Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS

February 5, 2026·45 min·4 clips
A misconfiguration in Cloudflare allowed attackers to bypass all customer-configured WAF rules using a simple path traversal.
The hosts discuss recent bug bounty research, including a Cloudflare zero-day WAF bypass, SSRF/XSS via email unsubscribe headers, a Heroku Postgres superuser vulnerability, parser discrepancies for XSS, and AI magic string attacks. They also share tips on bonus swag from Google and Adobe.

As heard by us

A loose hacker conversation finds real security stakes in the hidden functions behind managed cloud services.

Cloud security research gives this Critical Thinking episode a clear center of gravity. After a looser opening around an Adobe bounty promotion and updates on Cloudbot, OpenClaw, and Cloud Code, the hosts settle into the stronger thread: privileged accounts that managed cloud…

Read the full review in PlayNext →

Why you'd press play

Want a closer look at how overwriting a database function can turn a managed-service superuser into a privilege-escalation path?

Read the full recommendation in PlayNext →
Listen to the show on