Critical Thinking - Bug Bounty Podcast Podcast By Justin Gardner (Rhynorater) & Joseph Thacker (Rez0) cover art

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

By: Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
Listen for free

About this listen

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
Episodes
  • Episode 125: How to Win Live Hacking Events
    Jun 5 2025

    Episode 125: In this episode of Critical Thinking - Bug Bounty Podcast Justin shares insights on how to succeed at live hacking events. We cover pre-event preparations, challenges of collaboration, on-site strategies, and the importance of maintaining a healthy mindset throughout the entire process.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    ====== This Week in Bug Bounty ======

    Decathlon Public Bug Bounty Program on YesWeHack

    ====== Resources ======

    The Ultimate Double-Clickjacking PoC

    Grafana Full read SSRF and Account Takeover: CVE-2025-4123

    Grafana CVE-2025-4123 Exploit

    What I learned from my first 100 HackerOne Reports

    Root for your friends

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:02:30) The Ultimate Double-Clickjacking PoC, Grafana CVE, & Evan Connelly's first 100 bugs

    (00:10:23) How to win at Live Hacking Events

    (00:11:53) Pre-event

    (00:11:45) Scope Call

    (00:33:11) Dupe window Ends

    (00:36:00) Onsite & and Day of Event

    (00:42:46) Don't define your identity on the outcome

    Show more Show less
    47 mins
  • Episode 124: Bug Bounty Lifestyle = Less Hacking Time?
    May 29 2025

    Episode 124: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph cover some news from around the community, hitting on Joseph’s Anthropic safety testing, Justin’s guest appearance on For Crying Out Cloud, and several fascinating tweets. Then they have a quick Full-time Bug Bounty check-in.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today’s Sponsor - ThreatLocker Web Control

    https://www.criticalthinkingpodcast.io/tl-webcontrol

    ====== This Week in Bug Bounty ======

    Louis Vuitton Public Bug Bounty Program

    CVE-2025-47934 was discovered on one of our Bug Bounty program : OpenPGP.js

    Stored XSS in File Upload Leads to Privilege Escalation and Full Workspace Takeover

    ====== Resources ======

    Jorian tweet

    Clipjacking: Hacked by copying text - Clickjacking but better

    Crying out Cloud Appearance

    Wiz Research takes 1st place in Pwn2Own AI category

    New XSS vector with image tag

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:10:50) Supabase

    (00:13:47) Tweet-research from Jorian and Wyatt Walls.

    (00:20:24) Anthropic safety testing challenge & Wiz Podcast guest appearance

    (00:27:44) New XSS vector, Google i/o, and coding agents

    (00:35:48) Full Time Bug Bounty

    Show more Show less
    45 mins
  • Episode 123: Hacking AI Series: Vulnus ex Machina - Part 2
    May 22 2025

    Episode 123: In this episode of Critical Thinking - Bug Bounty Podcast we’re back with part 2 of Rez0’s miniseries. Today we talk about mastering Prompt Injection, taxonomy of impact, and both triggering traditional Vulns and exploiting AI-specific features.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today’s Sponsor - ThreatLocker User Store

    https://www.criticalthinkingpodcast.io

    /tl-userstore

    ====== This Week in Bug Bounty ======

    Earning a HackerOne 2025 Live Hacking Invite

    https://www.hackerone.com/blog/earning-hackerone-2025-live-hacking-invite

    HTTP header hacks: basic and advanced exploit techniques explored

    https://www.yeswehack.com/learn-bug-bounty/http-header-exploitation

    ====== Resources ======

    Grep.app

    https://vercel.com/blog/migrating-grep-from-create-react-app-to-next-js

    Gemini 2.5 Pro prompt leak

    https://x.com/elder_plinius/status/1913734789544214841

    Pliny's CL4R1T4S

    https://github.com/elder-plinius/CL4R1T4S

    O3

    https://x.com/pdstat/status/1913701997141803329

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:05:25) Grep.app, O3, and Gemini 2.5 Pro prompt leak

    (00:11:09) Delivery and impactful action

    (00:20:44) Mastering Prompt Injection

    (00:30:36) Traditional vulns in Tool Calls, and AI Apps

    (00:37:32) Exploiting AI specific features

    Show more Show less
    44 mins
adbl_web_global_use_to_activate_webcro805_stickypopup
All stars
Most relevant  
as someone who is still very new to the industry, I like listening to this podcast as I find the information very useful

great information

Something went wrong. Please try again in a few minutes.