- 49 minutes 50 secondsEpisode 175: Rhyno’s Hackbot Setup, Sick Bugs, and ZDI Drama
Episode 175: In this episode of Critical Thinking - Bug Bounty Podcast we’re comparing Hackbot setups and results. We also talk about some of the recent ZDI drama, as well as the importance of freaking beautiful POCs
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out Zero Trust Cloud Access from ThreatLocker
https://www.criticalthinkingpodcast.io/tl-ztca
====== Resources ======
Another day, another universal linux LPE
https://x.com/v12sec/status/2054491454064746629
ZDI Drama
https://x.com/ryotkak/status/2052881664909660521
Orange Tsai Bug on Edge
https://x.com/thezdi/status/2054868495888777266
Chompie's Exploit in NV Container Toolkit
https://x.com/chompie1337/status/2054882193055601140
GitHub Security April bug bounty stats
https://x.com/GitHubSecurity/status/2054274356403138932
====== Timestamps ======
(00:00:00) Introduction
(00:02:14) q param prompt injection & Mobile CSPT
(00:14:17) Admin API Key MegaCrit
(00:17:13) Hackbots
(00:37:10) Pretty POCs and ZDI Drama
(00:44:48) GitHub Security April Stats
21 May 2026, 9:00 am - 1 hour 9 minutesEpisode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.5
Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
====== This Week in Bug Bounty ======
COST, AI frontier models and more: A measured take on the future of security testing
https://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testing
Common AI misconceptions debugged!
BountySync + Social
https://luma.com/bountysync_social
====== Resources ======
Ghosts of Encryption Past
https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/
tessl Skill Optimizer
https://tessl.io/registry/tessl/skill-optimizer/0.8.0
The Internet Is Falling Down, Falling Down, Falling Down
High Fidelity Check for the cPanel Authentication Bypass
Achieving Deterministic Prompt Injection Through Client-Side Feedback Loops
GPT-5.5: Mythos-Like Hacking, Open To All
https://xbow.com/blog/mythos-like-hacking-open-to-all
Remote Command Execution in Google Cloud with Single Directory Deletion
====== Timestamps ======
(00:00:00) Introduction
(00:09:20) AMPScript
(00:25:10) Tessl Skill Optimizer
(00:33:07) cPanel & WHM Authentication Bypass
(00:40:46) Advice for Bug Bounty Programs
(00:50:07) Prompt Injection Through Client-Side Feedback Loops
(00:54:37) GPT 5.5
(01:01:00) Remote Command Execution in Google Cloud
14 May 2026, 9:00 am - 1 hour 1 minuteEpisode 173: Bug Bounty is Dead and AI Killed it.
Episode 173: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about the negative effects that AI is having on the Bug Bounty scene as a whole. Is it over, or are we so back?
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out Zero Trust Cloud Access:
https://www.criticalthinkingpodcast.io/tl-ztca
====== Resources ======
We want your feedback on this!
https://forms.ctbb.show/future_of_bug_bounty
Evolving the Android & Chrome VRPs for the AI Era
https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era
Paid Submissions?
https://x.com/d0rsky/status/2047744193976742120
Keep the Robots Out of the Gym
https://danielmiessler.com/blog/keep-the-robots-out-of-the-gym
Is my data used for model training?
https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training
====== Timestamps ======
(00:00:00) Introduction
(00:06:28) Network effects of Bug Bounty
(00:31:55) Hopium/Copium
(00:47:21) The Great Training Data Debate
7 May 2026, 9:00 am - 51 minutes 1 secondEpisode 172: Source Code Review Meta Analysis
Episode 172: In this episode of Critical Thinking - Bug Bounty Podcast trying out a new structure of episode: a Meta Analysis of sorts of many Source Code Review techniques. This episode features tips gathered from Shubs, Rafax, and FSI. Justin highlights best approaches, patterns, and common pitfalls.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Sponsor: Adobe - Get 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.
