Interested in going full-time bug bounty? Check out our blueprint!

Videos

July 29, 2025

Free-After-Use or Web Cache Deception?

#hacking #bugbounty #bugbountytips #websecurity #infosec #webcachedeception #cachedeception

View more
July 28, 2025

Nesting Tags to Break Sanitisers... 🍕

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
July 26, 2025

[Hacker x AI] vs. [Hacker + AI]

#hacking #bugbounty #bugbountytips #websecurity #infosec #AIHacking #AISecurity

View more
July 25, 2025

Exploiting fetchLater() with Redirect Chaining

#hacking #bugbounty #bugbountytips #websecurity #infosec #fetchLater

View more
July 24, 2025

Archive Testing Methodology with Mathias Karlsson (Ep.132)

Episode 132: In this episode of Critical Thinking - Bug Bounty Podcast, Justin Gardner is joined by Mathias Karlsson to discuss vulnerabilities associated with archives. They talk about his new tool, Archive Alchemist, and explore topics like the significance of Unicode paths, symlinks, and TAR before they end up talking…

View more
July 22, 2025

Clever Way to Weaponise AI Retrieval Systems

#hacking #bugbounty #bugbountytips #websecurity #infosec #AI #RAG

View more
July 21, 2025

OBS Websockets to RCE Research

#hacking #bugbounty #bugbountytips #websecurity #infosec #websocket #OBS #RCE

View more
July 19, 2025

THIS is How You Bypass IP Allow-lists

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
July 18, 2025

Reverse Engineering JSON Request Bodies with Caido Shift

Using Caido's new AI plugin Shift, it is a breeze to reverse JSON request bodies. #bugbounty #appsec #https #javascript

View more
July 17, 2025

SL Cyber Writeups, Metastrategy & Orphaned Github Commits (Ep. 131)

Episode 131: Christmas in July HACKING STYLE -SL Cyber Writeups, Bug Bounty Metastrategy, and Orphaned Github Commits Episode 131: In this episode of Critical Thinking - Bug Bounty Podcast we're covering Christmas in July with several banger articles from Searchlight Cyber, as well as covering things like Raycast for Windows,…

View more
July 11, 2025

URL Normalization Gone Wrong

#hacking #bugbounty #bugbountytips #websecurity #infosec #SSRF

View more
July 10, 2025

Minecraft Hacks to Google Hacking Star - Valentino (Ep 130)

Episode 130: In this episode of Critical Thinking - Bug Bounty Podcast Justin is joined by Valentino, who shares his journey from hacking Minecraft to becoming a Google hunter. He talks us through several bugs, including an HTML Sanitizer bypass and .NET deserialization, and highlights the hyper creative approaches he…

View more
July 9, 2025

The Ultimate Double-Clickjacking POC

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
July 7, 2025

Sometimes All You Have to do is Ask… And it’s not the first time we say this

#hacking #bugbounty #bugbountytips #websecurity #infosec #LHE

View more
July 6, 2025

Hack, Rest, Reset → Peak Performance

#hacking #bugbounty #bugbountytips #websecurity #infosec #mentalhealth

View more
July 4, 2025

You NEED to See This UUID Trick

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
July 3, 2025

Is this how Bug Bounty Ends (Ep. 129)

Episode 129: Is this how Bug Bounty Ends? Episode 129: In this episode of Critical Thinking - Bug Bounty Podcast we chat about the future of hack bots and human-AI collaboration, the challenges posed by tokenization, and the need for cybersecurity professionals to adapt to the evolving landscape of hacking…

View more
June 30, 2025

This is What Full-Time Bug Bounty REALLY Means

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
June 26, 2025

POC: Embedding Pages → Data Theft

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
June 26, 2025

New Research in Blind SSRF and Self-XSS, and How to Architect Source-code Review AI Bots (Ep. 128)

Episode 128: New Research in Blind SSRF and Self-XSS, and How to Architect Source-code Review AI Bots Episode 128: In this episode of Critical Thinking - Bug Bounty Podcast we talking Blind SSRF and Self-XSS, as well as Reversing massive minified JS with AI and a wild Google Logo Ligature…

View more
June 24, 2025

CSRF → Command Execution in MCP

#hacking #bugbounty #bugbountytips #websecurity #infosec #csrf

View more
June 19, 2025

Drama, PDF as JS Chaos, Bounty Profile Apps, And More (Ep. 127)

Episode 127: In this episode of Critical Thinking - Bug Bounty Podcast we address some recent bug bounty controversy before jumping into a slew of news items, as well as talking about how to hack efficiently and Hackedin vs. Disclosed Online. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas…

View more
June 12, 2025

Hacking AI Series: Vulnus ex Machina - Part 3 (Ep. 126)

Episode 126: Hacking AI Series: Vulnus ex Machina - Part 3 Episode 126: In this episode of Critical Thinking - Bug Bounty Podcast we wrap up Rez0’s AI miniseries ‘Vulnus Ex Machina’. Part 3 includes a showcase of AI Vulns that Rez0 himself has found, and how much they paid…

View more
June 5, 2025

How to Win Live Hacking Events (Ep. 125)

Episode 125: In this episode of Critical Thinking - Bug Bounty Podcast Justin shares insights on how to succeed at live hacking events. We cover pre-event preparations, challenges of collaboration, on-site strategies, and the importance of maintaining a healthy mindset throughout the entire process. Follow us on twitter at: https://x.com/ctbbpodcast…

View more