Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

173 episodes listed below

Listen to the show on

PRESS PLAY

Find your next episode

All episodes

In their own words

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

As heard by us

Based on 6 episodes we listened to · September 2026

Detailed conversations make bug discovery, impact assessment, and reporting methodology legible from a working researcher's point of view.

Critical Thinking - Bug Bounty Podcast treats security research as work that can be examined, questioned, and improved. The conversations move between bug reports, reward decisions, testing methodology, and the technical mechanics behind an exploit.

Read our full review in PlayNext →

Why you'd press play

The world's dumbest fuzzer sounds pretty smart when you're stuck on a bug.

Press play if you want

  • to understand why your Google Cloud finding might earn less when it depends on an unlikely customer setup
  • to hear how a crude IOCTL fuzzer can help you find which handlers are reachable
Read the full recommendation in PlayNext →

Talks about

Best episodes of Critical Thinking - Bug Bounty Podcast

Short reviews from the PlayNext desk, based on the episodes we processed.

Episode 167: Stealing Bugs with Valeriy ShevchenkoMar 26, 2026

A grounded bug bounty conversation about preparation, speed, and knowing when to step away.

This episode frames bug bounty success as something less glamorous, and more useful, than a sudden flash of technical genius. It starts with a sharp joke about stolen reports and borrowed credit, then settles into the practical rhythm behind faster, cleaner submissions: prepare…

Episode 166: Rez0’s Top Claude Skill Secrets Mar 19, 2026

A grounded look at when an AI tool's freedom helps a hacker, and when structure keeps the work honest.

The episode treats AI-assisted hacking less as a novelty than as a workflow design problem: how much freedom a tool should have while mapping a client-side attack surface.

Episode 162: HackerOne Training AI on Bug Bounty Data?Feb 19, 2026

A bug bounty trust debate turns AI-data anxiety into a practical question of disclosure and escalation.

The episode centers on a live trust issue in bug bounty work: how researchers should respond when they worry submitted techniques or reports could be used by AI systems.

Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSSFeb 5, 2026

A loose hacker conversation finds real security stakes in the hidden functions behind managed cloud services.

Cloud security research gives this Critical Thinking episode a clear center of gravity. After a looser opening around an Adobe bounty promotion and updates on Cloudbot, OpenClaw, and Cloud Code, the hosts settle into the stronger thread: privileged accounts that managed cloud…

Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby HopkinsJan 29, 2026

A practical bug bounty episode about cloud targets, report quality, and how rewards are decided.

The episode stays focused on the bug bounty details that matter most in practice: making reports easier to reproduce, understanding how cloud configuration shapes what researchers can test, and seeing how an unusual setup can change the reward path.

Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side BugsJan 22, 2026

A charity hack-along recap becomes a clear browser-security lesson on null event sources and loose comparisons.

This single-episode review turns a charity hack-along recap into a focused lesson on how live hacking can build a working memory for bugs, browser behavior, and researcher techniques.

Episode 152: GeminiJack and Agentic Security with Sasi LeviDec 11, 2025

A practical bug bounty conversation with clear process detail and a career story rooted in security work.

A practical episode that starts with ThreatLocker elevation control and then moves into Sasi Levi's path through software engineering, R and D, and late-night bug bounty work.

Episode 151: Client-side Advanced TopicsDec 4, 2025

A browser-security discussion that moves from ThreatLocker elevation control into null-origin iframes, `postMessage`, and MessagePort handling.

This episode starts with a practical ThreatLocker detour, then moves into client-side edge cases around null-origin iframes, `postMessage`, and MessagePort handling.

Podcasts like Critical Thinking - Bug Bounty Podcast

  • Security Now (Audio)TWiT

    Patient cybersecurity analysis with practical teeth.

  • Malicious LifeMalicious Life

    Deeply researched narrative dives into hacking history and cyber-law cases, hosted by Ran Levi.

  • Click Here

    Reported narratives on hackers, spyware, and data crimes from Dina Temple-Raston.

  • Hacking HumansN2K Networks

    Dave, Joe, and Maria break down phishing kits, deepfakes, and social-engineering scams weekly.