Expires June 30, 2026.
====== This Week in Bug Bounty ======
Open-source security testing: the Bug Bounty guide to code analysis
====== Resources ======
Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)
====== Timestamps ======
(00:00:00) Introduction
(00:06:49) Tracing Data Flow, knowing where your playload is landing, and developer mistakes.
(00:17:33) Mapping the software
(00:24:46) Sniffing for blood
(00:31:54) Common Patterns and Pitfalls
30 April 2026, 9:00 am - 22 minutes 44 secondsEpisode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw Protobuf XSS
Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking ages
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out ThreatLocker Ringfencing
https://www.criticalthinkingpodcast.io/tl-rf
====== Resources ======
The ultimate Bug Bounty guide to OS command injection vulnerabilities
Critical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validation
Aituglo featured on YWH
https://www.yeswehack.com/community/developer-aituglo-bug-bounty-story
Adobe will be sponsoring Ekoparty in Miami and hosting a live hacking event on May 21st
https://ekoparty.org/ekoparty-miami-2026-super-live-hacking-event/
====== Resources ======
SVG clickjacking
https://lyra.horse/blog/2025/12/svg-clickjacking/
====== Timestamps ======
(00:00:00) Introduction
(00:06:35) Protobuff XSS
(00:12:51) Leaking Age & CSPTs
(00:15:59) Capital Letters and Clickjacking
23 April 2026, 9:00 am - 32 minutes 50 secondsEpisode 170: Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways
Episode 170: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph their trip to Korea with some quick takeaways from the LHE.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
====== Timestamps ======
(00:00:00) Introduction
(00:01:41) Google LHE Debrief
(00:09:27) Old AI Exfils & AI report writing
(00:18:14) Human Tokens
(00:26:13) Protoscope & Caido Websocket Repeater
16 April 2026, 9:00 am - 30 minutes 16 secondsEpisode 169: Attacking OAuth 2.1
Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out ThreatLocker Ringfencing
https://www.criticalthinkingpodcast.io/tl-rf
====== This Week in Bug Bounty ======
Intigriti is providing free Burp Pro for Hackers!
====== Resources ======
Django-allauth Account Takeover (ZeroPath Audit)
https://zeropath.com/blog/django-allauth-account-takeover-vulnerabilities
CVE-2025-4144: Cloudflare Workers PKCE Bypass
https://github.com/cloudflare/workers-oauth-provider/security/advisories/GHSA-qgp8-v765-qxx9
CVE-2025-54576: OAuth2-Proxy Auth Bypass
https://zeropath.com/blog/cve-2025-54576-oauth2-proxy-auth-bypass
====== Timestamps ======
(00:00:00) Introduction
(00:02:16) OAuth 2.0 Standards
(00:12:08) Agent to Agent Communication
(00:17:19) CVE Case studies
9 April 2026, 9:00 am - 1 hour 35 minutesEpisode 168: XSSDoctor - Client-side Path Traversal Research
Episode 168: In this episode of Critical Thinking - Bug Bounty Podcast we’re getting a visit from the XSS Doctor. Jonathan joins us to go through his Client-side workflow, run labs, and diagnose some bugs live.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Guest: https://x.com/xssdoctor
====== Resources ======
The Dot-Dot-Slash That Frameworks Hand You: CSPT Across Every Major Frontend Framework
https://lab.ctbb.show/research/the-dot-dot-slash-that-frameworks-hand-you
URL validation bypass cheat sheet
https://portswigger.net/web-security/ssrf/url-validation-bypass-cheat-sheet
====== Timestamps ======
(00:00:00) Introduction
(00:01:37) Home Automation AI Hack & E-signature bug stories
(00:12:15) E-signature bug
(00:17:01) XSS DR Intro and Bug Bounty Journey
(00:31:51) CSPT Workflows
(01:07:57) Wildcard Path Parameters
