Critical Thinking - Bug Bounty Podcast
Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Dernier épisode
187 épisodes
- Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out Zero Trust Network Access:
https://www.criticalthinkingpodcast.io/tl-ztna
Today’s Guests:
Harley Kimball - https://x.com/infinitelogins
Ariel Garcia - https://x.com/Arl_rose
====== This Week in Bug Bounty ======
Meet YesWeHack at DEFCON 34
https://www.yeswehack.com/fr/page/yeswehack-defcon-34
====== Resources ======
Bug Bounty Village Agenda
https://www.bugbountydefcon.com/agenda-2026
BBV CTF 2026
https://www.bugbountydefcon.com/ctf
Hacker Hangout with TikTok, HackerOne, and Bug Bounty Village
https://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd
====== Timestamps ======
(00:00:00) Introduction
(00:04:39) Podcast ATO & ATM Hacks
(00:17:12) Bug Bounty Village Preview
(00:31:02) BBV Room Layout and Swag
(00:42:36) BBV Agenda
(01:10:57) Harley's Hackbot - Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Guest: https://substack.com/@0xmoose
====== This Week in Bug Bounty ======
How to use Claude Code for Bug Bounty: find fast, validate manually
https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
====== Resources ======
Signal Over Noise: AI Agents and the Operator Moat
https://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-the
FBDL Goes Agentic: AI Agents Can Now Build Your Test Environments
https://bugbounty.meta.com/blog/fbdl-goes-agentic/
====== Timestamps ======
(00:00:00) Introduction
(00:11:01) Satisfaction for hackbot finds
(00:19:31) Hackbot Mechanics and Tech Debt
(00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models
(00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing
(01:05:45) Hackbot Load Distribution - Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labs
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out Zero Trust Network Access:
https://www.criticalthinkingpodcast.io/tl-ztna
====== This Week in Bug Bounty ======
How LLMs are changing Bug Bounty Interview series
https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglo
https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynorater
https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare
====== Resources ======
$15k - CSPT to full account takeover, then 2FA bypass via the prototype chain
https://whoareme.com/blog/cspt-account-takeover-2fa-bypass/
Two Bypasses for Chrome’s Sanitizer API
https://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/
Documenting the impossible: Unexploitable XSS labs
https://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labs
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos
https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
Chaining Razor SSTI into RCE via Reflection and Runtime Strings
https://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/
====== Timestamps ======
(00:00:00) Introduction
(00:06:07) AI Features Are Just Tech Features
(00:20:02) CSPT to full Account Takeover & Other Chains
(00:35:27) Sanitizer API for Chrome and Firefox
(00:46:57) Solving PortSwigger's Impossible Lab & GitLost
(01:01:19) SSTI into RCE via Reflection - Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some GraphQL Hackbot finds, and what AI’s #1 mission should be.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== This Week in Bug Bounty ======
LeHack 2026 Recap
https://event.yeswehack.com/events/lehack-2026
Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits
https://www.yeswehack.com/fr/news/chocopocs-vulnerability-researchers-trojanised-exploits
Navigating the AI Wave: How We're Keeping Security Research Meaningful
https://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actions
====== Resources ======
Caido Skills
https://github.com/caido/skills/pull/22
Hunting For AWS Cognito Security
Misconfigurations
https://www.yassineaboukir.com/talks/NahamConEU2022.pdf
X MCP
https://docs.x.com/tools/mcp
US South Summer Sessions: Hack the Heat
https://h1.community/events/details/hackerone-us-south-hackerone-club-presents-us-south-summer-sessions-hack-the-heat/
====== Timestamps ======
(00:00:00) Introduction
(00:08:31) WPM Bug & Wayback to Guest Bearer
(00:18:42) GraphQL Hackbot Finds, Fable Updates, & AI's #1 Mission
(00:29:45) MCP, US South H1 Event, & AI Sandbox Escapes - Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
https://x.com/Rhynorater
https://x.com/rez0__
https://x.com/gr3pme
Critical Research Lab:
https://lab.ctbb.show/
Need a Pentest? We just launched CTBB Pentests!
https://pentest.ctbb.show/
Hack full time? Check out the Full-Time Hunter’s Guild!
https://ctbb.show/fthg
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out Zero Trust Network Access:
https://www.criticalthinkingpodcast.io/tl-ztna
====== Resources ======
Are bug bounties cooked?
https://hakluke.com/are-bug-bounties-cooked
We built a Hackbot
https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html
====== Timestamps ======
(00:00:00) Introduction
(00:07:22) Manual vs. AI Hacking
(00:17:27) Building a Hackbot
(00:23:53) Negatives of Hackbots
(00:31:34) Logistics and Problems of Singularity
(00:46:21) Successes
Plus de podcasts Technologies
Podcasts tendance de Technologies
À propos de Critical Thinking - Bug Bounty Podcast
A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.
Site web du podcastÉcoutez Critical Thinking - Bug Bounty Podcast, Tech Café ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités
Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités


Critical Thinking - Bug Bounty Podcast
Scannez le code,
Téléchargez l’app,
Écoutez.
Téléchargez l’app,
Écoutez.


































