Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)
Maa Yhdysvallat
Genret Teknologia
Kieli EN
Jaksot 177
Viimeisin 17.09.2026

A technical podcast by hackers for hackers, covering bug bounty tips, write-up explanations, and the latest hacking techniques. Hosted by Justin Gardner, Joseph Thacker, and Brandyn Murtagh.

Jaksot

  • Episode 192: Building Amazing Proof-of-Concepts with AI 17.09.2026 26min
    Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Privileged Access Managementhttps://www.criticalthinkingpodcast.io/tl-pam====== This Week in Bug Bounty ======LHE at Ekoparty, open to all Ekoparty Attendeeshttps://www.yeswehack.com/fr/page/live-hacking-event-banco-galicia-yeswehack-ekoparty-2026Builders & Breakers | Building Hackbots: Models, Harnesses and Human Expertise with Hamid Kashfihttps://www.youtube.com/watch?v=MYK9-66qe6w====== Resources ======Get Justin’s exclusive masterclass for more informationhttps://www.ctbb.show/discord====== Timestamps ======(00:00:00) Introduction(00:05:33) PoC Creation Goals & Formats(00:15:01) Nuts and Bolts of Python & HTML Files
  • Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens 10.09.2026 37min
    Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!====== This Week in Bug Bounty ======How to use Codex for Bug Bounty research: explore broadly, validate rigorouslyhttps://www.yeswehack.com/learn-bug-bounty/llm-series-codex====== Resources ======Herdrhttps://herdr.dev/====== Timestamps ======(00:00:00) Introduction(00:02:43) Rez0's Sick Caching Bug(00:11:38) Hackbot Scale & Hardware Spend(00:19:16) Stretching your Subscriptions(00:27:53) Herdr.dev & LHE's with Total Bounty Pools
  • Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill? 03.09.2026 33min
    Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, and where to focus tokens.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Privileged Access Managementhttps://www.criticalthinkingpodcast.io/tl-pam====== This Week in Bug Bounty ======Web Fuzzing for Hackershttps://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackersWhen fear no longer holds you back. Interview with Ryan Bonnerhttps://www.intigriti.com/blog/business-insights/interview-with-ryan-bonner-roll4combatusSteve’s Maturity Frameworkhttps://x.com/SteveHernandezM/status/2094398761946493107====== Timestamps ======(00:00:00) Introduction(00:07:10) Focusing your Tokens, Cloud Providers, and Dropping Bounties(00:18:30) Amount vs. Impact(00:25:42) Ideal Work Day and Focus State
  • Episode 189: What Happened to HackerOne with Joel Margolis 27.08.2026 1t 14min
    Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Guest - Joel Magolishttps://x.com/0xteknogeek====== This Week in Bug Bounty ======Kara Sprague’s Statement:“I read Joel’s post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don’t have the full fix yet, but I own it and am also open to working together to find a good solution.” Kara Sprague, CEO, HackerOne Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit pluginhttps://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-codeClaude Kithttps://github.com/yeswehack/claude-kit====== Resources ======What Happened to HackerOne?https://blog.teknogeek.io/posts/what-happened-to-hackerone/Watch our episode with Alex Ricehttps://www.youtube.com/watch?v=Pa4wWv_ONjM====== Timestamps ======(00:00:00) Introduction(00:04:18) The early days: LHE's, Covid, and the rise of AI(00:17:20) HSM Program, HAI, and resource allocation(00:36:41) Sales Incentivisation(00:46:10) AI and Researcher Reports Data(00:54:38) How Can H1 Revive its Old Self(01:02:40) Triage
  • Episode 188: DEFCON 34 Hotel Room Debrief 20.08.2026 41min
    Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!Today’s Guests:https://x.com/7urb01https://x.com/busf4ctor====== This Week in Bug Bounty ======YesWeHack is introducing Credits to combat AI slop reportshttps://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits====== Timestamps ======(00:00:00) Introduction(00:03:45) DEFCON Event Reactions and Takeaways(00:12:56) Bus & Turbo Talk Overviews(00:21:53) Event Bugs
  • Episode 187: Are Live Hacking Events even worth it? 13.08.2026 42min
    Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Sponsor: Adobe - Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!====== This Week in Bug Bounty ======Exploiting web cache poisoning vulnerabilitieshttps://www.intigriti.com/researchers/blog/hacking-tools/exploiting-web-cache-poisoning-vulnerabilities====== Resources ======frontier class vulnerabilities: it gets worse before it (maybe) gets betterhttps://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better/====== Timestamps ======(00:00:00) Introduction(00:05:41) LHE Vs. AI(00:19:27) Hacker Intuition and Gaslighting your Hackbot(00:25:49) Resolving Sol 5.6 compaction error & AI memory usage(00:37:00) Frontier Class Vulnerabilities
  • Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty? 06.08.2026 58min
    Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Network Accesshttps://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Trend of Bug Bounty Programshttps://x.com/iangcarroll/status/2082535987633410540Next chapter: Restructuring GitHub’s bug bounty programhttps://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHubhttps://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854Gauntlet Loophttps://x.com/mattshumer_/status/2081830214384886228KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/====== Timestamps ======(00:00:00) Introduction(00:05:40) Bug Bounty Program Trends & Pricing Changes(00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6(00:29:06) AI Harnessing, prompting, and the Gauntlet Loop(00:36:58) LHE vs Hackbot(00:43:21) KindaRails2Shell & WP2Shell
  • Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026 30.07.2026 1t 23min
    Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Network Accesshttps://www.criticalthinkingpodcast.io/tl-ztnaToday’s Guests: Harley Kimball - https://x.com/infiniteloginsAriel Garcia - https://x.com/Arl_rose====== This Week in Bug Bounty ======Meet YesWeHack at DEFCON 34https://www.yeswehack.com/fr/page/yeswehack-defcon-34====== Resources ======Bug Bounty Village Agenda https://www.bugbountydefcon.com/agenda-2026BBV CTF 2026https://www.bugbountydefcon.com/ctfHacker Hangout with TikTok, HackerOne, and Bug Bounty Villagehttps://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd====== Timestamps ======(00:00:00) Introduction(00:04:39) Podcast ATO & ATM Hacks(00:17:12) Bug Bounty Village Preview(00:31:02) BBV Room Layout and Swag(00:42:36) BBV Agenda(01:10:57) Harley's Hackbot
  • Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson) 23.07.2026 1t 13min
    Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Guest: https://substack.com/@0xmoose====== This Week in Bug Bounty ======How to use Claude Code for Bug Bounty: find fast, validate manuallyhttps://www.yeswehack.com/learn-bug-bounty/llm-series-claude====== Resources ======Signal Over Noise: AI Agents and the Operator Moathttps://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-theFBDL Goes Agentic: AI Agents Can Now Build Your Test Environmentshttps://bugbounty.meta.com/blog/fbdl-goes-agentic/====== Timestamps ======(00:00:00) Introduction(00:11:01) Satisfaction for hackbot finds(00:19:31) Hackbot Mechanics and Tech Debt(00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models(00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing(01:05:45) Hackbot Load Distribution
  • Episode 183: PortSwigger Research Impossible XSS SOLVED 16.07.2026 1t 14min
    Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labsFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Network Accesshttps://www.criticalthinkingpodcast.io/tl-ztna====== This Week in Bug Bounty ======How LLMs are changing Bug Bounty Interview serieshttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglohttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynoraterhttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare====== Resources ======$15k - CSPT to full account takeover, then 2FA bypass via the prototype chainhttps://whoareme.com/blog/cspt-account-takeover-2fa-bypass/Two Bypasses for Chrome’s Sanitizer APIhttps://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/Documenting the impossible: Unexploitable XSS labshttps://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labsGitLost: How We Tricked GitHub’s AI Agent into Leaking Private Reposhttps://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/Chaining Razor SSTI into RCE via Reflection and Runtime Stringshttps://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/====== Timestamps ======(00:00:00) Introduction(00:06:07) AI Features Are Just Tech Features(00:20:02) CSPT to full Account Takeover & Other Chains(00:35:27) Sanitizer API for Chrome and Firefox(00:46:57) Solving PortSwigger's Impossible Lab & GitLost(01:01:19) SSTI into RCE via Reflection
  • Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission 09.07.2026 39min
    Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some GraphQL Hackbot finds, and what AI’s #1 mission should be.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!====== This Week in Bug Bounty ======LeHack 2026 Recaphttps://event.yeswehack.com/events/lehack-2026Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploitshttps://www.yeswehack.com/fr/news/chocopocs-vulnerability-researchers-trojanised-exploitsNavigating the AI Wave: How We're Keeping Security Research Meaningfulhttps://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actions====== Resources ======Caido Skillshttps://github.com/caido/skills/pull/22Hunting For AWS Cognito SecurityMisconfigurationshttps://www.yassineaboukir.com/talks/NahamConEU2022.pdfX MCPhttps://docs.x.com/tools/mcpUS South Summer Sessions: Hack the Heathttps://h1.community/events/details/hackerone-us-south-hackerone-club-presents-us-south-summer-sessions-hack-the-heat/====== Timestamps ======(00:00:00) Introduction(00:08:31) WPM Bug & Wayback to Guest Bearer(00:18:42) GraphQL Hackbot Finds, Fable Updates, & AI's #1 Mission(00:29:45) MCP, US South H1 Event, & AI Sandbox Escapes
