Back

Explore every episode of the podcast Critical Thinking - Bug Bounty Podcast

Dive into the complete episode list for Critical Thinking - Bug Bounty Podcast. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.

Rows per page:

1–50 of 193

TitlePub. DateDuration
Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?03 Sep 202600:33:50

Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, and where to focus tokens.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Privileged Access Management

https://www.criticalthinkingpodcast.io/tl-pam


====== This Week in Bug Bounty ======


Web Fuzzing for Hackers

https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers


When fear no longer holds you back. Interview with Ryan Bonner

https://www.intigriti.com/blog/business-insights/interview-with-ryan-bonner-roll4combatus


Steve’s Maturity Framework

https://x.com/SteveHernandezM/status/2094398761946493107


====== Timestamps ======

(00:00:00) Introduction

(00:07:10) Focusing your Tokens, Cloud Providers, and Dropping Bounties

(00:18:30) Amount vs. Impact

(00:25:42) Ideal Work Day and Focus State

Episode 189: What Happened to HackerOne with Joel Margolis27 Aug 202601:14:18

Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab: 

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Guest - Joel Magolis

https://x.com/0xteknogeek


====== This Week in Bug Bounty ======


Kara Sprague’s Statement:

“I read Joel’s post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don’t have the full fix yet, but I own it and am also open to working together to find a good solution.” 

Kara Sprague, CEO, HackerOne 


Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit plugin

https://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-code


Claude Kit

https://github.com/yeswehack/claude-kit


====== Resources ======

What Happened to HackerOne?

https://blog.teknogeek.io/posts/what-happened-to-hackerone/


Watch our episode with Alex Rice

https://www.youtube.com/watch?v=Pa4wWv_ONjM


====== Timestamps ======

(00:00:00) Introduction

(00:04:18) The early days: LHE's, Covid, and the rise of AI

(00:17:20) HSM Program, HAI, and resource allocation

(00:36:41) Sales Incentivisation

(00:46:10) AI and Researcher Reports Data

(00:54:38) How Can H1 Revive its Old Self

(01:02:40) Triage

Episode 188: DEFCON 34 Hotel Room Debrief20 Aug 202600:41:47

Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!


Today’s Guests:

https://x.com/7urb01

https://x.com/busf4ctor


====== This Week in Bug Bounty ======


YesWeHack is introducing Credits to combat AI slop reports

https://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits


====== Timestamps ======

(00:00:00) Introduction

(00:03:45) DEFCON Event Reactions and Takeaways

(00:12:56) Bus & Turbo Talk Overviews

(00:21:53) Event Bugs

Episode 187: Are Live Hacking Events even worth it?13 Aug 202600:42:32

Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Sponsor: Adobe - Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!


====== This Week in Bug Bounty ======


Exploiting web cache poisoning vulnerabilities

https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-web-cache-poisoning-vulnerabilities


====== Resources ======

frontier class vulnerabilities: it gets worse before it (maybe) gets better

https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better/


====== Timestamps ======

(00:00:00) Introduction

(00:05:41) LHE Vs. AI

(00:19:27) Hacker Intuition and Gaslighting your Hackbot

(00:25:49) Resolving Sol 5.6 compaction error & AI memory usage

(00:37:00) Frontier Class Vulnerabilities



Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?06 Aug 202600:58:04

Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Zero Trust Network Access

https://www.criticalthinkingpodcast.io/tl-ztna


====== Resources ======

Trend of Bug Bounty Programs

https://x.com/iangcarroll/status/2082535987633410540


Next chapter: Restructuring GitHub’s bug bounty program

https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/


Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub

https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854


Gauntlet Loop

https://x.com/mattshumer_/status/2081830214384886228


KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)

https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066


Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/


====== Timestamps ======

(00:00:00) Introduction

(00:05:40) Bug Bounty Program Trends & Pricing Changes

(00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6

(00:29:06) AI Harnessing, prompting, and the Gauntlet Loop

(00:36:58) LHE vs Hackbot

(00:43:21) KindaRails2Shell & WP2Shell

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 202630 Jul 202601:23:11

Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Zero Trust Network Access

https://www.criticalthinkingpodcast.io/tl-ztna


Today’s Guests: 

Harley Kimball - https://x.com/infinitelogins

Ariel Garcia - https://x.com/Arl_rose


====== This Week in Bug Bounty ======

Meet YesWeHack at DEFCON 34

https://www.yeswehack.com/fr/page/yeswehack-defcon-34


====== Resources ======

Bug Bounty Village Agenda 

https://www.bugbountydefcon.com/agenda-2026


BBV CTF 2026

https://www.bugbountydefcon.com/ctf


Hacker Hangout with TikTok, HackerOne, and Bug Bounty Village

https://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd


====== Timestamps ======

(00:00:00) Introduction

(00:04:39) Podcast ATO & ATM Hacks

(00:17:12) Bug Bounty Village Preview

(00:31:02) BBV Room Layout and Swag

(00:42:36) BBV Agenda

(01:10:57) Harley's Hackbot

Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)23 Jul 202601:13:10

Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Guest: https://substack.com/@0xmoose


====== This Week in Bug Bounty ======

How to use Claude Code for Bug Bounty: find fast, validate manually

https://www.yeswehack.com/learn-bug-bounty/llm-series-claude


====== Resources ======

Signal Over Noise: AI Agents and the Operator Moat

https://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-the


FBDL Goes Agentic: AI Agents Can Now Build Your Test Environments

https://bugbounty.meta.com/blog/fbdl-goes-agentic/


====== Timestamps ======

(00:00:00) Introduction

(00:11:01) Satisfaction for hackbot finds

(00:19:31) Hackbot Mechanics and Tech Debt

(00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models

(00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing

(01:05:45) Hackbot Load Distribution

Episode 183: PortSwigger Research Impossible XSS SOLVED16 Jul 202601:14:43

Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labs


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Zero Trust Network Access

https://www.criticalthinkingpodcast.io/tl-ztna


====== This Week in Bug Bounty ======

How LLMs are changing Bug Bounty Interview series

https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglo

https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynorater


https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare


====== Resources ======

$15k - CSPT to full account takeover, then 2FA bypass via the prototype chain

https://whoareme.com/blog/cspt-account-takeover-2fa-bypass/


Two Bypasses for Chrome’s Sanitizer API

https://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/


Documenting the impossible: Unexploitable XSS labs

https://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labs


GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos

https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/


Chaining Razor SSTI into RCE via Reflection and Runtime Strings

https://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/


====== Timestamps ======

(00:00:00) Introduction

(00:06:07) AI Features Are Just Tech Features

(00:20:02) CSPT to full Account Takeover & Other Chains

(00:35:27) Sanitizer API for Chrome and Firefox

(00:46:57) Solving PortSwigger's Impossible Lab & GitLost

(01:01:19) SSTI into RCE via Reflection

Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission09 Jul 202600:39:05

Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some GraphQL Hackbot finds, and what AI’s #1 mission should be.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


====== This Week in Bug Bounty ======

LeHack 2026 Recap

https://event.yeswehack.com/events/lehack-2026


Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits

https://www.yeswehack.com/fr/news/chocopocs-vulnerability-researchers-trojanised-exploits


