- 26 minutes 30 secondsEpisode 192: Hackbot Proof-of-Concept Skill Creation
Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Sponsored by ThreatLocker - Privileged Access Management
https://www.criticalthinkingpodcast.io/tl-pam
====== This Week in Bug Bounty ======
LHE at Ekoparty, open to all Ekoparty Attendees
https://www.yeswehack.com/fr/page/live-hacking-event-banco-galicia-yeswehack-ekoparty-2026
Builders & Breakers | Building Hackbots: Models, Harnesses and Human Expertise with Hamid Kashfi
https://www.youtube.com/watch?v=MYK9-66qe6w
====== Resources ======
Get Justin’s exclusive masterclass for more information
====== Timestamps ======
(00:00:00) Introduction
(00:05:33) PoC Creation Goals & Formats
(00:15:01) Nuts and Bolts of Python & HTML Files
17 September 2026, 9:00 am - 37 minutes 28 secondsEpisode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens
Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== This Week in Bug Bounty ======
How to use Codex for Bug Bounty research: explore broadly, validate rigorously
https://www.yeswehack.com/learn-bug-bounty/llm-series-codex
====== Resources ======
Herdr
https://herdr.dev/
====== Timestamps ======
(00:00:00) Introduction
(00:02:43) Rez0's Sick Caching Bug
(00:11:38) Hackbot Scale & Hardware Spend
(00:19:16) Stretching your Subscriptions
(00:27:53) Herdr.dev & LHE's with Total Bounty Pools
10 September 2026, 1:00 pm - 33 minutes 50 secondsEpisode 190: Hacker Life Coaching & is Rez0 a Claude Shill?
Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, and where to focus tokens.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Sponsored by ThreatLocker - Privileged Access Management
https://www.criticalthinkingpodcast.io/tl-pam
====== This Week in Bug Bounty ======
Web Fuzzing for Hackers
https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers
When fear no longer holds you back. Interview with Ryan Bonner
https://www.intigriti.com/blog/business-insights/interview-with-ryan-bonner-roll4combatus
Steve’s Maturity Framework
https://x.com/SteveHernandezM/status/2094398761946493107
====== Timestamps ======
(00:00:00) Introduction
(00:07:10) Focusing your Tokens, Cloud Providers, and Dropping Bounties
(00:18:30) Amount vs. Impact
(00:25:42) Ideal Work Day and Focus State
3 September 2026, 1:00 pm - 1 hour 14 minutesEpisode 189: What Happened to HackerOne with Joel Margolis
Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Guest - Joel Magolis
====== This Week in Bug Bounty ======
Kara Sprague’s Statement:
“I read Joel’s post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don’t have the full fix yet, but I own it and am also open to working together to find a good solution.”
Kara Sprague, CEO, HackerOne
Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit plugin
https://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-code
Claude Kit
https://github.com/yeswehack/claude-kit
====== Resources ======
What Happened to HackerOne?
https://blog.teknogeek.io/posts/what-happened-to-hackerone/
Watch our episode with Alex Rice
https://www.youtube.com/watch?v=Pa4wWv_ONjM
====== Timestamps ======
(00:00:00) Introduction
(00:04:18) The early days: LHE's, Covid, and the rise of AI
(00:17:20) HSM Program, HAI, and resource allocation
(00:36:41) Sales Incentivisation
(00:46:10) AI and Researcher Reports Data
(00:54:38) How Can H1 Revive its Old Self
(01:02:40) Triage
27 August 2026, 9:00 am - 41 minutes 47 secondsEpisode 188: DEFCON 34 Hotel Room Debrief
Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!
Today’s Guests:
====== This Week in Bug Bounty ======
YesWeHack is introducing Credits to combat AI slop reports
https://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits
====== Timestamps ======
(00:00:00) Introduction
(00:03:45) DEFCON Event Reactions and Takeaways
(00:12:56) Bus & Turbo Talk Overviews
(00:21:53) Event Bugs
20 August 2026, 9:00 am - 42 minutes 32 secondsEpisode 187: Are Live Hacking Events even worth it?
Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Sponsor: Adobe - Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!
