• Get the App
  • Moon FM - The Ultimate Podcast App
  • Get the App
Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

  • 26 minutes 30 seconds
    Episode 192: Hackbot Proof-of-Concept Skill Creation

    Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Sponsored by ThreatLocker - Privileged Access Management

    https://www.criticalthinkingpodcast.io/tl-pam


    ====== This Week in Bug Bounty ======

    LHE at Ekoparty, open to all Ekoparty Attendees

    https://www.yeswehack.com/fr/page/live-hacking-event-banco-galicia-yeswehack-ekoparty-2026


    Builders & Breakers | Building Hackbots: Models, Harnesses and Human Expertise with Hamid Kashfi

    https://www.youtube.com/watch?v=MYK9-66qe6w


    ====== Resources ======

    Get Justin’s exclusive masterclass for more information

    https://www.ctbb.show/discord


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:05:33) PoC Creation Goals & Formats

    (00:15:01) Nuts and Bolts of Python & HTML Files

    17 September 2026, 9:00 am
  • 37 minutes 28 seconds
    Episode 191: Rez0s Sick Caching Bug & Local AI vs Subsidized tokens

    Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    ====== This Week in Bug Bounty ======

    How to use Codex for Bug Bounty research: explore broadly, validate rigorously

    https://www.yeswehack.com/learn-bug-bounty/llm-series-codex


    ====== Resources ======

    Herdr

    https://herdr.dev/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:02:43) Rez0's Sick Caching Bug

    (00:11:38) Hackbot Scale & Hardware Spend

    (00:19:16) Stretching your Subscriptions

    (00:27:53) Herdr.dev & LHE's with Total Bounty Pools

    10 September 2026, 1:00 pm
  • 33 minutes 50 seconds
    Episode 190: Hacker Life Coaching & is Rez0 a Claude Shill?

    Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, and where to focus tokens.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Sponsored by ThreatLocker - Privileged Access Management

    https://www.criticalthinkingpodcast.io/tl-pam


    ====== This Week in Bug Bounty ======


    Web Fuzzing for Hackers

    https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers


    When fear no longer holds you back. Interview with Ryan Bonner

    https://www.intigriti.com/blog/business-insights/interview-with-ryan-bonner-roll4combatus


    Steve’s Maturity Framework

    https://x.com/SteveHernandezM/status/2094398761946493107


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:07:10) Focusing your Tokens, Cloud Providers, and Dropping Bounties

    (00:18:30) Amount vs. Impact

    (00:25:42) Ideal Work Day and Focus State

    3 September 2026, 1:00 pm
  • 1 hour 14 minutes
    Episode 189: What Happened to HackerOne with Joel Margolis

    Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab: 

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Guest - Joel Magolis

    https://x.com/0xteknogeek


    ====== This Week in Bug Bounty ======


    Kara Sprague’s Statement:

    “I read Joel’s post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don’t have the full fix yet, but I own it and am also open to working together to find a good solution.” 

    Kara Sprague, CEO, HackerOne 


    Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit plugin

    https://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-code


    Claude Kit

    https://github.com/yeswehack/claude-kit


    ====== Resources ======

    What Happened to HackerOne?

    https://blog.teknogeek.io/posts/what-happened-to-hackerone/


    Watch our episode with Alex Rice

    https://www.youtube.com/watch?v=Pa4wWv_ONjM


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:04:18) The early days: LHE's, Covid, and the rise of AI

    (00:17:20) HSM Program, HAI, and resource allocation

    (00:36:41) Sales Incentivisation

    (00:46:10) AI and Researcher Reports Data

    (00:54:38) How Can H1 Revive its Old Self

    (01:02:40) Triage

    27 August 2026, 9:00 am
  • 41 minutes 47 seconds
    Episode 188: DEFCON 34 Hotel Room Debrief

    Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!


    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!


    Today’s Guests:

    https://x.com/7urb01

    https://x.com/busf4ctor


    ====== This Week in Bug Bounty ======


    YesWeHack is introducing Credits to combat AI slop reports

    https://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:03:45) DEFCON Event Reactions and Takeaways

    (00:12:56) Bus & Turbo Talk Overviews

    (00:21:53) Event Bugs

    20 August 2026, 9:00 am
  • 42 minutes 32 seconds
    Episode 187: Are Live Hacking Events even worth it?

    Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Sponsor: Adobe - Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership!


    ====== This Week in Bug Bounty ======


    Exploiting web cache poisoning vulnerabilities

    https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-web-cache-poisoning-vulnerabilities


    ====== Resources ======

    frontier class vulnerabilities: it gets worse before it (maybe) gets better

    https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:05:41) LHE Vs. AI

    (00:19:27) Hacker Intuition and Gaslighting your Hackbot

    (00:25:49) Resolving Sol 5.6 compaction error & AI memory usage

    (00:37:00) Frontier Class Vulnerabilities



    13 August 2026, 9:00 am
  • 58 minutes 4 seconds
    Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

    Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Sponsored by ThreatLocker - Zero Trust Network Access

    https://www.criticalthinkingpodcast.io/tl-ztna


    ====== Resources ======

    Trend of Bug Bounty Programs

    https://x.com/iangcarroll/status/2082535987633410540


    Next chapter: Restructuring GitHub’s bug bounty program

    https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/


    Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub

    https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854


    Gauntlet Loop

    https://x.com/mattshumer_/status/2081830214384886228


    KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)

    https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066


    Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

    https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:05:40) Bug Bounty Program Trends & Pricing Changes

