
Hosted by Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme) · EN
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztnaToday’s Guests: Harley Kimball - https://x.com/infiniteloginsAriel Garcia - https://x.com/Arl_rose====== This Week in Bug Bounty ======Meet YesWeHack at DEFCON 34https://www.yeswehack.com/fr/page/yeswehack-defcon-34====== Resources ======Bug Bounty Village Agenda https://www.bugbountydefcon.com/agenda-2026BBV CTF 2026https://www.bugbountydefcon.com/ctfHacker Hangout with TikTok, HackerOne, and Bug Bounty Villagehttps://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd====== Timestamps ======(00:00:00) Introduction(00:04:39) Podcast ATO & ATM Hacks(00:17:12) Bug Bounty Village Preview(00:31:02) BBV Room Layout and Swag(00:42:36) BBV Agenda(01:10:57) Harley's Hackbot

Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Guest: https://substack.com/@0xmoose====== This Week in Bug Bounty ======How to use Claude Code for Bug Bounty: find fast, validate manuallyhttps://www.yeswehack.com/learn-bug-bounty/llm-series-claude====== Resources ======Signal Over Noise: AI Agents and the Operator Moathttps://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-theFBDL Goes Agentic: AI Agents Can Now Build Your Test Environmentshttps://bugbounty.meta.com/blog/fbdl-goes-agentic/====== Timestamps ======(00:00:00) Introduction(00:11:01) Satisfaction for hackbot finds(00:19:31) Hackbot Mechanics and Tech Debt(00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models(00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing(01:05:45) Hackbot Load Distribution

Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labsFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztna====== This Week in Bug Bounty ======How LLMs are changing Bug Bounty Interview serieshttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglohttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynoraterhttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare====== Resources ======$15k - CSPT to full account takeover, then 2FA bypass via the prototype chainhttps://whoareme.com/blog/cspt-account-takeover-2fa-bypass/Two Bypasses for Chrome’s Sanitizer APIhttps://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/Documenting the impossible: Unexploitable XSS labshttps://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labsGitLost: How We Tricked GitHub’s AI Agent into Leaking Private Reposhttps://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/Chaining Razor SSTI into RCE via Reflection and Runtime Stringshttps://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/====== Timestamps ======(00:00:00) Introduction(00:06:07) AI Features Are Just Tech Features(00:20:02) CSPT to full Account Takeover & Other Chains(00:35:27) Sanitizer API for Chrome and Firefox(00:46:57) Solving PortSwigger's Impossible Lab & GitLost(01:01:19) SSTI into RCE via Reflection

Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some GraphQL Hackbot finds, and what AI’s #1 mission should be.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!====== This Week in Bug Bounty ======LeHack 2026 Recaphttps://event.yeswehack.com/events/lehack-2026Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploitshttps://www.yeswehack.com/fr/news/chocopocs-vulnerability-researchers-trojanised-exploitsNavigating the AI Wave: How We're Keeping Security Research Meaningfulhttps://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actions====== Resources ======Caido Skillshttps://github.com/caido/skills/pull/22Hunting For AWS Cognito SecurityMisconfigurationshttps://www.yassineaboukir.com/talks/NahamConEU2022.pdfX MCPhttps://docs.x.com/tools/mcpUS South Summer Sessions: Hack the Heathttps://h1.community/events/details/hackerone-us-south-hackerone-club-presents-us-south-summer-sessions-hack-the-heat/====== Timestamps ======(00:00:00) Introduction(00:08:31) WPM Bug & Wayback to Guest Bearer(00:18:42) GraphQL Hackbot Finds, Fable Updates, & AI's #1 Mission(00:29:45) MCP, US South H1 Event, & AI Sandbox Escapes

Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Are bug bounties cooked?https://hakluke.com/are-bug-bounties-cookedWe built a Hackbothttps://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html====== Timestamps ======(00:00:00) Introduction(00:07:22) Manual vs. AI Hacking(00:17:27) Building a Hackbot(00:23:53) Negatives of Hackbots(00:31:34) Logistics and Problems of Singularity (00:46:21) Successes