  • The Privacy AdvisorJedidiah Bracy, IAPP Editorial Director

    IAPP's Jedidiah Bracy interviews the regulators and lawyers writing privacy and AI law.

  • The CyberWireAlan Geason

    A daily cybersecurity briefing hosted by Dave Bittner, pairing breaking incidents with a guest interview.

Episodes

  1. 1

    Episode 146: Hacking Horror Stories

    Hidden gem

    Critical Thinking opens with spooky energy and heads straight into hacker war stories.

    ·1h 51m·5 clips
  2. 2

    Episode 169: Attacking OAuth 2.1

    ·30m
  3. 3

    Episode 156: Chill AMA from bugbounty.forum

    Hidden gem

    Critical Thinking - Bug Bounty Podcast Episode 156 centers on an AMA from bugbounty.forum, with questions about AI agents, live hacking events, bug value, and getting started.

    ·1h 23m
  4. 4

    Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

    Hidden gem

    Critical Thinking - Bug Bounty Podcast episode 158 centers on a 10-hour charity hack-along in the CTPB Discord, with five people rotating through two-hour blocks and live narration proving much harder than expected.

    ·59m·3 clips
  5. 5

    Episode 165: Protobuf Hacking, AI-Powered Bug Hunting, and Self-Improving Claude Workflows

    Hidden gem

    Justin and Richard spend much of this episode on AI-assisted bug hunting, including a Kaido workflow for decoding protobuf-encoded parameters and a discussion of Claude's growing ability to host and deploy projects.

    ·44m·2 clips
  6. 6

    Episode 163: Best Technical Takeaways from Portswigger Top 10 2025

    Hidden gem

    Critical Thinking - Bug Bounty Podcast Episode 163 covers PortSwigger Top 10 2025 research, starting with parser differentials that let JavaScript, Erlang, and Java interpret duplicate keys, double Authorization headers, and YAML tags differently.

    ·1h 8m·4 clips
  7. 7

    Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil

    Hidden gem

    Critical Thinking - Bug Bounty Podcast Episode 161 opens with a Gemini exploit chain that turns a user's 2FA code into DTMF tones and calls it out over a phone line.

    ·25m·1 clip
  8. 8

    Episode 140: Crit Research Lab Update & Client-Side Tricks Galore

    Hidden gem

    Critical Thinking - Bug Bounty Podcast Episode 140 centers on Jorian's article, "Exploiting Web Workers XSS with Blobs," and on a new research lab submission model at ctbb.show.

    ·58m·3 clips
  9. 9

    Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND

    Hidden gem

    Tommy DeVoss explains how a Yahoo SSRF in Las Vegas became an $180,000 payout, with each of 18 reports paying $10,000 and the money funding a Nissan GTR.

    ·1h 12m·4 clips
  10. 10

    Episode 157: Crushing Pwn2Own & H1 with Kernel Driver Exploits

    Hidden gem

    Critical Thinking - Bug Bounty Podcast episode 157 centers on Enrique Hyperdude and CVE-2025-2742, a heap overflow in MediaTek kernel drivers inside a Netgear router.

    ·1h 35m·5 clips
  11. 11

    Episode 155: 2025 Hacker Stats & 2026 Goals

    Hidden gem

    Critical Thinking - Bug Bounty Podcast Episode 155 centers on 2025 hacker stats, 2026 goals, and the realities of full-time bug bounty work.

    ·1h 32m·5 clips
  12. 12

    Episode 147: Stupid Simple Hacking Workflow Tips

    Hidden gem

    Critical Thinking - Bug Bounty Podcast Episode 147 centers on Hugo and Justin trading workflow shortcuts for faster bug bounty work, from Kaido command-palette encodings to Chrome DevTools' Edit as HTML.

    ·59m·4 clips
  13. 13

    Episode 168: XSSDoctor - Client-side Path Traversal Research

    ·1h 36m
  14. 14

    Episode 149: DEFCON Debrief: AI Vulns, Unicode Weirdness, and Wild Vulnerability Chains

    Hidden gem

    Critical Thinking opens with its usual community housekeeping.