Navigating the AI Wave: How We're Keeping Security Research Meaningful

https://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actions


====== Resources ======

Caido Skills

https://github.com/caido/skills/pull/22


Hunting For AWS Cognito Security

Misconfigurations

https://www.yassineaboukir.com/talks/NahamConEU2022.pdf


X MCP

https://docs.x.com/tools/mcp


US South Summer Sessions: Hack the Heat

https://h1.community/events/details/hackerone-us-south-hackerone-club-presents-us-south-summer-sessions-hack-the-heat/


====== Timestamps ======

(00:00:00) Introduction

(00:08:31) WPM Bug & Wayback to Guest Bearer

(00:18:42) GraphQL Hackbot Finds, Fable Updates, & AI's #1 Mission

(00:29:45) MCP, US South H1 Event, & AI Sandbox Escapes

Episode 181: Bug Bounty Singularity02 Jul 202600:52:16

Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Zero Trust Network Access

https://www.criticalthinkingpodcast.io/tl-ztna


====== Resources ======


Are bug bounties cooked?

https://hakluke.com/are-bug-bounties-cooked


We built a Hackbot

https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html


====== Timestamps ======

(00:00:00) Introduction

(00:07:22) Manual vs. AI Hacking

(00:17:27) Building a Hackbot

(00:23:53) Negatives of Hackbots

(00:31:34) Logistics and Problems of Singularity 

(00:46:21) Successes


Episode 180: State of Bug Bounty Maturity Posture Report25 Jun 202601:12:44

Episode 180: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Steve Hernandez, founder of the Bug Bounty Maturity Framework (BBMF), to walk us through the inaugural State of Bug Bounty Maturity Posture Report. We go through the scores and cover Asset Hygiene, Operational Signal, how to re-engage the relationship between trust and researcher participation.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Guest: https://x.com/SteveHernandezM

Email Steve at info@bugbountymaturity.com


Fill out this form to enter a Critical Thinkers raffle

https://forms.ctbb.show/mdaz


====== Resources ======

State of Bug Bounty Maturity Posture

https://bugbountymaturity.com/research/state-of-bug-bounty-maturity-posture-2026


Take the Bug Bounty Maturity Assessment

https://bugbountymaturity.com/assessment


AI Is Compressing the Bug Bounty Maturity Curve

https://bugbountymaturity.com/research/ai-is-compressing-the-bug-bounty-maturity-curve


====== Timestamps ======

(00:00:00) Introduction

(00:04:09) State of Bug Bounty Maturity Posture

(00:22:33) Researcher Interface & Program Trust

(00:44:38) Maturity Bands and Scoring 

(01:08:19) AI Is Compressing the Bug Bounty Maturity Curve



Episode 179: Maintaining Motivation in Post-AI Bug Bounty World18 Jun 202600:46:27

Episode 179: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how to stay motivated and keep the vibes strong during this trying time for Bug Bounty.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Zero Trust Cloud Access

https://www.criticalthinkingpodcast.io/tl-ztca


====== Timestamps ======

(00:00:00) Introduction

(00:04:57) Managing Hacker Motivation

(00:10:45) Community, Competition, & Curosity

(00:16:54) Using AI with Passion

(00:23:10) The LHE Method & Sharing Wins

(00:28:01) Video POCs, Scripts, & Talking about Bugs

(00:40:49) Watching your health & stopping mid-hack

Episode 178: 600k in ~3 months - BruteCat pt 211 Jun 202601:23:56

Episode 178: In this episode of Critical Thinking - Bug Bounty Podcast we’re back with BruteCat to finish up our discussion on hacking Google. This week we hit AI.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Guest: https://x.com/brutecat


====== Resources ======

Hacking Google with AI

https://brutecat.com/articles/hacking-google-with-ai/


====== Timestamps ======

(00:00:00) Introduction

(00:03:07) Discovery Docs Refresher & AI at BugSWAT Mexico

(00:30:49) Auth & Enumeration of Referer and Origin

(00:45:59) Pwning Google Stories

(01:09:32) Batch Execute & GraphQL



Episode 177: 2x Google RCE with VRP Legend Brutecat04 Jun 202601:25:27

Episode 177: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by BruteCat to talk about his journey hacking Google Cloud, Gmail, Youtube, and Google Phone.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Zero Trust Cloud Access

https://www.criticalthinkingpodcast.io/tl-ztca


Today’s Guest: https://x.com/brutecat


====== Resources ======

StubZero: $148,337 RCE in Google Cloud Production

https://brutecat.com/articles/google-cloud-rce/


Leaking the email of any YouTube user for $10,000

https://brutecat.com/articles/leaking-youtube-emails/


Disclosing YouTube Creator Emails for a $20k Bounty

https://brutecat.com/articles/youtube-creator-emails/


Leaking the phone number of any Google user

https://brutecat.com/articles/leaking-google-phones/



====== Timestamps ======

(00:00:00) Introduction

(00:29:14) 2nd RCE in Application Integration

(00:39:55) BruteCat's Background & RCE Follow-up Questions

(00:48:02) Google VRP and Youtube Bugs

(01:10:17) Google Phone Leak

(01:18:36) Discovery Docs and Episode 178 Teaser

Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam)28 May 202601:50:49

Episode 176: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by top Adobe hacker Jim Green to deep-dive AEM. We talk through Sling selectors, Permissions, and how to spot AEM Red Flags.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Sponsor: Adobe. Earn more for AI bugs with Adobe’s new AI Tier! https://blog.adobe.com/security/adobe-expands-bug-bounty-program-to-incentivize-ai-security-research


Also don’t forget to also grab a 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.

Expires June 30, 2026. 


====== This Week in Bug Bounty ======

Scaling Bug Bounty triage in the AI era

(https://www.yeswehack.com/security-best-practices/scaling-bug-bounty-triage-ai)


The AI impact: a triager’s perspective

https://www.intigriti.com/blog/business-insights/the-ai-impact-a-triagers-perspective


====== Resources ======

Sling Selectors - The Key to Unlocking AEM's Attack Surface

https://greenjam.co.uk/blog/sling-selectors/


Just a Moment CTF

https://poc.greenjam.co.uk/just-a-moment.html


General XSS jquery .text()

https://poc.greenjam.co.uk/text-xss.html


URL XXS Challenge

https://poc.greenjam.co.uk/url-xss.html


====== Timestamps ======

(00:00:00) Introduction

(00:04:35) Background and AEM Bug

(00:17:40) Sling Selectors & the Tech Stack

(00:38:14) Permissions & Apache Sling Resolution

(01:01:37) The Bugs & AEM Red Flags

(01:31:55) Moment in Time CTF

(01:40:38) General XSS jquery .text()

(01:45:45) URL XXS Challenge

Episode 175: Rhyno’s Hackbot Setup, Sick Bugs, and ZDI Drama21 May 202600:49:50

Episode 175: In this episode of Critical Thinking - Bug Bounty Podcast we’re comparing Hackbot setups and results. We also talk about some of the recent ZDI drama, as well as the importance of freaking beautiful POCs


