Critical Thinking - Bug Bounty Podcast
Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Dernier épisode
196 épisodes
- Episode 194: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph cover Faav’s Microsoft hack, Salesforce adjusting their scope, and if/how Jev can be used for Bug Bounty
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Sponsored by ThreatLocker - Privileged Access Management
https://www.criticalthinkingpodcast.io/tl-pam
====== Resources ======
How I Could've Accessed 17 Trillion Microsoft Records
https://t.co/ASdR0j7rDN
====== Timestamps ======
(00:00:00) Introduction
(00:04:10) Opus 5.5 & Cyber Verification Program
(00:12:01) Jev, Tac, and CVP
(00:24:45) Turbo Intruder 2
(00:31:33) Salesforce's critical error & Faav's Findings - Episode 193: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Jorian Woltjer to talk through his Bug Bounty journey and all the crazy research he’s done for the Critical Thinking Lab.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== Resources ======
Cache key injection: Smuggling poison through the door
https://www.yeswehack.com/lab/research-cache-key-injection
====== Resources ======
XS-Leaks
https://xsleaks.dev/
Solving an ORB mystery
https://lab.ctbb.show/research/solving-an-orb-mystery
Research Review #24: Solving an ORB mystery (J0R1AN)
https://www.youtube.com/watch?v=TpXccQbOb48
Stopping Redirects
https://lab.ctbb.show/research/stopping-redirects
Ethical Hacker Groep Nederland
https://www.youtube.com/playlist?list=PL-cT3O--POR-ElvSufpZ1oPfyocmWYeos
====== Timestamps ======
(00:00:00) Introduction
(00:04:19) CTFd status code XS-Leak
(00:18:05) Jorian's Journey & Solving an ORB mystery
(00:33:39) Stopping Redirects
(00:58:55) DNS Rebinding in the browser
(01:08:47) Popunder: weak password prompt
(01:24:33) Declarative partial updates - Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Sponsored by ThreatLocker - Privileged Access Management
https://www.criticalthinkingpodcast.io/tl-pam
====== This Week in Bug Bounty ======
LHE at Ekoparty, open to all Ekoparty Attendees
https://www.yeswehack.com/fr/page/live-hacking-event-banco-galicia-yeswehack-ekoparty-2026
Builders & Breakers | Building Hackbots: Models, Harnesses and Human Expertise with Hamid Kashfi
https://www.youtube.com/watch?v=MYK9-66qe6w
====== Resources ======
Get Justin’s exclusive masterclass for more information
https://www.ctbb.show/discord
====== Timestamps ======
(00:00:00) Introduction
(00:05:33) PoC Creation Goals & Formats
(00:15:01) Nuts and Bolts of Python & HTML Files - Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== This Week in Bug Bounty ======
How to use Codex for Bug Bounty research: explore broadly, validate rigorously
https://www.yeswehack.com/learn-bug-bounty/llm-series-codex
====== Resources ======
Herdr
https://herdr.dev/
====== Timestamps ======
(00:00:00) Introduction
(00:02:43) Rez0's Sick Caching Bug
(00:11:38) Hackbot Scale & Hardware Spend
(00:19:16) Stretching your Subscriptions
(00:27:53) Herdr.dev & LHE's with Total Bounty Pools - Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, and where to focus tokens.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Sponsored by ThreatLocker - Privileged Access Management
https://www.criticalthinkingpodcast.io/tl-pam
====== This Week in Bug Bounty ======
Web Fuzzing for Hackers
https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers
When fear no longer holds you back. Interview with Ryan Bonner
https://www.intigriti.com/blog/business-insights/interview-with-ryan-bonner-roll4combatus
Steve’s Maturity Framework
https://x.com/SteveHernandezM/status/2094398761946493107
====== Timestamps ======
(00:00:00) Introduction
(00:07:10) Focusing your Tokens, Cloud Providers, and Dropping Bounties
(00:18:30) Amount vs. Impact
(00:25:42) Ideal Work Day and Focus State
Plus de podcasts Technologies
Podcasts tendance de Technologies
À propos de Critical Thinking - Bug Bounty Podcast
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
Site web du podcastÉcoutez Critical Thinking - Bug Bounty Podcast, Silicon Carne, un peu de picante dans un monde de Tech ! ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités
Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités


Critical Thinking - Bug Bounty Podcast
Scannez le code,
Téléchargez l’app,
Écoutez.
Téléchargez l’app,
Écoutez.


































