
Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)
Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS
February 5, 2026·45 min·4 clips
A misconfiguration in Cloudflare allowed attackers to bypass all customer-configured WAF rules using a simple path traversal.
As heard by us
A loose hacker conversation finds real security stakes in the hidden functions behind managed cloud services.
Cloud security research gives this Critical Thinking episode a clear center of gravity. After a looser opening around an Adobe bounty promotion and updates on Cloudbot, OpenClaw, and Cloud Code, the hosts settle into the stronger thread: privileged accounts that managed cloud…
Why you'd press play
Want a closer look at how overwriting a database function can turn a managed-service superuser into a privilege-escalation path?
Listen to the show on