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Zero Trust Cloud Access

https://www.criticalthinkingpodcast.io/tl-ztca


====== Resources ======

Another day, another universal linux LPE

https://x.com/v12sec/status/2054491454064746629


ZDI Drama

https://x.com/ryotkak/status/2052881664909660521


Orange Tsai Bug on Edge

https://x.com/thezdi/status/2054868495888777266


Chompie's Exploit in NV Container Toolkit

https://x.com/chompie1337/status/2054882193055601140


GitHub Security April bug bounty stats

https://x.com/GitHubSecurity/status/2054274356403138932


====== Timestamps ======

(00:00:00) Introduction

(00:02:14) q param prompt injection & Mobile CSPT

(00:14:17) Admin API Key MegaCrit

(00:17:13) Hackbots

(00:37:10) Pretty POCs and ZDI Drama

(00:44:48) GitHub Security April Stats

Episode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.514 May 202601:09:57

Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Need a Pentest? We just launched CTBB Pentests!

https://pentest.ctbb.show/


Hack full time? Check out the Full-Time Hunter’s Guild!

https://ctbb.show/fthg


====== This Week in Bug Bounty ======

COST, AI frontier models and more: A measured take on the future of security testing

https://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testing


Common AI misconceptions debugged!

https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportion


BountySync + Social

https://luma.com/bountysync_social


====== Resources ======

Ghosts of Encryption Past

https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/


tessl Skill Optimizer

https://tessl.io/registry/tessl/skill-optimizer/0.8.0


The Internet Is Falling Down, Falling Down, Falling Down

https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/


High Fidelity Check for the cPanel Authentication Bypass

https://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/


Achieving Deterministic Prompt Injection Through Client-Side Feedback Loops

https://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/


GPT-5.5: Mythos-Like Hacking, Open To All

https://xbow.com/blog/mythos-like-hacking-open-to-all


Remote Command Execution in Google Cloud with Single Directory Deletion

https://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&utm_medium=referral


====== Timestamps ======

(00:00:00) Introduction

(00:09:20) AMPScript

(00:25:10) Tessl Skill Optimizer

(00:33:07) cPanel & WHM Authentication Bypass

(00:40:46) Advice for Bug Bounty Programs

(00:50:07) Prompt Injection Through Client-Side Feedback Loops

(00:54:37) GPT 5.5

(01:01:00) Remote Command Execution in Google Cloud

Episode 173: Bug Bounty is Dead and AI Killed it.07 May 202601:01:30

Episode 173: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about the negative effects that AI is having on the Bug Bounty scene as a whole. Is it over, or are we so back?


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Zero Trust Cloud Access

https://www.criticalthinkingpodcast.io/tl-ztca


====== Resources ======

We want your feedback on this!

https://forms.ctbb.show/future_of_bug_bounty


Evolving the Android & Chrome VRPs for the AI Era

https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era


Paid Submissions?

https://x.com/d0rsky/status/2047744193976742120


Keep the Robots Out of the Gym

https://danielmiessler.com/blog/keep-the-robots-out-of-the-gym


Is my data used for model training?

https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training


====== Timestamps ======

(00:00:00) Introduction

(00:06:28) Network effects of Bug Bounty

(00:31:55) Hopium/Copium

(00:47:21) The Great Training Data Debate

Episode 172: Source Code Review Meta Analysis30 Apr 202600:51:01

Episode 172: In this episode of Critical Thinking - Bug Bounty Podcast trying out a new structure of episode: a Meta Analysis of sorts of many Source Code Review techniques. This episode features tips gathered from Shubs, Rafax, and FSI. Justin highlights best approaches, patterns, and common pitfalls.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Sponsor: Adobe - Get 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.

Expires June 30, 2026. 


====== This Week in Bug Bounty ======


Open-source security testing: the Bug Bounty guide to code analysis

https://www.yeswehack.com/learn-bug-bounty/open-source-guide-code-analysis?utm_source=youtube&utm_medium=sponsor-critical-thinking&utm_campaign=open-source-guide-code-analysis


====== Resources ======

Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)

https://slcyber.io/research-center/abusing-windows-net-quirks-and-unicode-normalization-to-exploit-dnn-dotnetnuke/#:~:text=across%20different%20languages.-,A%20MUST%2DKNOW%20BEHAVIOUR%20OF%20PATH.COMBINE,-Another%20key%20implementation


====== Timestamps ======

(00:00:00) Introduction

(00:06:49) Tracing Data Flow, knowing where your playload is landing, and developer mistakes.

(00:17:33) Mapping the software

(00:24:46) Sniffing for blood

(00:31:54) Common Patterns and Pitfalls

Episode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw Protobuf XSS23 Apr 202600:22:44

Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking ages


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Ringfencing

https://www.criticalthinkingpodcast.io/tl-rf


====== Resources ======


The ultimate Bug Bounty guide to OS command injection vulnerabilities

https://www.yeswehack.com/learn-bug-bounty/ultimate-guide-os-command-injection?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-os-command-injection


Critical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validation

https://www.yeswehack.com/news/auth-bypass-wordpress-azure-plugin?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-wordpress-bypass-plugin


Aituglo featured on YWH

https://www.yeswehack.com/community/developer-aituglo-bug-bounty-story


Adobe will be sponsoring Ekoparty in Miami and hosting a live hacking event on May 21st

https://ekoparty.org/ekoparty-miami-2026-super-live-hacking-event/


====== Resources ======


SVG clickjacking

https://lyra.horse/blog/2025/12/svg-clickjacking/ 


====== Timestamps ======

(00:00:00) Introduction

(00:06:35) Protobuff XSS

(00:12:51) Leaking Age & CSPTs

(00:15:59) Capital Letters and Clickjacking



Episode 170: Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways16 Apr 202600:32:50

Episode 170: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph their trip to Korea with some quick takeaways from the LHE. 


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


====== Timestamps ======

(00:00:00) Introduction

(00:01:41) Google LHE Debrief

(00:09:27) Old AI Exfils & AI report writing

(00:18:14) Human Tokens

(00:26:13) Protoscope & Caido Websocket Repeater

Episode 169: Attacking OAuth 2.109 Apr 202600:30:16

Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Ringfencing

https://www.criticalthinkingpodcast.io/tl-rf


====== This Week in Bug Bounty ======


Intigriti is providing free Burp Pro for Hackers!

https://www.intigriti.com/blog/news/intigriti-collaborates-with-portswigger-to-support-ethical-hacking-excellence


====== Resources ======

Django-allauth Account Takeover (ZeroPath Audit)

https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilities


CVE-2025-4144: Cloudflare Workers PKCE Bypass

https://github.com/cloudflare/workers-oauth-provider/security/advisories/GHSA-qgp8-v765-qxx9


CVE-2025-54576: OAuth2-Proxy Auth Bypass

https://zeropath.com/blog/cve-2025-54576-oauth2-proxy-auth-bypass


====== Timestamps ======

(00:00:00) Introduction

(00:02:16) OAuth 2.0 Standards

(00:12:08) Agent to Agent Communication

(00:17:19) CVE Case studies



Episode 168: XSSDoctor - Client-side Path Traversal Research02 Apr 202601:35:55

Episode 168: In this episode of Critical Thinking - Bug Bounty Podcast we’re getting a visit from the XSS Doctor. Jonathan joins us to go through his Client-side workflow, run labs, and diagnose some bugs live.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Guest: https://x.com/xssdoctor