    ·1h 3m·4 clips
  15. 15

    Episode 153: Hacking the Robots of the Future: Hardware, AI, and Bug Bounties with Matt Brown

    Hidden gem

    The episode opens with a pitch for the Critical Thinkers tier in the CTV Discord before Matt Brown joins the conversation.

    ·1h 17m·4 clips
  16. 16

    Episode 145: Gr3pme's Secret: Bug Bounty Note Taking Methodology

    Hidden gem

    Brandon lays out a Notion-based note-taking system for long-term bug bounty work, starting with target tech stack, third-party components, and a “brainstorming / risks” section.

    ·28m·1 clip
  17. 17

    Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins

    Hidden gem

    The episode opens with a conference promo, then settles into a week-in-bug-bounty conversation about cloud research.

    ·1h 47m·5 clips
  18. 18

    Episode 141: Hacking the Pod - Google Docs 0-day & React CreateElement Exploits with Nick Copi (7urb0)

    Hidden gem

    The episode opens with its usual housekeeping, including a sponsor read about ThreatLocker DAC and a quick bit of banter with Nick, also known as Turbo.

    ·1h 24m·5 clips
  19. 19

    Episode 154: Starting a Pentesting Company on Top of Bug Bounty

    Hidden gem

    Critical Thinking - Bug Bounty Podcast Episode 154 focuses on starting a pentesting company on top of bug bounty, with the hosts comparing bug bounty income volatility to the steadier cash flow of contract pen tests.

    ·41m
  20. 20

    Episode 170: Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways

    Two hackers discuss their experiences at recent live hacking events and share insights on bug bounty techniques.

    Apr 16, 2026·33m
  21. 21

    Episode 167: Stealing Bugs with Valeriy Shevchenko

    Hidden gem

    Episode 167 features a conversation between Jason and Valeriy Shevchenko, a highly-ranked HackerOne bug bounty hunter (98th percentile impact).

    Mar 26, 2026·52m·1 clip
  22. 22

    Episode 166: Rez0’s Top Claude Skill Secrets

    Hidden gem

    Critical Thinking - Bug Bounty Podcast episode 166 centers on Rez0's methods for using Claude skills in bug bounty work, including custom VPS setup, hidden techniques, and tools like Kaido.

    Mar 19, 2026·53m·3 clips
  23. 23

    Episode 162: HackerOne Training AI on Bug Bounty Data?

    Feb 19, 2026·53m·2 clips
  24. 24

    Episode 160: Cloudflare Zero-days & Mail Unsubscribing for XSS

    The hosts discuss recent bug bounty research, including a Cloudflare zero-day WAF bypass, SSRF/XSS via email unsubscribe headers, a Heroku Postgres superuser vulnerability, parser discrepancies for XSS, and AI magic string attacks.

    Feb 5, 2026·45m·4 clips
  25. 25

    Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins

    Hidden gem

    Brandon Grett discusses AI red teaming terminology with HackerOne experts Rezo and Luke Stevens, clarifying industry confusion.

    Jan 29, 2026·1h 47m·1 clip
  26. 26

    Episode 158: 10hr Marathon Hack-Along Recap + $300k Client-side Bugs

    Hidden gem

    Technical security podcast discussing 10-hour charity hack-along event involving five security researchers.

    Jan 22, 2026·59m
  27. 27

    Episode 152: GeminiJack and Agentic Security with Sasi Levi

    Hidden gem

    This Critical Thinking - Bug Bounty Podcast episode centers on Sasi Levi's Vertex AI and Gemini Enterprise research, where a single prompt could pull Gmail, Google Docs, spreadsheets, and calendar data from workspace sources.

    Dec 11, 2025·1h 22m·5 clips
  28. 28

    Episode 151: Client-side Advanced Topics

    This episode dives into advanced client-side hacking topics, covering PostMessage vulnerabilities, iframe sandboxing tricks, and URL parsing bugs.

    Dec 4, 2025·1h 7m·6 clips
  29. 29

    Episode 150: ASP.NET MVC Patterns, Popping Oracle Identity, and Esoteric Subdomain Enumeration

    I love it when you pop a vuln quick - that's the opposite of imposter syndrome

    Nov 27, 2025·57m·5 clips
  30. 30

    Episode 148: MCP Hacking Guide

    Hidden gem

    Episode 148 of Critical Thinking - Bug Bounty Podcast is a solo Model Context Protocol deep dive after both co-hosts were sick or traveling.

