to hack you instead? 🤯 That's the chilling reality I'll be exploring in my upcoming talk: AI Agents Gone Rogue? Hackbots, AI Agents and The Future of the AI Attack Surface

MCP is all anyone can talk about right now, but uhh what is it? And what do you actually need to know about the latest hyped AI thing? Join me tomorrow as I dig into it as we cover a TL;DR for security teams and perhaps why it might actually be industry changing

Bild

Officially booked flights to Australia! I’ll be in Melbourne, Brisbane and Sydney for YOW! Conference(s) 30 Nov - 6 Dec Melbourne 6 Dec - 10 Dec Brisbane 10 Dec - 14 Dec Sydney If you want to meet up let me know! This will be my first time in Australia (and flying this far!)

How do you find Reflected XSS in real programs? Well I'm glad you asked! This episode we're diving DOM-first into Javascript and covering how to find XSS in highly interactive applications like Angular!

Bild

Thank you everyone for coming to my DEEPLY unserious vibe coding talk, hopefully it inspires you to just learn how to program ESP32 rather than spend 4-5 hours trying to get it to produce working YAML

Bild

🥁🥁🥁🥁🥁 Pleased to announce that I have officially joined the team at @semgrep.com as a security advocate! I’m thrilled to be alongside my fellow Infosec content creators (aaaaaa 🫨) in helping organisations secure the next generation of applications the easy way!

Wondering where I'll be speaking this Hacker Summer Camp? Well here's the official schedule! I'll be speaking at the @BugBountyDEFCON, @IoTvillage @ DEFCON on friday. Then on saturday I'll be delivering a 2hr workshop on everything API hacking at the @RedTeamVillage 1/2

Bild

What kind of Hackybara are you? Come find me at Hacker Summer Camp and say hi for one (or an entire set) of these little guys, I’ll be at BlackHat, BSidesLV and DEFCON

Bild

I will be at Hacker Summer Camp this year and it’s going to be a busy one! 8/3 - 8/11 ✅In person free workshop ✅Talks (more info soooooon) ✅Booth Duty ✅Big announcement AND fun giveaway stuff PLEASE invite me to things I can’t wait to catch up with everyone!

I am delighted to be apart of this panel at the @RUSI_org on the 7th of July, we'll be exploring @joetidy's world of teenager cyber criminals and answer the key question, how do we prevent teenage boys down this path in the first place 1/2

BildBild

I really like working with hardware because you get some FUN bugs: code only worked while spamming the serial port because otherwise the loop was running too fast 😂😂😂