Interested in going full-time bug bounty? Check out our blueprint!

Episodes

Episode 178: 600k in ~3 months - BruteCat pt 2
June 11, 2026

Episode 178: 600k in ~3 months - BruteCat pt 2

Episode 178: In this episode of Critical Thinking - Bug Bounty Podcast we’re back with BruteCat to finish up our discussion on hacking Google. This week we hit AI. Follow us on twitter at: https://x.com/ctbbpodcast Got any id...

Listen to the Episode
Episode 177: 2x Google RCE with VRP Legend Brutecat
June 4, 2026

Episode 177: 2x Google RCE with VRP Legend Brutecat

Episode 177: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by BruteCat to talk about his journey hacking Google Cloud, Gmail, Youtube, and Google Phone. Follow us on twitter at: https://x.com/ctbbpodc...

Listen to the Episode
Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam)
May 28, 2026

Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam)

Episode 176: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by top Adobe hacker Jim Green to deep-dive AEM. We talk through Sling selectors, Permissions, and how to spot AEM Red Flags. Follow us on twi...

Listen to the Episode
Episode 175: Rhyno’s Hackbot Setup, Sick Bugs, and ZDI Drama
May 21, 2026

Episode 175: Rhyno’s Hackbot Setup, Sick Bugs, and ZDI Drama

Episode 175: In this episode of Critical Thinking - Bug Bounty Podcast we’re comparing Hackbot setups and results. We also talk about some of the recent ZDI drama, as well as the importance of freaking beautiful POCs Follow u...

Listen to the Episode
Episode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.5
May 14, 2026

Episode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.5

Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike. F...

Listen to the Episode
Episode 173: Bug Bounty is Dead and AI Killed it.
May 7, 2026

Episode 173: Bug Bounty is Dead and AI Killed it.

Episode 173: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about the negative effects that AI is having on the Bug Bounty scene as a whole. Is it over, or are we so back? Follow us on twitter at: htt...

Listen to the Episode
Episode 172: Source Code Review Meta Analysis
April 30, 2026

Episode 172: Source Code Review Meta Analysis

Episode 172: In this episode of Critical Thinking - Bug Bounty Podcast trying out a new structure of episode: a Meta Analysis of sorts of many Source Code Review techniques. This episode features tips gathered from Shubs, Raf...

Listen to the Episode
Episode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw Protobuf XSS
April 23, 2026

Episode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw…

Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking ages Follow u...

Listen to the Episode
Episode 170: Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways
April 16, 2026

Episode 170: Claude Code + Tmux, Websockets, and Other Korea LHE Take…

Episode 170: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph their trip to Korea with some quick takeaways from the LHE. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggest...

Listen to the Episode
Episode 169: Attacking OAuth 2.1
April 9, 2026

Episode 169: Attacking OAuth 2.1

Episode 169: In this episode of Critical Thinking - Bug Bounty Podcast gr3pme goes over some of the changes from OAuth 2.0 vs 2.1 and how Hackers can capitalize. Follow us on twitter at: https://x.com/ctbbpodcast Got any idea...

Listen to the Episode
Episode 168: Novel Client-side Path Traversal Research with XSSDoctor
April 2, 2026

Episode 168: Novel Client-side Path Traversal Research with XSSDoctor

Episode 168: In this episode of Critical Thinking - Bug Bounty Podcast we’re getting a visit from the XSS Doctor. Jonathan joins us to go through his Client-side workflow, run labs, and diagnose some bugs live. Follow us on t...

Listen to the Episode
Episode 167: Stealing Bugs with Valeriy Shevchenko
March 26, 2026

Episode 167: Stealing Bugs with Valeriy Shevchenko

Episode 167: In this episode of Critical Thinking - Bug Bounty Podcast we welcome Valeriy Shevchenko to talk about program management, anchor programs, and Theft in Bug Bounty. Follow us on twitter at: https://x.com/ctbbpodca...