====== Resources ======


The Dot-Dot-Slash That Frameworks Hand You: CSPT Across Every Major Frontend Framework

https://lab.ctbb.show/research/the-dot-dot-slash-that-frameworks-hand-you


URL validation bypass cheat sheet

https://portswigger.net/web-security/ssrf/url-validation-bypass-cheat-sheet


====== Timestamps ======

(00:00:00) Introduction

(00:01:37) Home Automation AI Hack & E-signature bug stories

(00:12:15) E-signature bug

(00:17:01) XSS DR Intro and Bug Bounty Journey

(00:31:51) CSPT Workflows

(01:07:57) Wildcard Path Parameters 

(01:30:34) Custom Sinks

Episode 167: Stealing Bugs with Valeriy Shevchenko26 Mar 202600:51:40

Episode 167: In this episode of Critical Thinking - Bug Bounty Podcast we welcome Valeriy Shevchenko to talk about program management, anchor programs, and Theft in Bug Bounty.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Ringfencing

https://www.criticalthinkingpodcast.io/tl-rf


Today’s Guest: https://x.com/Krevetk0Valeriy


====== This Week in Bug Bounty ======


HackerOne’s Bug Bounty Maturity Framework:

https://www.hackerone.com/blog/program-maturity-framework-bug-bounty-operations


Intigriti is hiring a Product Security Analyst

https://jobs.criticalthinkingpodcast.io/jobs/product-security-analyst-25ef4706


====== Resources ======


Valeriy’s Blog

https://krevetk0.medium.com/


====== Timestamps ======

(00:00:00) Introduction

(00:03:15) Valeriy's Bug story

(00:19:48) Anchor Programs and Bug Hunting Motivation

(00:29:50) Stealing Bugs

Episode 166: Rez0’s Top Claude Skill Secrets 19 Mar 202600:53:02

Episode 166: In this episode of Critical Thinking - Bug Bounty Podcast we talk about Rez0’s Claude Skill Secrets, when AI Generated reports fall apart, and agents vs filters.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Sponsor: Adobe


====== This Week in Bug Bounty ======


Intigriti launched their ambassadors program. https://www.intigriti.com/ambassador


Adobe will be at Hack The Bay

https://www.hackthebay.org/


Bug Bounty Maturity Framework

https://bugbountymaturity.com/


====== Resources ======

h1-brain

https://github.com/PatrikFehrenbach/h1-brain


caido skills

http://github.com/caido/skills


Tweet from Karpathy

https://x.com/karpathy/status/2031767720933634100?s=20


Find every inefficiency in your Claude workflow with one prompt

https://x.com/shannholmberg/status/2030605364421595468


====== Timestamps ======

(00:00:00) Introduction

(00:08:28) Claude skills

(00:30:00) How AI Generated reports fall apart

(00:38:44) Orchestration

(00:49:10) Agents vs Folders

Episode 165: Protobuf Hacking, AI-Powered Bug Hunting, and Self-Improving Claude Workflows12 Mar 202600:44:23

Episode 165: In this episode of Critical Thinking - Bug Bounty Podcast Justin recaps his Zero Trust World experience, before we dive into Permissions issues client-side bugs, New Hardware Hacking Classes, and using AI to hack.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker - Ringfencing

https://www.criticalthinkingpodcast.io/tl-rf


====== Resources ======


bbscope Update

https://x.com/sw33tLie/status/2029344643154919720


Matt Brown's Youtube Channel

https://www.youtube.com/channel/UC3VDCeZYZH7mCihtMVHqppw


Matt's Twitter:

https://x.com/nmatt0


MCP server for HackerOne to search reports

https://x.com/OriginalSicksec/status/2029503063095124461?s=20


Caido Skills

https://github.com/caido/skills


The Agentic Hacking Era: Ramblings and a Tool

https://josephthacker.com/hacking/2026/03/06/the-agentic-hacking-era.html


Announcing AI-driven Caido

https://caido.io/blog/2026-03-06-caido-skill


====== Timestamps ======

(00:00:00) Introduction

(00:06:23) bbscope report dumping & Matt Brown Training

(00:13:10) MCP server for HackerOne to search reports & protobuff success

(00:24:24) Hacking Mics with Permissions issues client-side bugs

(00:27:26) Can AI Hack things?

Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND05 Mar 202601:11:56

Episode 164: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Tommy DeVoss to talk about his origin story, Yahoo bugs, and how Tommy first got Justin into Bug Bounty


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Guest: https://x.com/thedawgyg


====== This Week in Bug Bounty ======


Python pitfalls: Turning developer mistakes into vulnerabilities

https://www.yeswehack.com/learn-bug-bounty/python-pitfalls-turning-developer-mistakes?utm_source=critical-thinking&utm_medium=sponsored&utm_campaign=article-research-python-pitfalls


====== Timestamps ======

(00:00:00) Introduction

(00:06:22) Yahoo SSRF

(00:14:56) Tommy's Origin

(00:44:10) Bug Bounty

(00:51:47) SSRF Attraction, AI implementation, & Browser Hacking

Episode 163: Best Technical Takeaways from Portswigger Top 10 202526 Feb 202601:08:23

Episode 163: In this episode of Critical Thinking - Bug Bounty Podcast It’s that time of year again! We’re looking at the Portswigger Research list of top 10 web hacking techniques of 2025.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!



====== Resources ======


Parser Differentials: When Interpretation Becomes a Vulnerability

https://www.youtube.com/watch?v=Dq_KVLXzxH8


XSS-Leak: Leaking Cross-Origin Redirects

https://blog.babelo.xyz/posts/cross-site-subdomain-leak/


Playing with HTTP/2 CONNECT

https://blog.flomb.net/posts/http2connect/


Next.js, cache, and chains: the stale elixir

https://zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir


SOAPwn: Pwning .NET Framework Apps Through HTTP Client Proxies And WSDL

https://watchtowr.com/wp-content/uploads/SOAPwnwatchtowr_soappwn-research-whitepaper_10-12-2025.pdf


Cross-Site ETag Length Leak

https://blog.arkark.dev/2025/12/26/etag-length-leak


Lost in Translation: Exploiting Unicode Normalization

https://www.youtube.com/watch?v=ETB2w-f3pM4


ORM Leaking More Than You Joined For

https://www.elttam.com/blog/leaking-more-than-you-joined-for/


Novel SSRF Technique Involving HTTP Redirect Loops

https://slcyber.io/research-center/novel-ssrf-technique-involving-http-redirect-loops/


Successful Errors: New Code Injection and SSTI Techniques

https://github.com/vladko312/Research_Successful_Errors




====== Timestamps ======

(00:00:00) Introduction

(00:02:33) Parser Differentials: When Interpretation Becomes a Vulnerability

(00:11:02) XSS-Leak: Leaking Cross-Origin Redirects

(00:18:25) Playing with HTTP/2 CONNECT

(00:22:10) Next.js, cache, and chains: the stale elixir

(00:29:15) SOAPwn: Pwning .NET Framework Apps Through HTTP Client Proxies And WSDL

