@InsiderPhDi
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom App Store
Account-level information from X, not a live location or the device used for a specific post.
Dr, apparently. Security Adovcate @semgrep & Hacker. #BugBounty hunter & #infosec YouTuber. APIs & Interlinked OffSec, PhD in AI+Sec @hacknotcrime. she/her
Manchester, UK
Joined February 2018
- Tweets21.5K
- Following1.7K
- Followers99.7K
- Likes19K
Pinned Tweet
Find me on the internet
Mastodon: infosec.exchange/@insiderphd
YouTube: youtube.com/@InsiderPhD
Newsletter: insiderphd.substack.com
Discord: InsiderPhD
Bluesky: bsky.app/profile/insider.phd
LinkedIn: linkedin.com/in/katiepf
Katie Paxton-Fear retweeted
proof AI isn't taking anyone's job
instead of asking AI to review this code, i @ tagged everyone in our engineering org to review this code change i hand-crafted by asking AI to refactor our entire codebase in a new programming language i made up
now they get to work over the whole weekend learning a new language and reviewing my code
it's tough to be a job creator but someone has to do it
I’m ngl cars are very daunting but I’ve managed to replace all the broken bulbs in my dashboard and switched the speed from kph to mph
What is AppSec? what do AppSec engineers do all day? What’s a SAST and a DAST? What gives npm? And wow you look tired, are you doing okay? Getting enough sleep? And other questions your AppSec Engineer friends are answering, answered, again
semgrep.dev/blog/2026/what-a…
2 of the static analysis bugs I was involved with finding along with @drewdennison at @semgrep just got published! Arbitrary file read and SQL injection in a DuckDB query runner in redash
Semgrep is featured in @latiotech 's latest AI Security industry report — and we’re excited to see Guardian included in the conversation. 🐸
AI agents are changing how software gets built, and security needs to evolve alongside them. As more code is generated by AI, securing it earlier in the development process is becoming increasingly important.
Guardian brings security directly into AI coding workflows, helping developers catch issues in AI-generated code before they reach the PR.
Become ungovernable use GLM
100% this!
I will stand on a mountain with everyone else on VCP/TAC, and than run to my local models and do real work.
Its about calling out the hypocrisy. They claim they want to support cyber protections, but only enable the corporations because of the 🤑 . But I disagree with @InsiderPhD on the "slow death of the independent researcher".
Not cause she's inherently wrong, but because I refuse to accept defeat. The open source / open weight model community is strong and there are TONS of people building capabilities for local independant researchers who aren't afraid to lean into AI.
I will not be able to name everyone, but @MiaAI_lab @Blackfrost_AI @OrcaRouter and SOOO many others are absolutely trying to preserve and/or match the capabilities for independants.
Please dont give up! Lean in! Reach out to me - i'll help. There IS room for everyone. YOU DO NOT need a datacenter at home. You can load models across a lot of hardware - and there are people pushing the limits daily.
I promise. We're not done.
Trusted access and cyber verification for AI favour companies over individuals. Maybe that’s better for verification purposes. But the best vuln-finding tools go to whoever has the corporate paperwork. We're watching the slow death of the independent bug bounty researcher.
Katie Paxton-Fear retweeted
Common themes I've noticed:
- AI is "totally different" than software, so cybersecurity doesn't apply
- Cybersecurity slows everything down, it's a legacy way of thinking in the AI age
- AI will replace cybersecurity through iterative self-improvement
They are speedrunning 30+ years of cybersecurity learnings through repeated public failures. It's both horrifying and hilarious at the same time.
Katie Paxton-Fear retweeted
i'm back on the job market again
- golang
- mid level role
- location flexible
⏰ pls rt for help ⏰
bad news I got a cease and desist, good news I have updated the firmware to add the carousel layout, and fixed the battery bug
Katie Paxton-Fear retweeted
Sad but necessary:
nomeatproxy.com/
I call my approach to using AI productively as “don’t touch my garbage”.
I don’t want AI to do anything to my ideas, I don’t want it to write as me, to give me solutions, or to tell me answers. Instead I get AI to ask me questions that challenge the way I’m thinking and forces me to re-explain my ideas and thoughts
And then I tell it to shut the fuck up so I can write it down myself. I am not a flesh UI for Claude.
Katie Paxton-Fear retweeted
I built a new home for my book, JavaScript for Hackers.
Every payload on the page is real. Click one and it pops in your browser.
Then learn to build your own: parenthesis-free calls, non-alpha JS from just !+[]{}, DOM clobbering, SOP bypasses, the latest XSS. 1/4
Katie Paxton-Fear retweeted
This was the most brilliant idea to secretly achieve an AI slowdown by the shadow council that I’ve ever seen.