(01:30:34) Custom Sinks
2 April 2026, 9:00 am - 51 minutes 40 secondsEpisode 167: Stealing Bugs with Valeriy Shevchenko
Episode 167: In this episode of Critical Thinking - Bug Bounty Podcast we welcome Valeriy Shevchenko to talk about program management, anchor programs, and Theft in Bug Bounty.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out ThreatLocker Ringfencing
https://www.criticalthinkingpodcast.io/tl-rf
Today’s Guest: https://x.com/Krevetk0Valeriy
====== This Week in Bug Bounty ======
HackerOne’s Bug Bounty Maturity Framework:
https://www.hackerone.com/blog/program-maturity-framework-bug-bounty-operations
Intigriti is hiring a Product Security Analyst
https://jobs.criticalthinkingpodcast.io/jobs/product-security-analyst-25ef4706
====== Resources ======
Valeriy’s Blog
====== Timestamps ======
(00:00:00) Introduction
(00:03:15) Valeriy's Bug story
(00:19:48) Anchor Programs and Bug Hunting Motivation
(00:29:50) Stealing Bugs
26 March 2026, 9:00 am - 53 minutes 2 secondsEpisode 166: Rez0’s Top Claude Skill Secrets
Episode 166: In this episode of Critical Thinking - Bug Bounty Podcast we talk about Rez0’s Claude Skill Secrets, when AI Generated reports fall apart, and agents vs filters.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today’s Sponsor: Adobe
====== This Week in Bug Bounty ======
Intigriti launched their ambassadors program. https://www.intigriti.com/ambassador
Adobe will be at Hack The Bay
Bug Bounty Maturity Framework
https://bugbountymaturity.com/
====== Resources ======
h1-brain
https://github.com/PatrikFehrenbach/h1-brain
caido skills
http://github.com/caido/skills
Tweet from Karpathy
https://x.com/karpathy/status/2031767720933634100?s=20
Find every inefficiency in your Claude workflow with one prompt
https://x.com/shannholmberg/status/2030605364421595468
====== Timestamps ======
(00:00:00) Introduction
(00:08:28) Claude skills
(00:30:00) How AI Generated reports fall apart
(00:38:44) Orchestration
(00:49:10) Agents vs Folders
19 March 2026, 9:00 am - 44 minutes 23 secondsEpisode 165: Protobuf Hacking, AI-Powered Bug Hunting, and Self-Improving Claude Workflows
Episode 165: In this episode of Critical Thinking - Bug Bounty Podcast Justin recaps his Zero Trust World experience, before we dive into Permissions issues client-side bugs, New Hardware Hacking Classes, and using AI to hack.
Follow us on twitter at: https://x.com/ctbbpodcast
Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]
Shoutout to YTCracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater, rez0 and gr3pme on X:
Critical Research Lab:
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
You can also find some hacker swag at https://ctbb.show/merch!
Today's Sponsor: Check out ThreatLocker Ringfencing
https://www.criticalthinkingpodcast.io/tl-rf
====== Resources ======
bbscope Update
https://x.com/sw33tLie/status/2029344643154919720
Matt Brown's Youtube Channel
https://www.youtube.com/channel/UC3VDCeZYZH7mCihtMVHqppw
Matt's Twitter:
MCP server for HackerOne to search reports
https://x.com/OriginalSicksec/status/2029503063095124461?s=20
Caido Skills
https://github.com/caido/skills
The Agentic Hacking Era: Ramblings and a Tool
https://josephthacker.com/hacking/2026/03/06/the-agentic-hacking-era.html
Announcing AI-driven Caido
https://caido.io/blog/2026-03-06-caido-skill
====== Timestamps ======
(00:00:00) Introduction
(00:06:23) bbscope report dumping & Matt Brown Training
(00:13:10) MCP server for HackerOne to search reports & protobuff success
(00:24:24) Hacking Mics with Permissions issues client-side bugs
(00:27:26) Can AI Hack things?
12 March 2026, 9:00 am - More Episodes? Get the App