    Nov 13, 2025·32m·2 clips
  31. 31

    Episode 144: Google’s Top AI Hackers: Busfactor and Monke

    Hidden gem

    Critical Thinking - Bug Bounty Podcast Episode 144 centers on Bus Factor and Kieran describing how they collaborated at a Google live hacking event in Mexico and finished second overall.

    Oct 16, 2025·53m·3 clips
  32. 32

    Episode 143: New Cohost + Client-Side Gadgets, LHE Meta — Instant Global Admin in Entra!

    Hidden gem

    Co-hosts Justin and Brandon discuss live hacking event strategy, competitive bug bounty hunting, and advanced exploitation techniques.

    Oct 9, 2025·1h 4m
  33. 33

    Episode 142: Gr3pme's Full-Time Hunting Journey Update, Insane AI research, And Some Light News

    Oct 2, 2025·55m
  34. 34

    Episode 139: James Kettle - Pwning in Prod & How to do Web Security Research

    Sep 11, 2025·2h 22m
  35. 35

    Episode 138: Caido Tools and Workflows

    This episode covers bug bounty tips, AI red teaming CTF, and a Ruby LFI challenge.

    Sep 4, 2025·23m
  36. 36

    Episode 137: How We Do AI-Assisted Whitebox Review, New CSPT Gadgets, and Tools from SLCyber

    A podcast episode discussing recent bug bounty news, including a high-paying jailbreak bounty and a Mozilla VPN RCE vulnerability, with a focus on AI-assisted source code review.

    Aug 28, 2025·49m
  37. 37

    Episode 136: Hacking Cluely, AI Prod Sec, and How To Not Get Sued with Jack Cable

    A technical podcast discussing bug bounty tips, hacking techniques, and a sponsor segment about an EDR tool.

    Aug 21, 2025·51m
  38. 38

    Episode 135: Akamai's Ryan Barnett on WAFs, Unicode Confusables, and Triage Stories

    A technical podcast for hackers discussing bug bounty tips, hacking techniques, and a recommendation for Threat Locker's EDR tool.

    Aug 14, 2025·1h 26m
  39. 39

    Episode 134: XBOW - AI Hacking Agent and Human in the Loop with Diego Djurado

    A podcast episode discussing bug bounty tips, zero trust innovations, and a live hacking event at NullCon Berlin.

    Aug 4, 2025·1h 54m
  40. 40

    Episode 133: Building Hacker Communities - Bug Bounty Village, getDisclosed, and the LHE Squad

    Jul 31, 2025·1h 16m
  41. 41

    Episode 132: Archive Testing Methodology with Mathias Karlsson

    Jul 24, 2025·1h 50m
  42. 42

    Episode 131: SL Cyber Writeups, Bug Bounty Metastrategy, and Orphaned Github Commits

    Jul 17, 2025·51m
  43. 43

    Episode 130: Minecraft Hacks to Google Hacking Star - Valentino

    Jul 10, 2025·1h 8m
  44. 44

    Episode 129: Is this how Bug Bounty Ends?

    Jul 3, 2025·36m
  45. 45

    Episode 128: New Research in Blind SSRF and Self-XSS, and How to Architect Source-code Review AI Bots

    Jun 26, 2025·58m
  46. 46

    Episode 127: Drama, PDF as JS Chaos, Bounty Profile Apps, And More

    Jun 19, 2025·1h 7m
  47. 47

    Episode 126: Hacking AI Series: Vulnus ex Machina - Part 3

    Jun 12, 2025·39m
  48. 48

    Episode 125: How to Win Live Hacking Events

    Jun 5, 2025·47m
  49. 49

    Episode 124: Bug Bounty Lifestyle = Less Hacking Time?

