
Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)
Episode 140: Crit Research Lab Update & Client-Side Tricks Galore
·58 min·3 clips
Jorian's write-up shows how XSS inside a web worker can jump back to the main domain with blobs.
As heard by us
AI-assisted bug hunting, verbose API feedback, and a classic cookie-prefix flaw.
It follows the thread of AI-assisted bug hunting from start to finish, with shift agents and Cloud Code applied to APIs that return far too much detail. That gives the piece a practical edge, and the cookie-prefix vulnerability near the end adds a clear security payoff.
Why you'd press play
Want to let Claude grind through prompt loops while you keep hunting the bug?
Listen to the show on