Interested in going full-time bug bounty? Check out our blueprint!

Episodes

Episode 165: Protobuf Hacking, AI-Powered Bug Hunting, and Self-Improving Claude Workflows
March 12, 2026

Episode 165: Protobuf Hacking, AI-Powered Bug Hunting, and Self-Impro…

Episode 165: In this episode of Critical Thinking - Bug Bounty Podcast Justin recaps his Zero Trust World experience, before we dive into Permissions issues client-side bugs, New Hardware Hacking Classes, and using AI to hack...

Listen to the Episode
Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND
March 5, 2026

Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND

Episode 164: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Tommy DeVoss to talk about his origin story, Yahoo bugs, and how Tommy first got Justin into Bug Bounty Follow us on twitter at: htt...

Listen to the Episode
Episode 163: Best Technical Takeaways from Portswigger Top 10 2025
Feb. 26, 2026

Episode 163: Best Technical Takeaways from Portswigger Top 10 2025

Episode 163: In this episode of Critical Thinking - Bug Bounty Podcast It’s that time of year again! We’re looking at the Portswigger Research list of top 10 web hacking techniques of 2025. Follow us on twitter at: https://x....

Listen to the Episode
Episode 162: HackerOne Training AI on Bug Bounty Data?
Feb. 19, 2026

Episode 162: HackerOne Training AI on Bug Bounty Data?

Episode 162: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph sit down with HackerOne Founder & CTO Alex Rice to discuss concerns of Using Hacker Data for AI and decreasing bounties. Follow us on tw...

Listen to the Episode
Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil
Feb. 12, 2026

Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil

Episode 161: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gives us some quick hits regarding CSRF and Cross Consumer Attacks, and also touches on some breaking questions surrounding HackerOne Follow us on ...

Listen to the Episode
Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS
Feb. 5, 2026

Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS

Episode 160: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn. Chat through some news, Including a Cloudflare Zero-day, Turning List-Unsubscribe into an SSRF/XSS Gadget, & Magic String Denial of Se...

Listen to the Episode
Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins
Jan. 29, 2026

Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Da…

Episode 159: In this episode of Critical Thinking - Bug Bounty Podcast we sit down with the Google Cloud VRP Team to deep-dive policy and reward changes, what the panel process looks like, and how to best configure for succes...

Listen to the Episode
Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins
Jan. 29, 2026

Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Da…

Episode 159: In this episode of Critical Thinking - Bug Bounty Podcast we sit down with the Google Cloud VRP Team to deep-dive policy and reward changes, what the panel process looks like, and how to best configure for succes...

Listen to the Episode
Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs
Jan. 22, 2026

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

Episode 158: In this episode of Critical Thinking - Bug Bounty Podcast we talk about our takeaways from the CTBB Charity Hackalong, and then break down some InsertScript POCs, what a $55,000 bug can look like, and if Smart Pe...

Listen to the Episode
Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs
Jan. 22, 2026

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

Episode 158: In this episode of Critical Thinking - Bug Bounty Podcast we talk about our personal takeaways from the CTBB Charity Hackalong, and then break down some InsertScript POCs, what a $55,000 bug can look like, and if...

Listen to the Episode
Episode 157: Crushing Pwn2Own & H1 with Kernel Driver Exploits
Jan. 15, 2026

Episode 157: Crushing Pwn2Own & H1 with Kernel Driver Exploits

Episode 157: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Hypr to talk about hacking Mediatek and his experiences with HackerOne and Pwn2Own Ecosystems. Follow us on twitter at: https://x.com/ctbb...

Listen to the Episode
Episode 156: Chill AMA from bugbounty.forum
Jan. 8, 2026

Episode 156: Chill AMA from bugbounty.forum

Episode 156: In this episode of Critical Thinking - Bug Bounty Podcast we answer some fantastic questions from over at bugbounty.forum Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel fre...

Listen to the Episode
Episode 155: 2025 Hacker Stats & 2026 Goals
Jan. 1, 2026

Episode 155: 2025 Hacker Stats & 2026 Goals

Episode 155: In this episode of Critical Thinking - Bug Bounty Podcast Justin, Joseph, and Brandyn reflect on last year of Bug Bounty, and list their goals and predictions for what 2026 holds. Follow us on twitter at: https:/...

