Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

  1. 2d ago

    Episode 192: Hackbot Proof-of-Concept Skill Creation

    Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Sponsored by ThreatLocker - Privileged Access Management https://www.criticalthinkingpodcast.io/tl-pam ====== This Week in Bug Bounty ====== LHE at Ekoparty, open to all Ekoparty Attendees https://www.yeswehack.com/fr/page/live-hacking-event-banco-galicia-yeswehack-ekoparty-2026 Builders & Breakers | Building Hackbots: Models, Harnesses and Human Expertise with Hamid Kashfi https://www.youtube.com/watch?v=MYK9-66qe6w ====== Resources ====== Get Justin’s exclusive masterclass for more information https://www.ctbb.show/discord ====== Timestamps ====== (00:00:00) Introduction (00:05:33) PoC Creation Goals & Formats (00:15:01) Nuts and Bolts of Python & HTML Files

  2. Sep 10

    Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens

    Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! ====== This Week in Bug Bounty ====== How to use Codex for Bug Bounty research: explore broadly, validate rigorously https://www.yeswehack.com/learn-bug-bounty/llm-series-codex ====== Resources ====== Herdr https://herdr.dev/ ====== Timestamps ====== (00:00:00) Introduction (00:02:43) Rez0's Sick Caching Bug (00:11:38) Hackbot Scale & Hardware Spend (00:19:16) Stretching your Subscriptions (00:27:53) Herdr.dev & LHE's with Total Bounty Pools

  3. Sep 3

    Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?

    Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, and where to focus tokens. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Sponsored by ThreatLocker - Privileged Access Management https://www.criticalthinkingpodcast.io/tl-pam ====== This Week in Bug Bounty ====== Web Fuzzing for Hackers https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers When fear no longer holds you back. Interview with Ryan Bonner https://www.intigriti.com/blog/business-insights/interview-with-ryan-bonner-roll4combatus Steve’s Maturity Framework https://x.com/SteveHernandezM/status/2094398761946493107 ====== Timestamps ====== (00:00:00) Introduction (00:07:10) Focusing your Tokens, Cloud Providers, and Dropping Bounties (00:18:30) Amount vs. Impact (00:25:42) Ideal Work Day and Focus State

  4. Aug 27

    Episode 189: What Happened to HackerOne with Joel Margolis

    Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab:  https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today’s Guest - Joel Magolis https://x.com/0xteknogeek ====== This Week in Bug Bounty ====== Kara Sprague’s Statement: “I read Joel’s post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don’t have the full fix yet, but I own it and am also open to working together to find a good solution.”  Kara Sprague, CEO, HackerOne  Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit plugin https://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-code Claude Kit https://github.com/yeswehack/claude-kit ====== Resources ====== What Happened to HackerOne? https://blog.teknogeek.io/posts/what-happened-to-hackerone/ Watch our episode with Alex Rice https://www.youtube.com/watch?v=Pa4wWv_ONjM ====== Timestamps ====== (00:00:00) Introduction (00:04:18) The early days: LHE's, Covid, and the rise of AI (00:17:20) HSM Program, HAI, and resource allocation (00:36:41) Sales Incentivisation (00:46:10) AI and Researcher Reports Data (00:54:38) How Can H1 Revive its Old Self (01:02:40) Triage

  5. Aug 20

    Episode 188: DEFCON 34 Hotel Room Debrief

    Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership! Today’s Guests: https://x.com/7urb01 https://x.com/busf4ctor ====== This Week in Bug Bounty ====== YesWeHack is introducing Credits to combat AI slop reports https://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits ====== Timestamps ====== (00:00:00) Introduction (00:03:45) DEFCON Event Reactions and Takeaways (00:12:56) Bus & Turbo Talk Overviews (00:21:53) Event Bugs

  6. Aug 13

    Episode 187: Are Live Hacking Events even worth it?

    Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Today’s Sponsor: Adobe - Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership! ====== This Week in Bug Bounty ====== Exploiting web cache poisoning vulnerabilities https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-web-cache-poisoning-vulnerabilities ====== Resources ====== frontier class vulnerabilities: it gets worse before it (maybe) gets better https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better/ ====== Timestamps ====== (00:00:00) Introduction (00:05:41) LHE Vs. AI (00:19:27) Hacker Intuition and Gaslighting your Hackbot (00:25:49) Resolving Sol 5.6 compaction error & AI memory usage (00:37:00) Frontier Class Vulnerabilities

  7. Aug 6

    Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

    Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Sponsored by ThreatLocker - Zero Trust Network Access https://www.criticalthinkingpodcast.io/tl-ztna ====== Resources ====== Trend of Bug Bounty Programs https://x.com/iangcarroll/status/2082535987633410540 Next chapter: Restructuring GitHub’s bug bounty program https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/ Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 Gauntlet Loop https://x.com/mattshumer_/status/2081830214384886228 KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066 Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/ ====== Timestamps ====== (00:00:00) Introduction (00:05:40) Bug Bounty Program Trends & Pricing Changes (00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6 (00:29:06) AI Harnessing, prompting, and the Gauntlet Loop (00:36:58) LHE vs Hackbot (00:43:21) KindaRails2Shell & WP2Shell

  8. Jul 30

    Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

    Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village! Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/  Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch! Sponsored by ThreatLocker - Zero Trust Network Access https://www.criticalthinkingpodcast.io/tl-ztna Today’s Guests:  Harley Kimball - https://x.com/infinitelogins Ariel Garcia - https://x.com/Arl_rose ====== This Week in Bug Bounty ====== Meet YesWeHack at DEFCON 34 https://www.yeswehack.com/fr/page/yeswehack-defcon-34 ====== Resources ====== Bug Bounty Village Agenda  https://www.bugbountydefcon.com/agenda-2026 BBV CTF 2026 https://www.bugbountydefcon.com/ctf Hacker Hangout with TikTok, HackerOne, and Bug Bounty Village https://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd ====== Timestamps ====== (00:00:00) Introduction (00:04:39) Podcast ATO & ATM Hacks (00:17:12) Bug Bounty Village Preview (00:31:02) BBV Room Layout and Swag (00:42:36) BBV Agenda (01:10:57) Harley's Hackbot

4.9
out of 5
58 Ratings

About

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

You Might Also Like