  • Episode 181: Bug Bounty Singularity 02.07.2026 52min
    Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Network Accesshttps://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Are bug bounties cooked?https://hakluke.com/are-bug-bounties-cookedWe built a Hackbothttps://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html====== Timestamps ======(00:00:00) Introduction(00:07:22) Manual vs. AI Hacking(00:17:27) Building a Hackbot(00:23:53) Negatives of Hackbots(00:31:34) Logistics and Problems of Singularity (00:46:21) Successes
  • Episode 180: State of Bug Bounty Maturity Posture Report 25.06.2026 1t 12min
    Episode 180: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Steve Hernandez, founder of the Bug Bounty Maturity Framework (BBMF), to walk us through the inaugural State of Bug Bounty Maturity Posture Report. We go through the scores and cover Asset Hygiene, Operational Signal, how to re-engage the relationship between trust and researcher participation.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Guest: https://x.com/SteveHernandezMEmail Steve at [email protected] out this form to enter a Critical Thinkers rafflehttps://forms.ctbb.show/mdaz====== Resources ======State of Bug Bounty Maturity Posturehttps://bugbountymaturity.com/research/state-of-bug-bounty-maturity-posture-2026Take the Bug Bounty Maturity Assessmenthttps://bugbountymaturity.com/assessmentAI Is Compressing the Bug Bounty Maturity Curvehttps://bugbountymaturity.com/research/ai-is-compressing-the-bug-bounty-maturity-curve====== Timestamps ======(00:00:00) Introduction(00:04:09) State of Bug Bounty Maturity Posture(00:22:33) Researcher Interface & Program Trust(00:44:38) Maturity Bands and Scoring (01:08:19) AI Is Compressing the Bug Bounty Maturity Curve
  • Episode 179: Maintaining Motivation in Post-AI Bug Bounty World 18.06.2026 46min
    Episode 179: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how to stay motivated and keep the vibes strong during this trying time for Bug Bounty.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Cloud Accesshttps://www.criticalthinkingpodcast.io/tl-ztca====== Timestamps ======(00:00:00) Introduction(00:04:57) Managing Hacker Motivation(00:10:45) Community, Competition, & Curosity(00:16:54) Using AI with Passion(00:23:10) The LHE Method & Sharing Wins(00:28:01) Video POCs, Scripts, & Talking about Bugs(00:40:49) Watching your health & stopping mid-hack
  • Episode 178: 600k in ~3 months - BruteCat pt 2 11.06.2026 1t 23min
    Episode 178: In this episode of Critical Thinking - Bug Bounty Podcast we’re back with BruteCat to finish up our discussion on hacking Google. This week we hit AI.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Guest: https://x.com/brutecat====== Resources ======Hacking Google with AIhttps://brutecat.com/articles/hacking-google-with-ai/====== Timestamps ======(00:00:00) Introduction(00:03:07) Discovery Docs Refresher & AI at BugSWAT Mexico(00:30:49) Auth & Enumeration of Referer and Origin(00:45:59) Pwning Google Stories(01:09:32) Batch Execute & GraphQL
  • Episode 177: 2x Google RCE with VRP Legend Brutecat 04.06.2026 1t 25min
    Episode 177: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by BruteCat to talk about his journey hacking Google Cloud, Gmail, Youtube, and Google Phone.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Cloud Accesshttps://www.criticalthinkingpodcast.io/tl-ztcaToday’s Guest: https://x.com/brutecat====== Resources ======StubZero: $148,337 RCE in Google Cloud Productionhttps://brutecat.com/articles/google-cloud-rce/Leaking the email of any YouTube user for $10,000https://brutecat.com/articles/leaking-youtube-emails/Disclosing YouTube Creator Emails for a $20k Bountyhttps://brutecat.com/articles/youtube-creator-emails/Leaking the phone number of any Google userhttps://brutecat.com/articles/leaking-google-phones/====== Timestamps ======(00:00:00) Introduction(00:29:14) 2nd RCE in Application Integration(00:39:55) BruteCat's Background & RCE Follow-up Questions(00:48:02) Google VRP and Youtube Bugs(01:10:17) Google Phone Leak(01:18:36) Discovery Docs and Episode 178 Teaser
  • Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam) 28.05.2026 1t 50min