(00:34:27) Cross-Site ETag Length Leak

(00:41:47) Lost in Translation: Exploiting Unicode Normalization

(00:47:27) ORM Leaking More Than You Joined For

(00:54:07) Novel SSRF Technique Involving HTTP Redirect Loops

(00:58:40) Successful Errors: New Code Injection and SSTI Techniques

Episode 162: HackerOne Training AI on Bug Bounty Data?19 Feb 202600:53:22

Episode 162: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph sit down with HackerOne Founder & CTO Alex Rice to discuss concerns of Using Hacker Data for AI and decreasing bounties.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker – Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26

https://ztw.com/


Today’s Guest: https://x.com/senorarroz


====== This Week in Bug Bounty ======


XML external entity: The ultimate Bug Bounty guide to exploiting XXE vulnerabilities

https://www.yeswehack.com/learn-bug-bounty/xml-external-entity-guide-xxe?utm_source=Critical_Thinking&utm_medium=Youtube&utm_campaign=XXE_Critical_Thinking&utm_id=XXE_CT


Bug Bounty Maturity Framework

https://bugbountymaturity.com/


====== Resources ======

Confidential Information and Confidentiality Obligations

https://www.hackerone.com/terms/general#:~:text=HackerOne%20may%20use%20Confidential%20Information%20to%20develop%20and/or%20improve%20its%20Services%20(for%20example%2C%20to%20identify%20trends%2C%20and%20to%20train%20AI%20models)%20provided%20such%20use%20does%20not%20result%20in%20disclosure%20of%20Confidential%20Information%20to%20unauthorized%20third%20parties


Ownership and Licenses

https://www.hackerone.com/terms/community#:~:text=8.%20Ownership%20and%20Licenses


I argued with an AI regarding HackerOne using Hacker reports to train PtaaS

https://bugbounty.forum/post/183ff0fc-eb9e-47f8-991d-c0aa5b0bba71


HackerOne PTaaS (likely training their AI on private reports data)

https://www.reddit.com/r/bugbounty/comments/1r5hixk/hackerone_ptaas_likely_training_their_ai_on/


What Makes Agentic PTaaS Different in Real Environments

https://www.hackerone.com/blog/agentic-penetration-testing-as-a-service#:~:text=Our%20agents%20are,real%20enterprise%20constraints


====== Timestamps ======

(00:00:00) Introduction

(00:08:44) HackerOne AI Terms of Service 

(00:24:56) Agentic PTaaS

(00:38:09) Selling data

(00:43:49) Decrease in Bounties

Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil12 Feb 202600:24:42

Episode 161: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gives us some quick hits regarding CSRF and Cross Consumer Attacks, and also touches on some breaking questions surrounding HackerOne


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker – Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26

https://ztw.com/


====== This Week in Bug Bounty ======


AS Watson

https://app.intigriti.com/programs/aswatson/watsons/detail


YesWeHack 2026 Report

https://choose.yeswehack.com/bug-bounty-report-2026-trends-and-key-insights-yeswehack?utm_source=youtube&utm_medium=sponsor-critical-thinking&utm_campaign=yeswehack-report-2026 


====== Resources ======


PhoneLeak: Data Exfiltration in Gemini via Phone Call

https://blog.starstrike.ai/posts/phoneleak-data-exfiltration-in-gemini-via-phone-call/


Max's Tweet about decreasing bounties

https://x.com/0xw2w/status/2020788164378427483


HackerOne General Terms and Conditions

https://www.hackerone.com/terms/general


Research Review #-2: RCE in Google's AI code editor Antigravity (sudi)

https://www.youtube.com/watch?v=JqvJSF2UMyY


====== Timestamps ======

(00:00:00) Introduction

(00:03:26) YesWeHack 2026 Report

(00:09:12) CSRF Realizations & Data Exfiltration in Gemini via Phone Call

(00:14:38) 7urb0's Youtube, HackerOne decreasing bounties and Section    3.1 controversy.

(00:19:06) Cross Consumer Attacks



Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS05 Feb 202600:45:04

Episode 160: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn. Chat through some news, Including a Cloudflare Zero-day, Turning List-Unsubscribe into an SSRF/XSS Gadget, & Magic String Denial of Service in Claude.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!


====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Today’s Sponsor: Adobe.

Use code CTBB040126, and get a 10% bonus on your bounty for any AI vulnerability which is mapped to the OWASP LLM top 10.

Valid on Adobe Acrobat Web - AI Assistant / PDF Spaces / Content Creation and presentation features using Express

Adobe Express AI Assistant. 

Valid through April 1st, 2026


Also we have a Google Cloud VRP Swag Bonus! Mention the podcast in any rewarded (cash or credit) VRP report submission before the end of April to receive bonus swag!


====== Resources ======

Cloudflare Zero-day

https://fearsoff.org/research/cloudflare-acme


Turning List-Unsubscribe into an SSRF/XSS Gadget

https://security.lauritz-holtmann.de/post/xss-ssrf-list-unsubscribe/


Breaking Multi-Tenant Isolation in Heroku Postgres

https://allistair.sh/blog/breaking-heroku-postgres/


Parse and Parse: MIME Validation Bypass to XSS via Parser Differential

https://lab.ctbb.show/research/parse-and-parse-mime-validation-bypass-to-xss-via-parser-differential


Claude Magic String Denial of Service

https://x.com/Frichette_n/status/2013988503336415522


From WebView to Remote Code Injection

https://djini.ai/from-webview-to-remote-code-injection/


DOM XSS Is Not Dead: The Rise of Polyglot Payloads

https://blogs.jsmon.sh/dom-xss-is-not-dead-the-rise-of-polyglot-payloads/


====== Timestamps ======

(00:00:00) Introduction

(00:06:17) Cloudflare Zero-day & Turning List-Unsubscribe into an SSRF/XSS Gadget

(00:16:57) Breaking Multi-Tenant Isolation in Heroku Postgres & CTBB Research

(00:25:46) Claude Magic String Denial of Service & From WebView to Remote Code Injection

Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins29 Jan 202601:46:50

Episode 159: In this episode of Critical Thinking - Bug Bounty Podcast we sit down with the Google Cloud VRP Team to deep-dive policy and reward changes, what the panel process looks like, and how to best configure for success.


Follow us on X


Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io


Shoutout to YTCracker for the awesome intro music!


====== Links ======


Follow your hosts Rhynorater, rez0 and gr3pme on X:


====== Ways to Support CTBBPodcast ======


Hop on the CTBB Discord


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


Get some hacker swag


Sponsored by ThreatLocker – Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26

https://ztw.com/


Google Cloud VRP Swag Bonus! Mention the podcast in any rewarded (cash or credit) VRP report submission before the end of April to receive bonus swag!


Today’s Guests:

Darby Hopkins

Michael Cote


====== This Week in Bug Bounty ======

AI Red Teaming Explained by AI Red Teamers


Good Faith AI Research Safe Harbor


Join the Adobe LHE at NULLCON GOA


====== Resources ======


‘Legendary Guy’ - Jakub Domeracki


Google Cloud VRP rewards rules


Google Cloud VRP product tiers


Bug Hunters blog on the 2025 Google Cloud VRP bugSWAT


Google VRP Discord


Google VRP on X


====== Timestamps ======


(00:00:00) Introduction

(00:10:03) CloudVRP Bugswat Event Breakdown

(00:16:40) VRP Policy & Rewards Changes

(00:04:50) Panel Process

(01:00:08) Configuring for Success & Avoiding Downgrades

(01:33:47) Scenarios for Success

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs22 Jan 202600:58:30

Episode 158: In this episode of Critical Thinking - Bug Bounty Podcast we talk about our personal takeaways from the CTBB Charity Hackalong, and then break down some InsertScript POCs, what a $55,000 bug can look like, and if Smart People Ever Say They’re Smart.


Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!



====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X: 

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme


Critical Research Lab:

https://lab.ctbb.show/ 


====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!


We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


You can also find some hacker swag at https://ctbb.show/merch!


Sponsored by ThreatLocker – Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26

https://ztw.com/


====== Resources ======

InsertScript - XSS Challenge Solution

https://insert-script.blogspot.com/2020/03/xss-challenge-solution-refresh-header.html


InsertScript - Redirect AuthHeader

https://www.insert-script.com/examples/redirectAuthHeader/send.html


CRLF injection on a 302 redirect

https://x.com/0xdef1ant/status/2009040359482118500


Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover

https://ysamm.com/uncategorized/2025/01/13/capig-xss.html


Arcanum Hack Tips

https://github.com/Arcanum-Sec/hack_tips


Trail of Bits Releases Claude Skills

https://x.com/dguido/status/2011541318229533063


what a $55,000 bug can look like

https://x.com/the_IDORminator/status/2007480636244697237


Pwning Claude Code in 8 Different Ways

https://flatt.tech/research/posts/pwning-claude-code-in-8-different-ways/


Do Smart People Ever Say They’re Smart?

https://labs.watchtowr.com/do-smart-people-ever-say-theyre-smart-smartertools-smartermail-pre-auth-rce-cve-2025-52691/



====== Timestamps ======

(00:00:00) Introduction

(00:04:18) Technical takeaways from CT Charity Hackalong

(00:22:21) InsertScript POCs & Rez0 and teknogeek's IOT Adventures

(00:32:16) CRLF injection on a 302 redirect & Multiple XSS in Meta

(00:41:00) Trail of Bits, what a $55,000 bug can look like, & Pwning Claude Code

(00:54:16) Do Smart People Ever Say They’re Smart?



Episode 157: Crushing Pwn2Own & H1 with Kernel Driver Exploits15 Jan 202601:34:58

Episode 157: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Hypr to talk about hacking Mediatek and his experiences with HackerOne and Pwn2Own Ecosystems.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

Critical Research Lab:

https://lab.ctbb.show/

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today’s Guest: https://x.com/hyprdude

====== This Week in Bug Bounty ======

Top 10 web hacking techniques of 2025: call for nominations

https://portswigger.net/research/top-10-web-hacking-techniques-of-2025-nominations-open

CVE-2025-13467

https://access.redhat.com/security/cve/cve-2025-13467

====== Resources ======

Hypr's Blog

https://blog.coffinsec.com

mediatek? more like media-rekt, amirite.

https://blog.coffinsec.com/0days/2025/12/15/more-like-mediarekt-amirite.html

kernel-utils

https://github.com/mellow-hype/kernel-utils

====== Timestamps ======

(00:00:00) Introduction

(00:03:23) Heap Overflow in Mediatek Kernel Drivers

(00:19:23) Kernel Debugging & ioctl Handlers

(00:43:30) Input Structs, Sync to Source, & Privilege Escalation

(00:51:30) HackerOne Ecosystem vs Pwn2Own Ecosystem

(01:17:00) Kernel Utils

(01:26:46) Real World Bugs for Exploit Development vs CTFs

Episode 156: Chill AMA from bugbounty.forum08 Jan 202601:23:07

Episode 156: In this episode of Critical Thinking - Bug Bounty Podcast we answer some fantastic questions from over at bugbounty.forum

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

====== Resources ======

Critical Thinking Lab

lab.ctbb.show

Cross-Site ETag Length Leak

https://blog.arkark.dev/2025/12/26/etag-length-leak

Clawdbot

https://github.com/clawdbot/clawdbot/

Post from Steve Caldwell

https://x.com/moreconfetti/status/2006494133159162008

====== Timestamps ======

(00:00:00) Introduction

(00:00:58) Crit Lab update

(00:04:36) Cross-Site ETag Length Leak

(00:13:26) Clawdbot

(00:16:56) Will bug hunting become obsolete, LHE invitations, and Fulltime vs Part time?

(00:30:52) 10 bugs at $5k or 1 bug at $5k, CTBB Background, & Future Plans

(00:38:32) Mentoring, Conquering Classes, and what angles we implement from the podcast

(00:49:27) Best approach on new targets, tips for making 500k in a year, AI/Vibecoding & Human in the Loop

(00:59:07) Mentally mapping the target, anti-patterns that waste time, and BB beliefs that were wrong.

(01:10:12) Tackling small scope, staying on one program, picking up after a break, & moving on

(01:17:41) Invisible elements that make the difference between $2k and $20k

Episode 155: 2025 Hacker Stats & 2026 Goals01 Jan 202601:32:16

Episode 155: In this episode of Critical Thinking - Bug Bounty Podcast Justin, Joseph, and Brandyn reflect on last year of Bug Bounty, and list their goals and predictions for what 2026 holds.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

====== Resources ======

2024 Hacker Stats & 2025 Goals

https://blog.criticalthinkingpodcast.io/p/hackernotes-ep-104-2024-hacker-stats-2025-goals

====== Timestamps ======

(00:00:00) Introduction

(00:02:08) 2025 Full Time Hunting Retrospective

(00:10:19) Most Fulfilling Moments and Bugs

(00:17:56) Satisfaction with 2025 Stats

(00:45:28) Automation, Organization, and Collaboration

(00:48:55) Time and Motivation

(01:08:01) Goals and Predictions for Bug Bounty in 2026

Episode 154: Starting a Pentesting Company on Top of Bug Bounty25 Dec 202500:41:28

Episode 154: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn talk through the transition from Bug Bounty hunting to Pentesting. We cover diversifying income streams, the challenges of pricing for Pentests, legal considerations, and what Bug Hunters can bring to the Pentesting world

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

====== Timestamps ======

(00:00:00) Introduction

(00:03:36) Starting a Pentesting Company

(00:12:25) Advantages of Pentesting as a Bug Bounty Hunter

(00:29:03) Pricing, Sales, and knowing your Market/Worth

(00:36:21) Compliance in Pentests & Rapid-Fire Takaways

Episode 153: Hacking the Robots of the Future: Hardware, AI, and Bug Bounties with Matt Brown18 Dec 202501:16:50

Episode 153: In this episode of Critical Thinking - Bug Bounty Podcast Matt Brown returns to talk with us about hacking robots, IOT hackbots, and his Zero-to-Hero Hardware Hacking Guide.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today’s Guest: Matt Brown

====== Resources ======

KeeYees USB Logic Analyzer Device

Saleae logic analyzer

XGecu

Hardware Hacking Tutorial by Make Me Hack

UART and SPI firmware extraction

UART Root Shell on Linux Router

UART Shell Jail and Unlocked Bootloader

Chinese IP Camera Firmware Extraction

Chip-Off Firmware Extraction

====== Timestamps ======

(00:00:00) Introduction

(00:01:22) Incremental Session Token Story and Matt Brown Intro

(00:10:42) Hardware Bug Bounty Scene & AI on Devices

(00:24:30) Hacking Human Robot

(00:41:33) Zero-to-Hero Hardware Hacking Guide

(01:01:47) IOT Hackbot

Episode 152: GeminiJack and Agentic Security with Sasi Levi11 Dec 202501:21:36

Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prompt Injection is a real Vuln.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

CHeck out our New Christmas Swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

https://ctbb.show/tl-ec

And Noma Security! https://noma.security/

Today’s Guest: https://x.com/sasi2103

====== This Week in Bug Bounty ======

Vercel Platform Protection

Dedicated HackerOne program for Vercel WAF

YesWeHack Open Source Programs

Android recon for Bug Bounty hunters

====== Resources ======

Sasi's Tweet from 2015

ForcedLeak: AI Agent risks exposed in Salesforce AgentForce

Is Prompt Injection a Vulnerability?