    (00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6

    (00:29:06) AI Harnessing, prompting, and the Gauntlet Loop

    (00:36:58) LHE vs Hackbot

    (00:43:21) KindaRails2Shell & WP2Shell

    6 August 2026, 9:00 am
  • 1 hour 23 minutes
    Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

    Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Sponsored by ThreatLocker - Zero Trust Network Access

    https://www.criticalthinkingpodcast.io/tl-ztna


    Today’s Guests: 

    Harley Kimball - https://x.com/infinitelogins

    Ariel Garcia - https://x.com/Arl_rose


    ====== This Week in Bug Bounty ======

    Meet YesWeHack at DEFCON 34

    https://www.yeswehack.com/fr/page/yeswehack-defcon-34


    ====== Resources ======

    Bug Bounty Village Agenda 

    https://www.bugbountydefcon.com/agenda-2026


    BBV CTF 2026

    https://www.bugbountydefcon.com/ctf


    Hacker Hangout with TikTok, HackerOne, and Bug Bounty Village

    https://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:04:39) Podcast ATO & ATM Hacks

    (00:17:12) Bug Bounty Village Preview

    (00:31:02) BBV Room Layout and Swag

    (00:42:36) BBV Agenda

    (01:10:57) Harley's Hackbot

    30 July 2026, 9:00 am
  • 1 hour 13 minutes
    Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)

    Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Today’s Guest: https://substack.com/@0xmoose


    ====== This Week in Bug Bounty ======

    How to use Claude Code for Bug Bounty: find fast, validate manually

    https://www.yeswehack.com/learn-bug-bounty/llm-series-claude


    ====== Resources ======

    Signal Over Noise: AI Agents and the Operator Moat

    https://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-the


    FBDL Goes Agentic: AI Agents Can Now Build Your Test Environments

    https://bugbounty.meta.com/blog/fbdl-goes-agentic/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:11:01) Satisfaction for hackbot finds

    (00:19:31) Hackbot Mechanics and Tech Debt

    (00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models

    (00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing

    (01:05:45) Hackbot Load Distribution

    23 July 2026, 9:00 am
  • 1 hour 14 minutes
    Episode 183: PortSwigger Research Impossible XSS SOLVED

    Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labs


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    Sponsored by ThreatLocker - Zero Trust Network Access

    https://www.criticalthinkingpodcast.io/tl-ztna


    ====== This Week in Bug Bounty ======

    How LLMs are changing Bug Bounty Interview series

    https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglo

    https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynorater


    https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare


    ====== Resources ======

    $15k - CSPT to full account takeover, then 2FA bypass via the prototype chain

    https://whoareme.com/blog/cspt-account-takeover-2fa-bypass/


    Two Bypasses for Chrome’s Sanitizer API

    https://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/


    Documenting the impossible: Unexploitable XSS labs

    https://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labs


    GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos

    https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/


    Chaining Razor SSTI into RCE via Reflection and Runtime Strings

    https://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:06:07) AI Features Are Just Tech Features

    (00:20:02) CSPT to full Account Takeover & Other Chains

    (00:35:27) Sanitizer API for Chrome and Firefox

    (00:46:57) Solving PortSwigger's Impossible Lab & GitLost

    (01:01:19) SSTI into RCE via Reflection

    16 July 2026, 9:00 am
  • 39 minutes 5 seconds
    Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission

    Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some GraphQL Hackbot finds, and what AI’s #1 mission should be.


    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: [email protected]

    Shoutout to YTCracker for the awesome intro music!



    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X: 

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme


    Critical Research Lab:

    https://lab.ctbb.show/ 


    Need a Pentest? We just launched CTBB Pentests!

    https://pentest.ctbb.show/


    Hack full time? Check out the Full-Time Hunter’s Guild!

    https://ctbb.show/fthg


    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!


    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.


    You can also find some hacker swag at https://ctbb.show/merch!


    ====== This Week in Bug Bounty ======

    LeHack 2026 Recap

    https://event.yeswehack.com/events/lehack-2026


    Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits

    https://www.yeswehack.com/fr/news/chocopocs-vulnerability-researchers-trojanised-exploits


    Navigating the AI Wave: How We're Keeping Security Research Meaningful

    https://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actions


    ====== Resources ======

    Caido Skills

    https://github.com/caido/skills/pull/22


    Hunting For AWS Cognito Security

    Misconfigurations

    https://www.yassineaboukir.com/talks/NahamConEU2022.pdf


    X MCP

    https://docs.x.com/tools/mcp


    US South Summer Sessions: Hack the Heat

    https://h1.community/events/details/hackerone-us-south-hackerone-club-presents-us-south-summer-sessions-hack-the-heat/


    ====== Timestamps ======

    (00:00:00) Introduction

    (00:08:31) WPM Bug & Wayback to Guest Bearer

    (00:18:42) GraphQL Hackbot Finds, Fable Updates, & AI's #1 Mission

    (00:29:45) MCP, US South H1 Event, & AI Sandbox Escapes

    9 July 2026, 9:00 am
  • More Episodes? Get the App

Discover

  • Featured
  • Top Charts
  • Popular

More

  • Get the App
  • News
  • Setting
  • Privacy Policy
  • Submit Your Podcast

Contact

  • [email protected]
  • Twitter
Your feedback is valuable to us. Should you encounter any bugs, glitches, lack of functionality or other problems, please email us at [email protected] or join where you can talk directly to the dev team.
© MoonFM 2026. All rights reserved.