Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

  1. 6h ago

    Episode 187: Are Live Hacking Events even worth it?

    Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today’s Sponsor: Adobe - Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership! ====== This Week in Bug Bounty ====== Exploiting web cache poisoning vulnerabilities https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-web-cache-poisoning-vulnerabilities ====== Resources ====== frontier class vulnerabilities: it gets worse before it (maybe) gets better https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better/ ====== Timestamps ====== (00:00:00) Introduction (00:05:41) LHE Vs. AI (00:19:27) Hacker Intuition and Gaslighting your Hackbot (00:25:49) Resolving Sol 5.6 compaction error & AI memory usage (00:37:00) Frontier Class Vulnerabilities

  2. Aug 6

    Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

    Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today's Sponsor: Check out Zero Trust Network Access: https://www.criticalthinkingpodcast.io/tl-ztna ====== Resources ====== Trend of Bug Bounty Programs https://x.com/iangcarroll/status/2082535987633410540 Next chapter: Restructuring GitHub’s bug bounty program https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/ Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 Gauntlet Loop https://x.com/mattshumer_/status/2081830214384886228 KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066 Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/ ====== Timestamps ====== (00:00:00) Introduction (00:05:40) Bug Bounty Program Trends & Pricing Changes (00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6 (00:29:06) AI Harnessing, prompting, and the Gauntlet Loop (00:36:58) LHE vs Hackbot (00:43:21) KindaRails2Shell & WP2Shell

  3. Jul 30

    Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

    Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village! Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today's Sponsor: Check out Zero Trust Network Access: https://www.criticalthinkingpodcast.io/tl-ztna Today’s Guests:  Harley Kimball - https://x.com/infinitelogins Ariel Garcia - https://x.com/Arl_rose ====== This Week in Bug Bounty ====== Meet YesWeHack at DEFCON 34 https://www.yeswehack.com/fr/page/yeswehack-defcon-34 ====== Resources ====== Bug Bounty Village Agenda  https://www.bugbountydefcon.com/agenda-2026 BBV CTF 2026 https://www.bugbountydefcon.com/ctf Hacker Hangout with TikTok, HackerOne, and Bug Bounty Village https://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd ====== Timestamps ====== (00:00:00) Introduction (00:04:39) Podcast ATO & ATM Hacks (00:17:12) Bug Bounty Village Preview (00:31:02) BBV Room Layout and Swag (00:42:36) BBV Agenda (01:10:57) Harley's Hackbot

  4. Jul 23

    Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)

    Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today’s Guest: https://substack.com/@0xmoose ====== This Week in Bug Bounty ====== How to use Claude Code for Bug Bounty: find fast, validate manually https://www.yeswehack.com/learn-bug-bounty/llm-series-claude ====== Resources ====== Signal Over Noise: AI Agents and the Operator Moat https://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-the FBDL Goes Agentic: AI Agents Can Now Build Your Test Environments https://bugbounty.meta.com/blog/fbdl-goes-agentic/ ====== Timestamps ====== (00:00:00) Introduction (00:11:01) Satisfaction for hackbot finds (00:19:31) Hackbot Mechanics and Tech Debt (00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models (00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing (01:05:45) Hackbot Load Distribution

  5. Jul 16

    Episode 183: PortSwigger Research Impossible XSS SOLVED

    Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labs Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today's Sponsor: Check out Zero Trust Network Access: https://www.criticalthinkingpodcast.io/tl-ztna ====== This Week in Bug Bounty ====== How LLMs are changing Bug Bounty Interview series https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglo https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynorater https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare ====== Resources ====== $15k - CSPT to full account takeover, then 2FA bypass via the prototype chain https://whoareme.com/blog/cspt-account-takeover-2fa-bypass/ Two Bypasses for Chrome’s Sanitizer API https://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/ Documenting the impossible: Unexploitable XSS labs https://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labs GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/ Chaining Razor SSTI into RCE via Reflection and Runtime Strings https://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/ ====== Timestamps ====== (00:00:00) Introduction (00:06:07) AI Features Are Just Tech Features (00:20:02) CSPT to full Account Takeover & Other Chains (00:35:27) Sanitizer API for Chrome and Firefox (00:46:57) Solving PortSwigger's Impossible Lab & GitLost (01:01:19) SSTI into RCE via Reflection

  6. Jul 9

    Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission

    Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some GraphQL Hackbot finds, and what AI’s #1 mission should be. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! ====== This Week in Bug Bounty ====== LeHack 2026 Recap https://event.yeswehack.com/events/lehack-2026 Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits https://www.yeswehack.com/fr/news/chocopocs-vulnerability-researchers-trojanised-exploits Navigating the AI Wave: How We're Keeping Security Research Meaningful https://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actions ====== Resources ====== Caido Skills https://github.com/caido/skills/pull/22 Hunting For AWS Cognito Security Misconfigurations https://www.yassineaboukir.com/talks/NahamConEU2022.pdf X MCP https://docs.x.com/tools/mcp US South Summer Sessions: Hack the Heat https://h1.community/events/details/hackerone-us-south-hackerone-club-presents-us-south-summer-sessions-hack-the-heat/ ====== Timestamps ====== (00:00:00) Introduction (00:08:31) WPM Bug & Wayback to Guest Bearer (00:18:42) GraphQL Hackbot Finds, Fable Updates, & AI's #1 Mission (00:29:45) MCP, US South H1 Event, & AI Sandbox Escapes

  7. Jul 2

    Episode 181: Bug Bounty Singularity

    Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today's Sponsor: Check out Zero Trust Network Access: https://www.criticalthinkingpodcast.io/tl-ztna ====== Resources ====== Are bug bounties cooked? https://hakluke.com/are-bug-bounties-cooked We built a Hackbot https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html ====== Timestamps ====== (00:00:00) Introduction (00:07:22) Manual vs. AI Hacking (00:17:27) Building a Hackbot (00:23:53) Negatives of Hackbots (00:31:34) Logistics and Problems of Singularity  (00:46:21) Successes

  8. Jun 25

    Episode 180: State of Bug Bounty Maturity Posture Report

    Episode 180: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Steve Hernandez, founder of the Bug Bounty Maturity Framework (BBMF), to walk us through the inaugural State of Bug Bounty Maturity Posture Report. We go through the scores and cover Asset Hygiene, Operational Signal, how to re-engage the relationship between trust and researcher participation. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today’s Guest: https://x.com/SteveHernandezM Email Steve at info@bugbountymaturity.com Fill out this form to enter a Critical Thinkers raffle https://forms.ctbb.show/mdaz ====== Resources ====== State of Bug Bounty Maturity Posture https://bugbountymaturity.com/research/state-of-bug-bounty-maturity-posture-2026 Take the Bug Bounty Maturity Assessment https://bugbountymaturity.com/assessment AI Is Compressing the Bug Bounty Maturity Curve https://bugbountymaturity.com/research/ai-is-compressing-the-bug-bounty-maturity-curve ====== Timestamps ====== (00:00:00) Introduction (00:04:09) State of Bug Bounty Maturity Posture (00:22:33) Researcher Interface & Program Trust (00:44:38) Maturity Bands and Scoring  (01:08:19) AI Is Compressing the Bug Bounty Maturity Curve

4.9
out of 5
58 Ratings

About

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

You Might Also Like