====== Timestamps ======

(00:00:00) Introduction

(00:09:16) Google Vertex AI Bug

(00:29:28) Sasi's Background and Bug Bounty Journey

(00:38:55) Resources for AI and Agentic Security Methodology

(00:50:34) ForcedLeak

(01:02:06) Is Prompt Injection a Vuln?

Episode 151: Client-side Advanced Topics04 Dec 202501:07:26

Episode 151: In this episode of Critical Thinking - Bug Bounty Podcast we’re covering Client-side advanced topics. Justin talks Joseph (and us) through Third-Party Cookie Nuances, Iframe Tricks, URL Parsing, and more.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

https://ctbb.show/tl-ec

====== Resources ======

Nowasky's Tweet #1

https://x.com/nowaskyjr/status/1993421017381744974

Nowasky's Tweet #2

https://x.com/nowaskyjr/status/1992717862398800081

rep+ in Chrome DevTools

https://x.com/BourAbdelhadi/status/1992622964077179229

Terjanq Post from 2021

https://x.com/terjanq/status/1421093136022048775

====== Timestamps ======

(00:00:00) Introduction

(00:02:58) Client-side news & AI Updates

(00:12:02) Third-Party Cookie Nuances & PostMessages

(00:30:09) Iframe Tricks

(00:47:43) URL Parsing, CSPTS, and Client-side Routes

Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration27 Nov 202500:57:20

Episode 150: In this episode of Critical Thinking - Bug Bounty Podcast we're highlighting some cool news and research, but not before expressing our gratitude to the Hacker community. We are so thankful for you all!

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

https://ctbb.show/tl-ec

====== This Week in Bug Bounty ======

Cache Overflow on Cloudflare

====== Resources ======

Breaking Oracle’s Identity Manager

Who Needs a Blind XSS?

ASP.NET MVC View Engine Search Patterns

Heretic

Lesser known techniques for large-scale subdomain enum

Antigravity – Known Issues

Bug Bounty Daily

Caido version of AssetNote Surf

====== Timestamps ======

(00:00:00) Introduction

(00:09:47) Breaking Oracle’s Identity Manager & Who Needs a Blind XSS?

(00:20:37) ASP.NET MVC View Engine Search Patterns & Heretic

(00:29:04) Lesser known techniques for large-scale subdomain enum

(00:35:29) Gemini 3 & Antigravity.

(00:45:57) Bug Bounty Daily

(00:52:42) Surf for Caido

Episode 149: DEFCON Debrief: AI Vulns, Unicode Weirdness, and Wild Vulnerability Chains20 Nov 202501:02:33

Episode 149: In this episode of Critical Thinking - Bug Bounty Podcast The DEFCON videos are up, and Justin and Joseph talk through some of their favorites.

Follow us on X

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

====== Resources ======

Unicode surrogates conversion

Prompt. Scan. Exploit

Breaking into thousands of cloud based VPNs with 1 bug

Examining Access Control Vulnerabilities in GraphQL

Smart Bus Smart Hacking

Passkeys Pwned

Bypassing Intent Destination Checks

Gemini Agents in Google Calendar

Exploitation of DOM Clobbering Vuln at Scale

TheHulk

Smart Devices, Dumb Resets

Mac PRT Cookie Theft

====== Timestamps ======

(00:00:00) Introduction

(00:10:10) Prompt. Scan. Exploit

(00:23:52) Breaking into thousands of cloud based VPNs with 1 bug

(00:33:25) Access Control Vulns in GraphQL, Smart Bus Hacking, & Passkeys Pwned

(00:44:10) Bypassing Intent Destination Checks & Invoking Gemini Agents

(00:57:08) DOM Clobbering, Mac PRT Cookie Theft, & Smart Devices, Dumb Resets

Episode 148: MCP Hacking Guide13 Nov 202500:32:26

Episode 148: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us a crash course on Model Context Protocol.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

====== Timestamps ======

(00:00:00) Introduction

(00:02:51) MCP Architecture & Authentication

(00:13:08) Roots, Sampling, & Elicitation

(00:19:15) Tools and Resources

Episode 147: Stupid Simple Hacking Workflow Tips06 Nov 202500:58:48

Episode 147: In this episode of Critical Thinking - Bug Bounty Podcast we're talking tips and tricks that help us in hacking that we really should’ve learned sooner.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker Network Control

https://www.criticalthinkingpodcast.io/tl-nc

====== This Week in Bug Bounty ======

Netscaler's new program

https://hackerone.com/netscaler_public_program?type=team

The ultimate Bug Bounty guide to HTTP request smuggling vulnerabilities

https://www.yeswehack.com/learn-bug-bounty/http-request-smuggling-guide-vulnerabilities

Hackers now have 2 Request-a-Response

https://docs.bugcrowd.com/changelog/researchers/request-a-response-researcher/

Evan Connelly Spotlight

https://www.bugcrowd.com/blog/hacker-spotlight-evan-connelly/

Epic Games Jobs Openings

Jobs.ctbb.show

====== Timestamps ======

(00:00:00) Introduction

(00:09:23) Command Palette, Auto-decoding, & Evenbetter

(00:17:28) Chrome Devtools Edit as html & Raycast

(00:33:23) ffuf -request flag

(00:41:33) JXScout

(00:48:55) Conditional Breakpoints in Devtools & Lightning round tips

Episode 146: Hacking Horror Stories30 Oct 202501:50:38

Episode 146: In this episode of Critical Thinking - Bug Bounty Podcast Justin, Joseph, and Brandyn all sit down to celebrate the spooky season by swapping their scariest bug stories. From frightening fails and firings to hacks with chilling and critical consequences. Grab your flashlight and a blanket for this one!

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, rez0 and gr3pme on X:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker Network Control

https://www.criticalthinkingpodcast.io/tl-nc

====== This Week in Bug Bounty ======

Methodology tips from top Bug Bounty hunters

YesWeHack marks first year of partnership with Singapore’s Government

HackerOne Hacker-Powered Security Report

====== Resources ======

Critical Research Lab

Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office

File Creation via SQLite Injection

====== Timestamps ======

(00:00:00) Introduction

(00:10:11) Crit Research Lab News

(00:21:31) Hacking the World Poker Tour & File Creation via SQLite Injection

(00:30:40) Brandyn's Spooky Bug

(00:38:02) Joseph's Spooky Bug

(00:44:18) Justin's Spooky Bug

(00:54:44) Banking Bugs, LHE Scares, and Workday weirdness.