Listen to the Episode
Episode 166: Rez0’s Top Claude Skill Secrets
March 19, 2026

Episode 166: Rez0’s Top Claude Skill Secrets

Episode 166: In this episode of Critical Thinking - Bug Bounty Podcast we talk about Rez0’s Claude Skill Secrets, when AI Generated reports fall apart, and agents vs filters. Follow us on twitter at: https://x.com/ctbbpodcast...

Listen to the Episode
Episode 165: Protobuf Hacking, AI-Powered Bug Hunting, and Self-Improving Claude Workflows
March 12, 2026

Episode 165: Protobuf Hacking, AI-Powered Bug Hunting, and Self-Impro…

Episode 165: In this episode of Critical Thinking - Bug Bounty Podcast Justin recaps his Zero Trust World experience, before we dive into Permissions issues client-side bugs, New Hardware Hacking Classes, and using AI to hack...

Listen to the Episode
Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND
March 5, 2026

Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND

Episode 164: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Tommy DeVoss to talk about his origin story, Yahoo bugs, and how Tommy first got Justin into Bug Bounty Follow us on twitter at: htt...

Listen to the Episode
Episode 163: Best Technical Takeaways from Portswigger Top 10 2025
Feb. 26, 2026

Episode 163: Best Technical Takeaways from Portswigger Top 10 2025

Episode 163: In this episode of Critical Thinking - Bug Bounty Podcast It’s that time of year again! We’re looking at the Portswigger Research list of top 10 web hacking techniques of 2025. Follow us on twitter at: https://x....

Listen to the Episode
Episode 162: HackerOne Training AI on Bug Bounty Data?
Feb. 19, 2026

Episode 162: HackerOne Training AI on Bug Bounty Data?

Episode 162: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph sit down with HackerOne Founder & CTO Alex Rice to discuss concerns of Using Hacker Data for AI and decreasing bounties. Follow us on tw...

Listen to the Episode
Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil
Feb. 12, 2026

Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil

Episode 161: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gives us some quick hits regarding CSRF and Cross Consumer Attacks, and also touches on some breaking questions surrounding HackerOne Follow us on ...

Listen to the Episode
Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS
Feb. 5, 2026

Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS

Episode 160: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn. Chat through some news, Including a Cloudflare Zero-day, Turning List-Unsubscribe into an SSRF/XSS Gadget, & Magic String Denial of Se...

Listen to the Episode
Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins
Jan. 29, 2026

Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Da…

Episode 159: In this episode of Critical Thinking - Bug Bounty Podcast we sit down with the Google Cloud VRP Team to deep-dive policy and reward changes, what the panel process looks like, and how to best configure for succes...

Listen to the Episode
Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins
Jan. 29, 2026

Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Da…

Episode 159: In this episode of Critical Thinking - Bug Bounty Podcast we sit down with the Google Cloud VRP Team to deep-dive policy and reward changes, what the panel process looks like, and how to best configure for succes...

Listen to the Episode
Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs
Jan. 22, 2026

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

Episode 158: In this episode of Critical Thinking - Bug Bounty Podcast we talk about our takeaways from the CTBB Charity Hackalong, and then break down some InsertScript POCs, what a $55,000 bug can look like, and if Smart Pe...

Listen to the Episode
Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs
Jan. 22, 2026

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

Episode 158: In this episode of Critical Thinking - Bug Bounty Podcast we talk about our personal takeaways from the CTBB Charity Hackalong, and then break down some InsertScript POCs, what a $55,000 bug can look like, and if...

Listen to the Episode
Episode 157: Crushing Pwn2Own & H1 with Kernel Driver Exploits
Jan. 15, 2026

Episode 157: Crushing Pwn2Own & H1 with Kernel Driver Exploits

Episode 157: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Hypr to talk about hacking Mediatek and his experiences with HackerOne and Pwn2Own Ecosystems. Follow us on twitter at: https://x.com/ctbb...

Listen to the Episode