エピソード

  • Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?
    2026/09/03

    Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, and where to focus tokens.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Sponsored by ThreatLocker - Privileged Access Management

    https://www.criticalthinkingpodcast.io/tl-pam


    ====== This Week in Bug Bounty ======


    Web Fuzzing for Hackers

    https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers


    When fear no longer holds you back. Interview with Ryan Bonner

    https://www.intigriti.com/blog/business-insights/interview-with-ryan-bonner-roll4combatus


    Steve’s Maturity Framework

    https://x.com/SteveHernandezM/status/2094398761946493107


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:07:10) Focusing your Tokens, Cloud Providers, and Dropping Bounties

    (00:18:30) Amount vs. Impact

    (00:25:42) Ideal Work Day and Focus State

    続きを読む 一部表示
    34 分
  • Episode 189: What Happened to HackerOne with Joel Margolis
    2026/08/27

    Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Guest - Joel Magolis

    https://x.com/0xteknogeek


    ====== This Week in Bug Bounty ======


    Kara Sprague’s Statement:

    “I read Joel’s post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don’t have the full fix yet, but I own it and am also open to working together to find a good solution.”

    Kara Sprague, CEO, HackerOne


    Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit plugin

    https://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-code


    Claude Kit

    https://github.com/yeswehack/claude-kit


    ====== Resources ======

    What Happened to HackerOne?

    https://blog.teknogeek.io/posts/what-happened-to-hackerone/


    Watch our episode with Alex Rice

    https://www.youtube.com/watch?v=Pa4wWv_ONjM


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:04:18) The early days: LHE's, Covid, and the rise of AI

    (00:17:20) HSM Program, HAI, and resource allocation

    (00:36:41) Sales Incentivisation

    (00:46:10) AI and Researcher Reports Data

    (00:54:38) How Can H1 Revive its Old Self

    (01:02:40) Triage

    続きを読む 一部表示
    1 時間 14 分
  • Episode 188: DEFCON 34 Hotel Room Debrief
    2026/08/20

    Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!


    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!


    Today’s Guests:

    https://x.com/7urb01

    https://x.com/busf4ctor


    ====== This Week in Bug Bounty ======


    YesWeHack is introducing Credits to combat AI slop reports

    https://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:03:45) DEFCON Event Reactions and Takeaways

    (00:12:56) Bus & Turbo Talk Overviews

    (00:21:53) Event Bugs

    続きを読む 一部表示
    42 分
  • Episode 187: Are Live Hacking Events even worth it?
    2026/08/13

    Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Sponsor: Adobe - Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!


    ====== This Week in Bug Bounty ======


    Exploiting web cache poisoning vulnerabilities

    https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-web-cache-poisoning-vulnerabilities


    ====== Resources ======

    frontier class vulnerabilities: it gets worse before it (maybe) gets better

    https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:05:41) LHE Vs. AI

    (00:19:27) Hacker Intuition and Gaslighting your Hackbot

    (00:25:49) Resolving Sol 5.6 compaction error & AI memory usage

    (00:37:00) Frontier Class Vulnerabilities



    続きを読む 一部表示
    43 分
  • Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?
    2026/08/06
    Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Network Accesshttps://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Trend of Bug Bounty Programshttps://x.com/iangcarroll/status/2082535987633410540Next chapter: Restructuring GitHub’s bug bounty programhttps://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHubhttps://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854Gauntlet Loophttps://x.com/mattshumer_/status/2081830214384886228KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/====== Timestamps ======(00:00:00) Introduction(00:05:40) Bug Bounty Program Trends & Pricing Changes(00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6(00:29:06) AI Harnessing, prompting, and the Gauntlet Loop(00:36:58) LHE vs Hackbot(00:43:21) KindaRails2Shell & WP2Shell
    続きを読む 一部表示
    58 分
  • Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026
    2026/07/30

    Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Sponsored by ThreatLocker - Zero Trust Network Access

    https://www.criticalthinkingpodcast.io/tl-ztna


    Today’s Guests:

    Harley Kimball - https://x.com/infinitelogins

    Ariel Garcia - https://x.com/Arl_rose


    ====== This Week in Bug Bounty ======

    Meet YesWeHack at DEFCON 34

    https://www.yeswehack.com/fr/page/yeswehack-defcon-34


    ====== Resources ======

    Bug Bounty Village Agenda

    https://www.bugbountydefcon.com/agenda-2026


    BBV CTF 2026

    https://www.bugbountydefcon.com/ctf


    Hacker Hangout with TikTok, HackerOne, and Bug Bounty Village

    https://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:04:39) Podcast ATO & ATM Hacks

    (00:17:12) Bug Bounty Village Preview

    (00:31:02) BBV Room Layout and Swag

    (00:42:36) BBV Agenda

    (01:10:57) Harley's Hackbot

    続きを読む 一部表示
    1 時間 23 分
  • Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)
    2026/07/23

    Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Guest: https://substack.com/@0xmoose


    ====== This Week in Bug Bounty ======

    How to use Claude Code for Bug Bounty: find fast, validate manually

    https://www.yeswehack.com/learn-bug-bounty/llm-series-claude


    ====== Resources ======

    Signal Over Noise: AI Agents and the Operator Moat

    https://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-the


    FBDL Goes Agentic: AI Agents Can Now Build Your Test Environments

    https://bugbounty.meta.com/blog/fbdl-goes-agentic/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:11:01) Satisfaction for hackbot finds

    (00:19:31) Hackbot Mechanics and Tech Debt

    (00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models

    (00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing

    (01:05:45) Hackbot Load Distribution

    続きを読む 一部表示
    1 時間 13 分
  • Episode 183: PortSwigger Research Impossible XSS SOLVED
    2026/07/16
    Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labsFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Sponsored by ThreatLocker - Zero Trust Network Accesshttps://www.criticalthinkingpodcast.io/tl-ztna====== This Week in Bug Bounty ======How LLMs are changing Bug Bounty Interview serieshttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglohttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynoraterhttps://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare====== Resources ======$15k - CSPT to full account takeover, then 2FA bypass via the prototype chainhttps://whoareme.com/blog/cspt-account-takeover-2fa-bypass/Two Bypasses for Chrome’s Sanitizer APIhttps://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/Documenting the impossible: Unexploitable XSS labshttps://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labsGitLost: How We Tricked GitHub’s AI Agent into Leaking Private Reposhttps://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/Chaining Razor SSTI into RCE via Reflection and Runtime Stringshttps://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/====== Timestamps ======(00:00:00) Introduction(00:06:07) AI Features Are Just Tech Features(00:20:02) CSPT to full Account Takeover & Other Chains(00:35:27) Sanitizer API for Chrome and Firefox(00:46:57) Solving PortSwigger's Impossible Lab & GitLost(01:01:19) SSTI into RCE via Reflection
    続きを読む 一部表示
    1 時間 15 分