(01:14:52) Firings and failures

(01:22:49) Bank Bug Redux

(01:35:55) Wedding planning/registry app & Amazon Rufus bugs

(01:40:52) New Relic bug

Episode 145: Gr3pme's Secret: Bug Bounty Note Taking Methodology23 Oct 202500:28:17

Episode 145: In this episode of Critical Thinking - Bug Bounty Podcast Brandyn lets us in on some of his notetaking tips, including his Templates, Threat Modeling, and ways he uses notes to help with collaboration.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater, Rez0, & gr3pme on Twitter:

https://x.com/Rhynorater

https://x.com/rez0__

https://x.com/gr3pme

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker Network Control

https://www.criticalthinkingpodcast.io/tl-nc

====== This Week in Bug Bounty ======

The minefield between syntaxes

https://www.yeswehack.com/learn-bug-bounty/syntax-confusion-ambiguous-parsing-exploits

====== Resources ======

Brandyn's Notion Template

https://terrific-dart-70e.notion.site/Example-Target-CTBB-294f4ca0f42481cca0b0ca6ac0a7c81d

====== Timestamps ======

(00:00:00) Introduction

(00:07:25) Templates, Target, and Tech Stack

(00:13:33) Threat Modeling and Attack Vectors

Episode 144: Google’s Top AI Hackers: Busfactor and Monke16 Oct 202500:52:40

Episode 144: In this episode of Critical Thinking - Bug Bounty Podcast Joseph is joined by Vitor Falcão and Ciarán Cotter to discuss their success at the recent Mexico LHE, as well as their journey and routines in fulltime hacking.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater and Rez0 on Twitter:

https://x.com/Rhynorater

https://x.com/rez0__

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker DAC

https://www.criticalthinkingpodcast.io/tl-dac

Today’s Guests:

Vitor Falcão

https://x.com/busf4ctor

Ciarán Cotter

https://x.com/monkehack

====== This Week in Bug Bounty======

Securing the Age of AI Autonomy: Priorities for 2026

https://www.hackerone.com/events/bionic-hacking

====== Resources ======

AI Vulnerability Reward Program Rules

https://bughunters.google.com/about/rules/google-friends/5222232590712832/ai-vulnerability-reward-program-rules

My First 3 Months as a Full-Time Bug Bounty Hunter

https://vitorfalcao.com/posts/3-months-as-a-full-time-bug-bounty-hunter/

====== Timestamps ======

(00:00:00) Introduction

(00:02:32) Client side Bug Story & Vitor's BB journey

(00:13:59) Google LHE Mexico takeaways

(00:26:55) Full-time hunting reflections

(00:33:39) Hacking routines

(00:42:56) Hacking AI

Episode 143: New Cohost + Client-Side Gadgets, LHE Meta — Instant Global Admin in Entra!09 Oct 202501:04:23

Episode 143: In this episode of Critical Thinking - Bug Bounty Podcast Justin brings Brandyn back to announce him as our newest co-host. We chat about recent LHE experiences, and then break down some news.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater and Rez0 on Twitter:

https://x.com/Rhynorater

https://x.com/rez0__

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

====== This Week in Bug Bounty ======

YesWeHack won the European commission: https://www.yeswehack.com/news/european-commission-tender-won-yeswehack

YesWeHack now have authorised cve numbering authority: https://www.yeswehack.com/news/yeswehack-authorised-cve-numbering-authority

A wide range of highly used open source bug bounty program such as Log4J, Systemd, GNOME and a lot more:

https://event.yeswehack.com/events/open-the-code-source-the-bounty

====== Resources ======

Attributes reference inside HTML

Explaining XSS without parentheses and semi-colons

Beyond Sandbox Domains: Rendering Untrusted Web Content with SafeContentFrame

One Token to rule them all

flareprox

Caido 101: How to master it

====== Timestamps ======

(00:00:00) Introduction

(00:03:16) LHE approaches and accomplishments

(00:30:54) Attributes reference inside HTML & Explaining XSS without parentheses and semi-colons

(00:44:33) One Token to rule them all

(00:57:13) Flareprox & Caido 101

Episode 142: Gr3pme's Full-Time Hunting Journey Update, Insane AI research, And Some Light News02 Oct 202500:54:50

Episode 142: In this episode of Critical Thinking - Bug Bounty Podcast Rez0 and Gr3pme join forces to discuss Websocket research, Meta’s $111750 Bug, PROMISQROUTE, and the opportunities afforded by going full time in Bug Bounty.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater and Rez0 on Twitter:

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker DAC

Today’s Guest: https://x.com/gr3pme

====== This Week in Bug Bounty ======

New Monthly Dojo challenge and Dojo UI design

The ultimate Bug Bounty guide to exploiting race condition vulnerabilities in web applications

Watch Our boy Brandyn on the TV

====== Resources ======

murtasec

WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine

Remote code execution though vulnerability in Facebook Messenger for Windows

Finding vulnerabilities in modern web apps using Claude Code and OpenAI Codex

Mind the Gap

PROMISQROUTE

====== Timestamps ======

(00:00:00) Introduction

(00:05:16) Full Time Bug Bounty and Business Startups

(00:15:50) Websockets

(00:22:17) Meta’s $111750 Bug

(00:28:38) Finding vulns using Claude Code and OpenAI Codex

(00:39:32) Time-of-Check to Time-of-Use Vulns in LLM-Enabled Agents

(00:45:22) PROMISQROUTE

Episode 141: Hacking the Pod - Google Docs 0-day & React CreateElement Exploits with Nick Copi (7urb0)25 Sep 202501:23:31

Episode 141: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Nick Copi to talk about CSPT, React, CSS Injections and how Nick hacked the pod.

Follow us on twitter at: https://x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

====== Links ======

Follow your hosts Rhynorater and Rez0 on Twitter:

https://x.com/Rhynorater

https://x.com/rez0__

====== Ways to Support CTBBPodcast ======

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

You can also find some hacker swag at https://ctbb.show/merch!

Today's Sponsor: ThreatLocker. Check out ThreatLocker DAC

https://www.criticalthinkingpodcast.io/tl-dac

Today’s Guest: https://x.com/7urb01

====== Resources ======

regexploit

https://github.com/doyensec/regexploit

Fontleak

https://adragos.ro/fontleak/

debug(function)

https://developer.chrome.com/docs/devtools/console/utilities#debug-function

domloggerpp

https://github.com/kevin-mizu/domloggerpp

====== Timestamps ======

(00:00:00) Introduction

(00:02:40) Google Docs Bug and 7urb0 Introduction

(00:13:26) Bring-a-bug story

(00:20:21) 7urb0's DEFCON talk teaser & Intrusive Thoughts Worth Sharing

(00:30:01) CSPTs and React Apps

(00:51:31) CSS Injections

(01:04:55) 7urb0's backstory and game hacking

(01:18:33) Worst Crit

© My Podcast Data · Independent project · Data from Apple & Spotify