PodcastsTechnologyCritical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)
Critical Thinking - Bug Bounty Podcast
Latest episode

175 episodes

  • Critical Thinking - Bug Bounty Podcast

    Episode 173: Bug Bounty is Dead and AI Killed it.

    2026-05-07 | 1h 1 mins.
    Episode 173: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about the negative effects that AI is having on the Bug Bounty scene as a whole. Is it over, or are we so back?

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: Check out Zero Trust Cloud Access:
    https://www.threatlocker.com/capabilities/zero-trust-cloud-access

    ====== Resources ======
    We want your feedback on this!
    https://forms.ctbb.show/future_of_bug_bounty

    Evolving the Android & Chrome VRPs for the AI Era
    https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era

    Paid Submissions?
    https://x.com/d0rsky/status/2047744193976742120

    Keep the Robots Out of the Gym
    https://danielmiessler.com/blog/keep-the-robots-out-of-the-gym

    Is my data used for model training?
    https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:06:28) Network effects of Bug Bounty
    (00:31:55) Hopium/Copium
    (00:47:21) The Great Training Data Debate
  • Critical Thinking - Bug Bounty Podcast

    Episode 172: Source Code Review Meta Analysis

    2026-04-30 | 51 mins.
    Episode 172: In this episode of Critical Thinking - Bug Bounty Podcast trying out a new structure of episode: a Meta Analysis of sorts of many Source Code Review techniques. This episode features tips gathered from Shubs, Rafax, and FSI. Justin highlights best approaches, patterns, and common pitfalls.

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today’s Sponsor: Adobe - Get 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.
    Expires June 30, 2026.

    ====== This Week in Bug Bounty ======

    Open-source security testing: the Bug Bounty guide to code analysis
    https://www.yeswehack.com/learn-bug-bounty/open-source-guide-code-analysis?utm_source=youtube&utm_medium=sponsor-critical-thinking&utm_campaign=open-source-guide-code-analysis

    ====== Resources ======
    Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)
    https://slcyber.io/research-center/abusing-windows-net-quirks-and-unicode-normalization-to-exploit-dnn-dotnetnuke/#:~:text=across%20different%20languages.-,A%20MUST%2DKNOW%20BEHAVIOUR%20OF%20PATH.COMBINE,-Another%20key%20implementation

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:06:49) Tracing Data Flow, knowing where your playload is landing, and developer mistakes.
    (00:17:33) Mapping the software
    (00:24:46) Sniffing for blood
    (00:31:54) Common Patterns and Pitfalls
  • Critical Thinking - Bug Bounty Podcast

    Episode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw Protobuf XSS

    2026-04-23 | 22 mins.
    Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking ages

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: Check out ThreatLocker Ringfencing
    https://www.criticalthinkingpodcast.io/tl-rf

    ====== Resources ======

    The ultimate Bug Bounty guide to OS command injection vulnerabilities
    https://www.yeswehack.com/learn-bug-bounty/ultimate-guide-os-command-injection?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-os-command-injection

    Critical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validation
    https://www.yeswehack.com/news/auth-bypass-wordpress-azure-plugin?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-wordpress-bypass-plugin

    Aituglo featured on YWH
    https://www.yeswehack.com/community/developer-aituglo-bug-bounty-story

    Adobe will be sponsoring Ekoparty in Miami and hosting a live hacking event on May 21st
    https://ekoparty.org/ekoparty-miami-2026-super-live-hacking-event/

    ====== Resources ======

    SVG clickjacking
    https://lyra.horse/blog/2025/12/svg-clickjacking/

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:06:35) Protobuff XSS
    (00:12:51) Leaking Age & CSPTs
    (00:15:59) Capital Letters and Clickjacking
  • Critical Thinking - Bug Bounty Podcast

    Episode 170: Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways

    2026-04-16 | 32 mins.
    Episode 170: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph their trip to Korea with some quick takeaways from the LHE.

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:01:41) Google LHE Debrief
    (00:09:27) Old AI Exfils & AI report writing
    (00:18:14) Human Tokens
    (00:26:13) Protoscope & Caido Websocket Repeater
  • Critical Thinking - Bug Bounty Podcast

    Episode 169: Attacking OAuth 2.1

    2026-04-09 | 30 mins.
    Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize.

    Follow us on twitter at: https://x.com/ctbbpodcast
    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======
    Follow your hosts Rhynorater, rez0 and gr3pme on X:
    https://x.com/Rhynorater
    https://x.com/rez0__
    https://x.com/gr3pme

    Critical Research Lab:
    https://lab.ctbb.show/

    ====== Ways to Support CTBBPodcast ======
    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: Check out ThreatLocker Ringfencing
    https://www.criticalthinkingpodcast.io/tl-rf

    ====== This Week in Bug Bounty ======

    Intigriti is providing free Burp Pro for Hackers!
    https://www.intigriti.com/blog/news/intigriti-collaborates-with-portswigger-to-support-ethical-hacking-excellence

    ====== Resources ======
    Django-allauth Account Takeover (ZeroPath Audit)
    https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilities

    CVE-2025-4144: Cloudflare Workers PKCE Bypass
    https://github.com/cloudflare/workers-oauth-provider/security/advisories/GHSA-qgp8-v765-qxx9

    CVE-2025-54576: OAuth2-Proxy Auth Bypass
    https://zeropath.com/blog/cve-2025-54576-oauth2-proxy-auth-bypass

    ====== Timestamps ======
    (00:00:00) Introduction
    (00:02:16) OAuth 2.0 Standards
    (00:12:08) Agent to Agent Communication
    (00:17:19) CVE Case studies

More Technology podcasts

About Critical Thinking - Bug Bounty Podcast

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
Podcast website

Listen to Critical Thinking - Bug Bounty Podcast, Darknet Diaries and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features