    May 29, 2025·45m
  50. 50

    Episode 123: Hacking AI Series: Vulnus ex Machina - Part 2

    May 22, 2025·44m
  51. 51

    Episode 122: We Won Google's AI Hacking Event in Tokyo - Main Takeaways

    May 15, 2025·1h 46m
  52. 52

    Episode 121: Slonser’s Image Injection 0-day -> ATO & New Caido Collab Plugin

    May 8, 2025·57m
  53. 53

    Episode 120: SpaceRaccoon - From Day Zero to Zero Day

    May 1, 2025·1h 37m
  54. 54

    Episode 119: Abusing Iframes from a client-side hacker

    Apr 17, 2025·34m
  55. 55

    Episode 118: Hacking Happy Hour: 0days on Tap and SQLi Shots

    Apr 10, 2025·58m
  56. 56

    Episode 117: Hacking AI Series: Vulnus ex Machina - Part 1

    Apr 3, 2025·32m
  57. 57

    Episode 116: Auth Bypasses and Google VRP Writeups

    Mar 27, 2025·27m
  58. 58

    Episode 115: Mentee to Career Hacker - Mokusou (So Sakaguchi)

    Mar 20, 2025·1h 41m
  59. 59

    Episode 114: Single Page Application Hacking Playbook

    Mar 13, 2025·1h 22m
  60. 60

    Episode 113: Best Technical Takeaways from Portswigger Top 10 2024

    Mar 6, 2025·1h 29m
  61. 61

    Episode 112: Interview with Ciarán Cotter (MonkeHack) - Critical Lab Researcher and Full-time Hunter

    A hacker discusses three bugs, starting with a client-side takeover via post message on a public program.

    Feb 27, 2025·1h 8m
  62. 62

    Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

    Feb 20, 2025·1h 49m
  63. 63

    Episode 110: Oauth Gadget Correlation and Common Attacks

    Feb 13, 2025·50m
  64. 64

    Episode 109: Creative Recon - Alternative Techniques

    Feb 6, 2025·1h 2m
  65. 65

    Episode 108: How to Hack Salesforce, ServiceNow, and Other SaaS Products With Aaron Costello

    Jan 30, 2025·1h 31m
  66. 66

    Episode 107: Bypassing Cross-Origin Browser Headers

    Jan 23, 2025·1h 6m
  67. 67

    Episode 106: Announcing our new cohost...

    Jan 16, 2025·58m
  68. 68

    Episode 105: Best Critical Thinking Moments from 2024

    Jan 9, 2025·2h 18m
  69. 69

    Episode 104: 2024 Hacker Stats & 2025 Goals

    Jan 2, 2025·29m
  70. 70

    Episode 103: Getting ANSI about Unicode Normalization

    Dec 26, 2024·1h 1m
  71. 71

    Episode 102: Building Web Hacking Micro Agents with Jason Haddix

    The hosts discuss using AI micro agents for hacking, including obfuscation bots and specific tools like Acquisition Finder GPT and Subdomain Doctor.

    Dec 19, 2024·1h 3m
  72. 72

    Episode 101: CTBB Hijacked: Rez0__ on AI Attack Vectors with Johann Rehberger

    A technical podcast episode discussing bug bounty tips, elevation control with ThreatLocker, and an interview with a prolific AI hacker about prompt injection.

    Dec 12, 2024·51m
  73. 73

    Ep 100 - 8 Fav Bugs of 2024, Farewell Joel, Hello Shift - Cursor of Hacking

    Dec 5, 2024·1h 42m
  74. 74

    Episode 99: Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty

    Nov 28, 2024·1h 43m
  75. 75

    Episode 98: Team 82 Sharon Brizinov - The Live Hacking Polymath

    Nov 21, 2024·1h 44m
  76. 76

    Episode 97: Bcrypt Hash Input Truncation & Mobile Device Threat Modeling

    Nov 14, 2024·53m
  77. 77

    Episode 96: Cookies & Caching with MatanBer

    This episode discusses converting partial cookie injections into full ones and other cookie quirks, along with caching write-ups from a CTF.

