Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

January 22, 2026·59 min
Technical security podcast discussing 10-hour charity hack-along event involving five security researchers. Hosts (Reso, Richard, XSS Doctor, Buss) analyze key vulnerabilities discovered including post-message race conditions, JavaScript execution throttling workarounds, partial authentication state exploitation across parent-child SaaS applications, and browser permission delegation attacks. Episode balances tactical exploit techniques with broader security principles, emphasizing threat modeling, precondition analysis, and code pattern recognition. Discusses challenges of live-narrating hacking while maintaining technical accuracy and responsible disclosure. Announcement: Zero Trust World Conference March 4-6 Orlando.

As heard by us

A charity hack-along recap becomes a clear browser-security lesson on null event sources and loose comparisons.

This single-episode review turns a charity hack-along recap into a focused lesson on how live hacking can build a working memory for bugs, browser behavior, and researcher techniques.

Read the full review in PlayNext →

Why you'd press play

You want a bug bounty segment where an old postMessage trick makes event.source null and turns browser mechanics into a practical bypass clue.

Read the full recommendation in PlayNext →
Listen to the show on