    Episode 176: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by top Adobe hacker Jim Green to deep-dive AEM. We talk through Sling selectors, Permissions, and how to spot AEM Red Flags.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Sponsor: Adobe. Earn more for AI bugs with Adobe’s new AI Tier! https://blog.adobe.com/security/adobe-expands-bug-bounty-program-to-incentivize-ai-security-researchAlso don’t forget to also grab a 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.Expires June 30, 2026. ====== This Week in Bug Bounty ======Scaling Bug Bounty triage in the AI era(https://www.yeswehack.com/security-best-practices/scaling-bug-bounty-triage-ai)The AI impact: a triager’s perspectivehttps://www.intigriti.com/blog/business-insights/the-ai-impact-a-triagers-perspective====== Resources ======Sling Selectors - The Key to Unlocking AEM's Attack Surfacehttps://greenjam.co.uk/blog/sling-selectors/Just a Moment CTFhttps://poc.greenjam.co.uk/just-a-moment.htmlGeneral XSS jquery .text()https://poc.greenjam.co.uk/text-xss.htmlURL XXS Challengehttps://poc.greenjam.co.uk/url-xss.html====== Timestamps ======(00:00:00) Introduction(00:04:35) Background and AEM Bug(00:17:40) Sling Selectors & the Tech Stack(00:38:14) Permissions & Apache Sling Resolution(01:01:37) The Bugs & AEM Red Flags(01:31:55) Moment in Time CTF(01:40:38) General XSS jquery .text()(01:45:45) URL XXS Challenge
  • Episode 175: Rhyno’s Hackbot Setup, Sick Bugs, and ZDI Drama 21.05.2026 49min
    Episode 175: In this episode of Critical Thinking - Bug Bounty Podcast we’re comparing Hackbot setups and results. We also talk about some of the recent ZDI drama, as well as the importance of freaking beautiful POCsFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Cloud Accesshttps://www.criticalthinkingpodcast.io/tl-ztca====== Resources ======Another day, another universal linux LPEhttps://x.com/v12sec/status/2054491454064746629ZDI Dramahttps://x.com/ryotkak/status/2052881664909660521Orange Tsai Bug on Edgehttps://x.com/thezdi/status/2054868495888777266Chompie's Exploit in NV Container Toolkithttps://x.com/chompie1337/status/2054882193055601140GitHub Security April bug bounty statshttps://x.com/GitHubSecurity/status/2054274356403138932====== Timestamps ======(00:00:00) Introduction(00:02:14) q param prompt injection & Mobile CSPT(00:14:17) Admin API Key MegaCrit(00:17:13) Hackbots(00:37:10) Pretty POCs and ZDI Drama(00:44:48) GitHub Security April Stats
  • Episode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.5 14.05.2026 1t 9min
    Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== This Week in Bug Bounty ======COST, AI frontier models and more: A measured take on the future of security testinghttps://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testingCommon AI misconceptions debugged!https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportionBountySync + Socialhttps://luma.com/bountysync_social====== Resources ======Ghosts of Encryption Pasthttps://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/tessl Skill Optimizerhttps://tessl.io/registry/tessl/skill-optimizer/0.8.0The Internet Is Falling Down, Falling Down, Falling Downhttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/High Fidelity Check for the cPanel Authentication Bypasshttps://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/Achieving Deterministic Prompt Injection Through Client-Side Feedback Loopshttps://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/GPT-5.5: Mythos-Like Hacking, Open To Allhttps://xbow.com/blog/mythos-like-hacking-open-to-allRemote Command Execution in Google Cloud with Single Directory Deletionhttps://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&utm_medium=referral====== Timestamps ======(00:00:00) Introduction(00:09:20) AMPScript(00:25:10) Tessl Skill Optimizer(00:33:07) cPanel & WHM Authentication Bypass(00:40:46) Advice for Bug Bounty Programs(00:50:07) Prompt Injection Through Client-Side Feedback Loops(00:54:37) GPT 5.5(01:01:00) Remote Command Execution in Google Cloud
  • Episode 173: Bug Bounty is Dead and AI Killed it. 07.05.2026 1t 1min
    Episode 173: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about the negative effects that AI is having on the Bug Bounty scene as a whole. Is it over, or are we so back?Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Cloud Accesshttps://www.criticalthinkingpodcast.io/tl-ztca====== Resources ======We want your feedback on this!https://forms.ctbb.show/future_of_bug_bountyEvolving the Android & Chrome VRPs for the AI Erahttps://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-eraPaid Submissions?https://x.com/d0rsky/status/2047744193976742120Keep the Robots Out of the Gymhttps://danielmiessler.com/blog/keep-the-robots-out-of-the-gymIs my data used for model training?https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training====== Timestamps ======(00:00:00) Introduction(00:06:28) Network effects of Bug Bounty(00:31:55) Hopium/Copium(00:47:21) The Great Training Data Debate

Suosittu maassa

Tämä podcast esiintyy myös näiden maiden podcast-listoilla.