    Nov 7, 2024·49m
  78. 78

    Episode 95: Attacking Chrome Extensions with MatanBer - Big Impact on the Client-Side

    Oct 31, 2024·1h 56m
  79. 79

    Episode 94: Zendesk Fiasco & the CTBB Naughty List

    Oct 24, 2024·49m
  80. 80

    Episode 93: A Chat with Dr. Bouman - Life as a Hacker and a Doctor

    Oct 17, 2024·1h 41m
  81. 81

    Episode 92 - SAML XPath Confusion, Chinese DNS Poisoning, and AI Powered 403 Bypasser

    Oct 10, 2024·48m
  82. 82

    Episode 91: Zero to LHE in 9 Months (feat gr3pme)

    Oct 3, 2024·1h 23m
  83. 83

    Episode 90: 5k Clickjacking, Encryption Oracles, and Cursor for PoCs

    Sep 26, 2024·52m
  84. 84

    Episode 89: The Untapped Bug Bounty Landscape of IoT w/ Matt Brown

    Sep 19, 2024·1h 58m
  85. 85

    Episode 88: News, Tools, and Writeups

    Sep 12, 2024·1h 6m
  86. 86

    Episode 87: 'Hacker Wife' Mariah Gardner on Bug Bounty mentality and relationships

    Sep 5, 2024·1h 27m
  87. 87

    Episode 86: The X-Correlation between Frans & RCE - Research Drop

    Aug 29, 2024·42m
  88. 88

    Episode 85: Practical Applications of DEFCON 32 Web Research

    Aug 22, 2024·1h 31m
  89. 89

    Episode 84: 0xLupin & Takeaways from Google's Las Vegas BugSwat

    Aug 15, 2024·27m
  90. 90

    Episode 83: Brainstorming Proxy Plugins

    Aug 8, 2024·55m
  91. 91

    Episode 82: Part-Time Bug Bounty

    Aug 1, 2024·37m
  92. 92

    Episode 81: Crushing Client-Side on Any Scope with MatanBer

    Jul 25, 2024·2h 5m
  93. 93

    Episode 80: Pwn2Own VS H1 Live Hacking Event (feat SinSinology)

    Jul 18, 2024·2h 49m
  94. 94

    Episode 79: The State of CSS Injection - Leaking Text Nodes & HTML Attributes

    Jul 11, 2024·1h 10m
  95. 95

    Episode 78: Less Writing, More Hacking - Reporting Efficiency Techniques

    Jul 4, 2024·1h 6m
  96. 96

    Episode 77: Bug Bounty Mental - Practical Tips for Staying Sharp & Motivated

    Jun 27, 2024·1h 50m
  97. 97

    Episode 76: Match & Replace - HTTP Proxies' Most Underrated Feature

    Jun 20, 2024·1h 35m
  98. 98

    Episode 75: *Rerun* of The OG Bug Bounty King - Frans Rosen

    Jun 13, 2024·2h 45m
  99. 99

    Episode 74: Supply Chain Attack Primer - Popping RCE Without an HTTP Request (feat 0xLupin)

    Jun 6, 2024·1h 38m
  100. 100

    Episode 73: Sandboxed IFrames and WAF Bypasses

    May 30, 2024·31m
  101. 101

    Episode 72: Research TLDRs & Smuggling Payloads in Well Known Data Types

    May 23, 2024·53m
  102. 102

    Episode 71: More VDP Chats & AI Bias Bounty Strats with Keith Hoodlet

    May 16, 2024·1h 45m
  103. 103

    Episode 70: NahamCon and CSP Bypasses Everywhere

    May 9, 2024·43m
  104. 104

    Episode 69: Johan Carlsson - 3 Month Check-in on Full-time Bug Bounty.

    May 2, 2024·1h 49m
  105. 105

    Episode 68: 0-days & HTMX-SS with Mathias

    Apr 25, 2024·1h 4m
  106. 106

    Episode 67: VDPs & Accidental Program VS Hacker Debate Part 2

    Apr 18, 2024·1h 20m
  107. 107

    Episode 66: CDN-CGI Research, Intent To Ship, and Louis Vuitton

    Apr 11, 2024·58m
  108. 108

    Episode 65: Motivation and Methodology with Sam Curry (Zlz)