Listen to the Episode
Episode 154: Starting a Pentesting Company on Top of Bug Bounty
Dec. 25, 2025

Episode 154: Starting a Pentesting Company on Top of Bug Bounty

Episode 154: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn talk through the transition from Bug Bounty hunting to Pentesting. We cover diversifying income streams, the challenges of pricing for ...

Listen to the Episode
Episode 153: Hacking the Robots of the Future: Hardware, AI, and Bug Bounties with Matt Brown
Dec. 18, 2025

Episode 153: Hacking the Robots of the Future: Hardware, AI, and Bug …

Episode 153: In this episode of Critical Thinking - Bug Bounty Podcast Matt Brown returns to talk with us about hacking robots, IOT hackbots, and his Zero-to-Hero Hardware Hacking Guide. Follow us on twitter at: https://x.com...

Listen to the Episode
Episode 152: GeminiJack and Agentic Security with Sasi Levi
Dec. 11, 2025

Episode 152: GeminiJack and Agentic Security with Sasi Levi

Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prom...

Listen to the Episode
Episode 151: Client-side Advanced Topics
Dec. 4, 2025

Episode 151: Client-side Advanced Topics

Episode 151: In this episode of Critical Thinking - Bug Bounty Podcast we’re covering Client-side advanced topics. Justin talks Joseph (and us) through Third-Party Cookie Nuances, Iframe Tricks, URL Parsing, and more. Follow ...

Listen to the Episode
Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration
Nov. 27, 2025

Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esote…

Episode 150: In this episode of Critical Thinking - Bug Bounty Podcast we're highlighting some cool news and research, but not before expressing our gratitude to the Hacker community. We are so thankful for you all! Follow us...

Listen to the Episode
Episode 149: DEFCON Debrief: AI Vulns, Unicode Weirdness, and Wild Vulnerability Chains
Nov. 20, 2025

Episode 149: DEFCON Debrief: AI Vulns, Unicode Weirdness, and Wild Vu…

Episode 149: In this episode of Critical Thinking - Bug Bounty Podcast The DEFCON videos are up, and Justin and Joseph talk through some of their favorites. Follow us on X Got any ideas and suggestions? Feel free to send us a...

Listen to the Episode
Episode 148: MCP Hacking Guide
Nov. 13, 2025

Episode 148: MCP Hacking Guide

Episode 148: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us a crash course on Model Context Protocol. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to s...

Listen to the Episode
Episode 147: Stupid, Simple, Hacking Workflow Tips
Nov. 6, 2025

Episode 147: Stupid, Simple, Hacking Workflow Tips

Episode 147: In this episode of Critical Thinking - Bug Bounty Podcast we're talking tips and tricks that help us in hacking that we really should’ve learned sooner. Follow us on twitter at: https://x.com/ctbbpodcast Got any ...

Listen to the Episode
Episode 146: Hacking Horror Stories
Oct. 30, 2025

Episode 146: Hacking Horror Stories

Episode 146: In this episode of Critical Thinking - Bug Bounty Podcast Justin, Joseph, and Brandyn all sit down to celebrate the spooky season by swapping their scariest bug stories. From frightening fails and firings to hack...

Listen to the Episode
Episode 145: Gr3pme's Secret: Bug Bounty Note Taking Methodology
Oct. 23, 2025

Episode 145: Gr3pme's Secret: Bug Bounty Note Taking Methodology

Episode 145: In this episode of Critical Thinking - Bug Bounty Podcast Brandyn lets us in on some of his notetaking tips, including his Templates, Threat Modeling, and ways he uses notes to help with collaboration. Follow us ...

Listen to the Episode
Episode 144: Google’s Top AI Hackers: Busfactor and Monke
Oct. 16, 2025

Episode 144: Google’s Top AI Hackers: Busfactor and Monke

Episode 144: In this episode of Critical Thinking - Bug Bounty Podcast Joseph is joined by Vitor Falcão and Ciarán Cotter to discuss their success at the recent Mexico LHE, as well as their journey and routines in fulltime ha...

Listen to the Episode