Critical Thinking - Bug Bounty Podcast Podcast By Justin Gardner (Rhynorater) & Joseph Thacker (Rez0) cover art

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

By: Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
Listen for free

About this listen

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
Episodes
  • Episode 129: Is this how Bug Bounty Ends?
    Jul 3 2025

    Episode 129: In this episode of Critical Thinking - Bug Bounty Podcast we chat about the future of hack bots and human-AI collaboration, the challenges posed by tokenization, and the need for cybersecurity professionals to adapt to the evolving landscape of hacking in the age of AI

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    ====== This Week in Bug Bounty ======

    Improper error handling in async cryptographic operations crashes process

    https://hackerone.com/reports/2817648

    Recon Series #6: Excavating hidden artifacts with Wayback Machine

    https://www.yeswehack.com/learn-bug-bounty/recon-wayback-machine-web-archive

    ====== Resources ======

    This is How They Tell Me Bug Bounty Ends

    https://josephthacker.com/hacking/2025/06/09/this-is-how-they-tell-me-bug-bounty-ends.html

    Welcome, Hackbots: How AI Is Shaping the Future of Vulnerability Discovery

    https://www.hackerone.com/blog/welcome-hackbots-how-ai-shaping-future-vulnerability-discovery

    Glitch Token

    https://www.youtube.com/watch?v=WO2X3oZEJOA

    Conducting smarter intelligences than me: new orchestras

    https://southbridge-research.notion.site/conducting-smarter-intelligences-than-me

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:04:05) Is this how Bug Bounty Ends?

    (00:11:14) Hackbots and handling leads

    (00:20:50) Hacker chain of thought & Tokenization

    (00:32:54) Context Engineering

    Show more Show less
    36 mins
  • Episode 128: New Research in Blind SSRF and Self-XSS, and How to Architect Source-code Review AI Bots
    Jun 26 2025

    Episode 128: In this episode of Critical Thinking - Bug Bounty Podcast we talking Blind SSRF and Self-XSS, as well as Reversing massive minified JS with AI and a wild Google Logo Ligature Bug

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater and Rez0 on Twitter:

    https://x.com/Rhynorater

    https://x.com/rez0__

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today's Sponsor: ThreatLocker - Patch Management

    ====== This Week in Bug Bounty ======

    BitK's "Payload plz" challenge at LeHack

    ====== Resources ======

    Make Self-XSS Great Again

    Novel SSRF Technique Involving HTTP Redirect Loops

    Surf - Escalate your SSRF vulnerabilities on Modern Cloud Environments

    Gecko: Intent to prototype: Framebusting Intervention

    Conducting smarter intelligences than me: new orchestras

    Mandark

    Lumentis

    jscollab

    Google Logo Ligature Bug

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:03:55) Self-XSS and credentialless iframe

    (00:16:50) Novel SSRF Technique Involving HTTP Redirect Loops

    (00:25:02) Framebusting

    (00:29:13) Reversing massive minified JS with AI

    (00:53:12) Google Logo Ligature Bug

    Show more Show less
    58 mins
  • Episode 127: Drama, PDF as JS Chaos, Bounty Profile Apps, And More
    Jun 19 2025
    Episode 127: In this episode of Critical Thinking - Bug Bounty Podcast we address some recent bug bounty controversy before jumping into a slew of news itemsFollow us on XShoutout to YTCracker for the awesome intro music!Today's Sponsor: Adobe====== This Week In Bug Bounty ======Hackers Guide to Google dorkingYesWeCaidoNew Dojo ChallengeSmart Contract BB tipsRed Team AAS====== Resources ======DisclosedPDF csp bypassBypassing File Upload Restrictions To Exploit Client-Side Path TraversalOBS WebSocket to RCETime in a bottle (or knapsack)How to Differentiate Yourself as a Bug Bounty HunterDisclosed. Onlinehacked-in‘EchoLeak’Piloting Edge CopilotNewtownerTips for agent promptingFirefox XSS vectorsTweet from Masato KinugawaChrome debug() function
    Show more Show less
    1 hr and 7 mins
All stars
Most relevant  
as someone who is still very new to the industry, I like listening to this podcast as I find the information very useful

great information

Something went wrong. Please try again in a few minutes.