    Apr 4, 2024·2h 29m
  109. 109

    Episode 64: .NET Remoting, CDN Attack Surface, and Recon vs Main App

    Mar 28, 2024·1h 8m
  110. 110

    Episode 63: JHaddix Returns

    Mar 21, 2024·1h 22m
  111. 111

    Episode 62: Frontend Language Oddities

    Mar 14, 2024·59m
  112. 112

    Episode 61: A Hacker on Wall Street - JR0ch17

    Mar 7, 2024·1h 27m
  113. 113

    Episode 60: Our Take on PortSwigger's Top 10 Web Hacking Techniques of 2023

    Feb 29, 2024·1h 25m
  114. 114

    Episode 59: Bug Bounty Gadget Hunting & Hacker's Intuition

    Feb 22, 2024·1h 39m
  115. 115

    Episode 58: Youssef Sammouda - Client-Side & ATO War Stories

    Feb 15, 2024·1h 55m
  116. 116

    Episode 57: Technical breakdown from Miami Hacking Event - H1-305

    Feb 8, 2024·33m
  117. 117

    Episode 56: Using Data Science to win Bug Bounty - Mayonaise (aka Jon Colston)

    Feb 1, 2024·1h 48m
  118. 118

    Episode 55: Popping WordPress Plugins - Methodology Braindump

    Jan 25, 2024·1h 44m
  119. 119

    Episode 54: White Box Formulas - Vulnerable Coding Patterns

    Jan 18, 2024·1h 13m
  120. 120

    Episode 53: 500k/yr as Full-Time Bug Hunter & Content Creator - Nahamsec

    Jan 11, 2024·1h 41m
  121. 121

    Episode 52: Best Technical Content from Year 1 of CTBB Podcast

    Jan 4, 2024·3h
  122. 122

    Episode 51: Hacker Stats 2023 & 2024 Goals

    Dec 28, 2023·1h 22m
  123. 123

    Episode 50: ­Mathias 'Fall in a well' Karlsson - Bug Bounty Prophet

    Dec 21, 2023·2h 25m
  124. 124

    Episode 49: Getting Live Hacking Event Invites & Bug Bounty Collab with Nagli

    Dec 14, 2023·52m
  125. 125

    Episode 48: MVH, DEFCON Black Badge, Googler - Sam Erb

    Dec 7, 2023·1h 37m
  126. 126

    Episode 47: CSP Research, Iframe Hopping, and Client-side Shenanigans

    Nov 30, 2023·1h 32m
  127. 127

    Episode 46: The SAML Ramble

    Nov 23, 2023·44m
  128. 128

    Episode 45: The OG Bug Bounty King - Frans Rosen

    Nov 16, 2023·2h 37m
  129. 129

    Episode 44: URL Parsing & Auth Bypass Magic

    Nov 9, 2023·1h 11m
  130. 130

    Episode 43: Caido - The Up-And-Coming HTTP Proxy

    Nov 2, 2023·1h 1m
  131. 131

    Episode 42: Renniepak Interview & Intigriti LHE Recap

    Oct 26, 2023·59m
  132. 132

    Episode 41: Mini Masterclass: Attack Vector Ideation

    Oct 19, 2023·17m
  133. 133

    Episode 40: Bug Bounty Mentoring

    Oct 12, 2023·1h 32m
  134. 134

    Episode 39: The Art of Architectures

    Oct 5, 2023·1h 21m
  135. 135

    Episode 38: Mobile Hacking Maestro: Sergey Toshin

    Sep 28, 2023·43m
  136. 136

    Episode 37: Tokyo Hacking & Interview with 0xLupin

    Sep 21, 2023·1h 15m
  137. 137

    Episode 36: Bug Bounty Ethics & CT Exclusive Bug Reports

    Sep 14, 2023·1h 4m
  138. 138

    Episode 35: King of Collaboration: Douglas Day

    Sep 7, 2023·1h 25m
  139. 139

    Episode 34: Program vs Hacker Debate

    Aug 31, 2023·2h 11m
  140. 140

    Episode 33: The Master of Hacker Show&Tell: Inti De Ceukelaire

    Aug 24, 2023·1h 22m
  141. 141

    Episode 32: The Great Write-up Low-down

    Aug 17, 2023·1h 1m