====== This Week in Bug Bounty ======
Exploiting web cache poisoning vulnerabilities
====== Resources ======
frontier class vulnerabilities: it gets worse before it (maybe) gets better
https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better/
====== Timestamps ======
(00:00:00) Introduction
(00:05:41) LHE Vs. AI
(00:19:27) Hacker Intuition and Gaslighting your Hackbot
(00:25:49) Resolving Sol 5.6 compaction error & AI memory usage
(00:37:00) Frontier Class Vulnerabilities
13 August 2026, 9:00 am - 58 minutes 4 secondsEpisode 186: Is Sol 5.6 SuperHuman for Bug Bounty?
Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Sponsored by ThreatLocker - Zero Trust Network Access
https://www.criticalthinkingpodcast.io/tl-ztna
====== Resources ======
Trend of Bug Bounty Programs
https://x.com/iangcarroll/status/2082535987633410540
Next chapter: Restructuring GitHub’s bug bounty program
https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/
Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
Gauntlet Loop
https://x.com/mattshumer_/status/2081830214384886228
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)
https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
====== Timestamps ======
(00:00:00) Introduction
(00:05:40) Bug Bounty Program Trends & Pricing Changes
(00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6
(00:29:06) AI Harnessing, prompting, and the Gauntlet Loop
(00:36:58) LHE vs Hackbot
(00:43:21) KindaRails2Shell & WP2Shell
6 August 2026, 9:00 am - 1 hour 23 minutesEpisode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026
Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Sponsored by ThreatLocker - Zero Trust Network Access
https://www.criticalthinkingpodcast.io/tl-ztna
Today’s Guests:
Harley Kimball - https://x.com/infinitelogins
Ariel Garcia - https://x.com/Arl_rose
====== This Week in Bug Bounty ======
Meet YesWeHack at DEFCON 34
https://www.yeswehack.com/fr/page/yeswehack-defcon-34
====== Resources ======
Bug Bounty Village Agenda
https://www.bugbountydefcon.com/agenda-2026
BBV CTF 2026
https://www.bugbountydefcon.com/ctf
Hacker Hangout with TikTok, HackerOne, and Bug Bounty Village
====== Timestamps ======
(00:00:00) Introduction
(00:04:39) Podcast ATO & ATM Hacks
(00:17:12) Bug Bounty Village Preview
(00:31:02) BBV Room Layout and Swag
(00:42:36) BBV Agenda
(01:10:57) Harley's Hackbot
30 July 2026, 9:00 am - 1 hour 13 minutesEpisode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)
Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Guest: https://substack.com/@0xmoose
====== This Week in Bug Bounty ======
How to use Claude Code for Bug Bounty: find fast, validate manually
https://www.yeswehack.com/learn-bug-bounty/llm-series-claude
====== Resources ======
Signal Over Noise: AI Agents and the Operator Moat
https://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-the
FBDL Goes Agentic: AI Agents Can Now Build Your Test Environments
https://bugbounty.meta.com/blog/fbdl-goes-agentic/
====== Timestamps ======
(00:00:00) Introduction
(00:11:01) Satisfaction for hackbot finds
(00:19:31) Hackbot Mechanics and Tech Debt
(00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models
(00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing
(01:05:45) Hackbot Load Distribution
23 July 2026, 9:00 am - 1 hour 14 minutesEpisode 183: PortSwigger Research Impossible XSS SOLVED
Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labs
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Sponsored by ThreatLocker - Zero Trust Network Access
https://www.criticalthinkingpodcast.io/tl-ztna
====== This Week in Bug Bounty ======
How LLMs are changing Bug Bounty Interview series
https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglo
https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynorater
https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare
====== Resources ======
$15k - CSPT to full account takeover, then 2FA bypass via the prototype chain
https://whoareme.com/blog/cspt-account-takeover-2fa-bypass/
Two Bypasses for Chrome’s Sanitizer API
https://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/
Documenting the impossible: Unexploitable XSS labs
https://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labs
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos
https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
Chaining Razor SSTI into RCE via Reflection and Runtime Strings
https://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/
====== Timestamps ======
(00:00:00) Introduction
(00:06:07) AI Features Are Just Tech Features
(00:20:02) CSPT to full Account Takeover & Other Chains
(00:35:27) Sanitizer API for Chrome and Firefox
(00:46:57) Solving PortSwigger's Impossible Lab & GitLost
(01:01:19) SSTI into RCE via Reflection
16 July 2026, 9:00 am - 39 minutes 5 secondsEpisode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission
Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some GraphQL Hackbot finds, and what AI’s #1 mission should be.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== This Week in Bug Bounty ======
LeHack 2026 Recap
https://event.yeswehack.com/events/lehack-2026
Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits
https://www.yeswehack.com/fr/news/chocopocs-vulnerability-researchers-trojanised-exploits
Navigating the AI Wave: How We're Keeping Security Research Meaningful
https://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actions
====== Resources ======
Caido Skills
https://github.com/caido/skills/pull/22
Hunting For AWS Cognito Security
Misconfigurations
https://www.yassineaboukir.com/talks/NahamConEU2022.pdf
X MCP
US South Summer Sessions: Hack the Heat
====== Timestamps ======
(00:00:00) Introduction
(00:08:31) WPM Bug & Wayback to Guest Bearer
(00:18:42) GraphQL Hackbot Finds, Fable Updates, & AI's #1 Mission
(00:29:45) MCP, US South H1 Event, & AI Sandbox Escapes
9 July 2026, 9:00 am - More Episodes? Get the App