Episode 180: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Steve Hernandez, founder of the Bug Bounty Maturity Framework (BBMF), to walk us through the inaugural State of Bug Bounty Maturity Posture Report. We go through the scores and cover Asset Hygiene, Operational Signal, how to re-engage the relationship between trust and researcher participation.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Guest: https://x.com/SteveHernandezMEmail Steve at info@bugbountymaturity.comFill out this form to enter a Critical Thinkers rafflehttps://forms.ctbb.show/mdaz====== Resources ======State of Bug Bounty Maturity Posturehttps://bugbountymaturity.com/research/state-of-bug-bounty-maturity-posture-2026Take the Bug Bounty Maturity Assessmenthttps://bugbountymaturity.com/assessmentAI Is Compressing the Bug Bounty Maturity Curvehttps://bugbountymaturity.com/research/ai-is-compressing-the-bug-bounty-maturity-curve====== Timestamps ======(00:00:00) Introduction(00:04:09) State of Bug Bounty Maturity Posture(00:22:33) Researcher Interface & Program Trust(00:44:38) Maturity Bands and Scoring (01:08:19) AI Is Compressing the Bug Bounty Maturity Curve

Episode 179: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how to stay motivated and keep the vibes strong during this trying time for Bug Bounty.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Cloud Access:https://www.threatlocker.com/capabilities/zero-trust-cloud-access====== Timestamps ======(00:00:00) Introduction(00:04:57) Managing Hacker Motivation(00:10:45) Community, Competition, & Curosity(00:16:54) Using AI with Passion(00:23:10) The LHE Method & Sharing Wins(00:28:01) Video POCs, Scripts, & Talking about Bugs(00:40:49) Watching your health & stopping mid-hack

Episode 178: In this episode of Critical Thinking - Bug Bounty Podcast we’re back with BruteCat to finish up our discussion on hacking Google. This week we hit AI.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Guest: https://x.com/brutecat====== Resources ======Hacking Google with AIhttps://brutecat.com/articles/hacking-google-with-ai/====== Timestamps ======(00:00:00) Introduction(00:03:07) Discovery Docs Refresher & AI at BugSWAT Mexico(00:30:49) Auth & Enumeration of Referer and Origin(00:45:59) Pwning Google Stories(01:09:32) Batch Execute & GraphQL

Episode 177: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by BruteCat to talk about his journey hacking Google Cloud, Gmail, Youtube, and Google Phone.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Cloud Access from ThreatLockerhttps://www.criticalthinkingpodcast.io/tl-ztcaToday’s Guest: https://x.com/brutecat====== Resources ======StubZero: $148,337 RCE in Google Cloud Productionhttps://brutecat.com/articles/google-cloud-rce/Leaking the email of any YouTube user for $10,000https://brutecat.com/articles/leaking-youtube-emails/Disclosing YouTube Creator Emails for a $20k Bountyhttps://brutecat.com/articles/youtube-creator-emails/Leaking the phone number of any Google userhttps://brutecat.com/articles/leaking-google-phones/====== Timestamps ======(00:00:00) Introduction(00:29:14) 2nd RCE in Application Integration(00:39:55) BruteCat's Background & RCE Follow-up Questions(00:48:02) Google VRP and Youtube Bugs(01:10:17) Google Phone Leak(01:18:36) Discovery Docs and Episode 178 Teaser

Episode 176: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by top Adobe hacker Jim Green to deep-dive AEM. We talk through Sling selectors, Permissions, and how to spot AEM Red Flags.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today’s Sponsor: Adobe. Earn more for AI bugs with Adobe’s new AI Tier! https://blog.adobe.com/security/adobe-expands-bug-bounty-program-to-incentivize-ai-security-researchAlso don’t forget to also grab a 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.Expires June 30, 2026. ====== This Week in Bug Bounty ======Scaling Bug Bounty triage in the AI era(https://www.yeswehack.com/security-best-practices/scaling-bug-bounty-triage-ai)The AI impact: a triager’s perspectivehttps://www.intigriti.com/blog/business-insights/the-ai-impact-a-triagers-perspective====== Resources ======Sling Selectors - The Key to Unlocking AEM's Attack Surfacehttps://greenjam.co.uk/blog/sling-selectors/Just a Moment CTFhttps://poc.greenjam.co.uk/just-a-moment.htmlGeneral XSS jquery .text()https://poc.greenjam.co.uk/text-xss.htmlURL XXS Challengehttps://poc.greenjam.co.uk/url-xss.html====== Timestamps ======(00:00:00) Introduction(00:04:35) Background and AEM Bug(00:17:40) Sling Selectors & the Tech Stack(00:38:14) Permissions & Apache Sling Resolution(01:01:37) The Bugs & AEM Red Flags(01:31:55) Moment in Time CTF(01:40:38) General XSS jquery .text()(01:45:45) URL XXS Challenge