  142. 142

    Episode 31: Alex Chapman - The Man of Many Crits

    Aug 10, 2023·1h 25m
  143. 143

    Episode 30: Recon Legend Shubs - From Burgers to Bounties

    Aug 3, 2023·1h 19m
  144. 144

    Episode 29: Live Episode with Sean Yeoh - Assetnote Engineer

    Jul 27, 2023·1h
  145. 145

    Episode 28: Surfin' with CSRFs

    Jul 20, 2023·1h 18m
  146. 146

    Episode 27: Top 7 Esoteric Web Vulnerabilities

    Jul 13, 2023·1h 20m
  147. 147

    Episode 26: Client-side Quirks & Browser Hacks

    Jul 6, 2023·1h 33m
  148. 148

    Episode 25: 2xMVH & Multi-million dollar hacker Inhibitor181

    Jun 29, 2023·1h 12m
  149. 149

    Episode 24: AI + Hacking with Daniel Miessler and Rez0

    Jun 22, 2023·1h 4m
  150. 150

    Episode 23: Hacker Loadouts

    Jun 15, 2023·1h 15m
  151. 151

    Episode 22: Chipping Away at Hardware Hacking

    Jun 8, 2023·1h 12m
  152. 152

    Episode 22: Chipping Away at Hardware Hacking

    Jun 8, 2023·1h 12m
  153. 153

    Episode 21: Chill Chat with Legendary DoD Hacker Corben Leo

    Jun 1, 2023·1h 14m
  154. 154

    Episode 20: Hacker Brain Hacks - Overcoming Bug Bounty's Mental Tolls

    May 25, 2023·1h 7m
  155. 155

    Episode 19: Audit Code, Earn Bounties (Part 2) + Zip-Snip, Sitecore, and more!

    May 18, 2023·53m
  156. 156

    Episode 18: Audit Code, Earn Bounties

    May 11, 2023·1h 7m
  157. 157

    Episode 17: LA Live Chat with Five Legendary Hackers

    May 4, 2023·47m
  158. 158

    Episode 16: The Hacker's Toolkit

    Apr 20, 2023·1h 17m
  159. 159

    Episode 15: The Israeli Million-Dollar Hacker

    Apr 13, 2023·1h 8m
  160. 160

    Episode 14: Mobile Hacking Dynamic Analysis w/ Frida + Random Hacker Stuff

    Apr 6, 2023·1h 22m
  161. 161

    Episode 13: How to Find a Good BBP + Acropalypse + ZDI

    Mar 30, 2023·1h 16m
  162. 162

    Episode 12: JHaddix on Hacker->Hacker CISO, OG Hacking Techniques, and Crazy Reports

    Mar 23, 2023·1h 47m
  163. 163

    Episode 11: CV$$, Web Cache Deception, and SSTI

    Mar 16, 2023·1h 4m
  164. 164

    Episode 10: The Life of a Full-Time Bug Bounty Hunter + BB News + Reports from Mentees

    Mar 9, 2023·1h 17m
  165. 165

    Episode 9: Headless Browser SSRF & RebindMultiA Tool Release + Web3 Bug

    Mar 2, 2023·1h 9m
  166. 166

    Episode 8: PostMessage Bugs, CSS Injection, and Bug Drops

    Feb 22, 2023·36m
  167. 167

    Episode 7: PortSwigger Top 10, TruffleSecurity Drama, and More!

    Feb 16, 2023·57m
  168. 168

    Episode 6: Mobile Hacking Attack Vectors with Teknogeek (Joel Margolis)

    Feb 9, 2023·1h 39m
  169. 169

    Episode 5: AI Security, Hacking WiFi, the New XSS Hunter, and more

    Feb 2, 2023·53m
  170. 170

    Episode 4: H1-407 Event Madness & Takeaways Part 2 w/ Special Guest Spaceraccoon

    Feb 2, 2023·46m
  171. 171

    Episode 3: H1-407 Event Madness & Takeaways Part 1

    Jan 26, 2023·46m
  172. 172

    Episode 2: Exploit Writing & Automation / Do you need to know how to program to hack?

    Jan 18, 2023·1h 15m
  173. 173

    Episode 1: Introductions, Bug Bounty Reports, and BB Tips

    Jan 10, 2023·56m