Mato
ShowsHow it worksAI talentsFree toolsPricing
Book a demo
ShowsHow it worksAI talentsFree toolsPricingSign in
Mato
Mato

The first generation of AI talents. Live AI media for brands, networks and creators.

ElevenLabs GrantsAWS ActivateGoogle for StartupsNVIDIA Inception Program

Product

  • How it works
  • AI talents
  • Documentation
  • The studio
  • Pricing
  • Embed player
  • Mato MCP
  • Mato Voice
  • Voice Studio
  • Changelog

Company

  • About
  • Vision
  • Partners
  • Affiliates
  • Blog
  • CustomersComing soon
  • CareersComing soon
  • Press kit
  • Contact

Resources

  • Investor overview
  • Free podcast tools
  • Free podcast transcription
  • Podcast ROI calculator
  • API docsComing soon
  • SecurityComing soon
  • StatusComing soon

© 2026 Mato. All rights reserved.

English · Multiple languages available

PrivacyTerms

Live Interview

And why does that matter?

This is how a Mato agent talks. Take the other seat: answer a few and feel it follow the thread.

Try it yourself

Podcast charts

Critical Thinking - Bug Bounty Podcast

Published by Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

  • Technology

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Listen on Apple Podcasts, opens in a new tabMake something like it

On the charts

1 chart placement

Every published chart this podcast appears in, in the snapshot behind this page. Each one links to the chart it came off.

  1. Number 164TechnologyNorway

From the feed

Recent episodes

The latest episodes published to this podcast’s own RSS feed. Titles and descriptions are the publisher’s.

  1. Episode 189: What Happened to HackerOne with Joel Margolis from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Aug 27, 20261 hr 14 min

    Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Guest - Joel Magolis https://x.com/0xteknogeek ====== This Week in Bug Bounty ====== Kara Sprague’s Statement: “I read Joel’s post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don’t have the full fix yet, but I own it and am also open to working together to find a good solution.” Kara Sprague, CEO, HackerOne Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit plugin https://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-code Claude Kit https://github.com/yeswehack/claude-kit ====== Resources ====== What Happened to HackerOne? https://blog.teknogeek.io/posts/what-happened-to-hackerone/ Watch our episode with Alex Rice https://www.youtube.com/watch?v=Pa4wWv_ONjM ====== Timestamps ====== (00:00:00) Introduction (00:04:18) The early days: LHE's, Covid, and the rise of AI (00:17:20) HSM Program, HAI, and resource allocation (00:36:41) Sales Incentivisation (00:46:10) AI and Researcher Reports Data (00:54:38) How Can H1 Revive its Old Self (01:02:40) Triage

  2. Episode 188: DEFCON 34 Hotel Room Debrief from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Aug 20, 202641 min

    Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Sponsor: The Adobe Program is moving to Intigriti! Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership! Today’s Guests: https://x.com/7urb01 https://x.com/busf4ctor ====== This Week in Bug Bounty ====== YesWeHack is introducing Credits to combat AI slop reports https://helpcenter.yeswehack.io/en/articles/711408-yeswehack-credits ====== Timestamps ====== (00:00:00) Introduction (00:03:45) DEFCON Event Reactions and Takeaways (00:12:56) Bus & Turbo Talk Overviews (00:21:53) Event Bugs

  3. Episode 187: Are Live Hacking Events even worth it? from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Aug 13, 202642 min

    Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Sponsor: Adobe - Head to our Discord and type “Ready to Hack Adobe” in the giveaway channel and paste your Intigriti profile for a chance to win a Lifetime CT Membership! ====== This Week in Bug Bounty ====== Exploiting web cache poisoning vulnerabilities https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-web-cache-poisoning-vulnerabilities ====== Resources ====== frontier class vulnerabilities: it gets worse before it (maybe) gets better https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-maybe-gets-better/ ====== Timestamps ====== (00:00:00) Introduction (00:05:41) LHE Vs. AI (00:19:27) Hacker Intuition and Gaslighting your Hackbot (00:25:49) Resolving Sol 5.6 compaction error & AI memory usage (00:37:00) Frontier Class Vulnerabilities

  4. Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty? from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Aug 6, 202658 min

    Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Zero Trust Network Access https://www.criticalthinkingpodcast.io/tl-ztna ====== Resources ====== Trend of Bug Bounty Programs https://x.com/iangcarroll/status/2082535987633410540 Next chapter: Restructuring GitHub’s bug bounty program https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/ Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 Gauntlet Loop https://x.com/mattshumer_/status/2081830214384886228 KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066 Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/ ====== Timestamps ====== (00:00:00) Introduction (00:05:40) Bug Bounty Program Trends & Pricing Changes (00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6 (00:29:06) AI Harnessing, prompting, and the Gauntlet Loop (00:36:58) LHE vs Hackbot (00:43:21) KindaRails2Shell & WP2Shell

  5. Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026 from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jul 30, 20261 hr 23 min

    Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village! Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Zero Trust Network Access https://www.criticalthinkingpodcast.io/tl-ztna Today’s Guests: Harley Kimball - https://x.com/infinitelogins Ariel Garcia - https://x.com/Arl_rose ====== This Week in Bug Bounty ====== Meet YesWeHack at DEFCON 34 https://www.yeswehack.com/fr/page/yeswehack-defcon-34 ====== Resources ====== Bug Bounty Village Agenda https://www.bugbountydefcon.com/agenda-2026 BBV CTF 2026 https://www.bugbountydefcon.com/ctf Hacker Hangout with TikTok, HackerOne, and Bug Bounty Village https://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd ====== Timestamps ====== (00:00:00) Introduction (00:04:39) Podcast ATO & ATM Hacks (00:17:12) Bug Bounty Village Preview (00:31:02) BBV Room Layout and Swag (00:42:36) BBV Agenda (01:10:57) Harley's Hackbot

  6. Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson) from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jul 23, 20261 hr 13 min

    Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Guest: https://substack.com/@0xmoose ====== This Week in Bug Bounty ====== How to use Claude Code for Bug Bounty: find fast, validate manually https://www.yeswehack.com/learn-bug-bounty/llm-series-claude ====== Resources ====== Signal Over Noise: AI Agents and the Operator Moat https://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-the FBDL Goes Agentic: AI Agents Can Now Build Your Test Environments https://bugbounty.meta.com/blog/fbdl-goes-agentic/ ====== Timestamps ====== (00:00:00) Introduction (00:11:01) Satisfaction for hackbot finds (00:19:31) Hackbot Mechanics and Tech Debt (00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models (00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing (01:05:45) Hackbot Load Distribution

  7. Episode 183: PortSwigger Research Impossible XSS SOLVED from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jul 16, 20261 hr 14 min

    Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’s Unexploitable XSS labs Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Zero Trust Network Access https://www.criticalthinkingpodcast.io/tl-ztna ====== This Week in Bug Bounty ====== How LLMs are changing Bug Bounty Interview series https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-aituglo https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-rhynorater https://www.yeswehack.com/fr/community/llms-bug-bounty-interview-icare ====== Resources ====== $15k - CSPT to full account takeover, then 2FA bypass via the prototype chain https://whoareme.com/blog/cspt-account-takeover-2fa-bypass/ Two Bypasses for Chrome’s Sanitizer API https://slcyber.io/research-center/two-bypasses-for-chromes-sanitizer-api/ Documenting the impossible: Unexploitable XSS labs https://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labs GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/ Chaining Razor SSTI into RCE via Reflection and Runtime Strings https://phsi.se/posts/chaining-razor-ssti-into-rce-via-reflection-and-runtime-strings/ ====== Timestamps ====== (00:00:00) Introduction (00:06:07) AI Features Are Just Tech Features (00:20:02) CSPT to full Account Takeover & Other Chains (00:35:27) Sanitizer API for Chrome and Firefox (00:46:57) Solving PortSwigger's Impossible Lab & GitLost (01:01:19) SSTI into RCE via Reflection

  8. Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jul 9, 202639 min

    Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some GraphQL Hackbot finds, and what AI’s #1 mission should be. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! ====== This Week in Bug Bounty ====== LeHack 2026 Recap https://event.yeswehack.com/events/lehack-2026 Don’t eat the ChocoPoCs! How vulnerability researchers were repeatedly targeted by trojanised exploits https://www.yeswehack.com/fr/news/chocopocs-vulnerability-researchers-trojanised-exploits Navigating the AI Wave: How We're Keeping Security Research Meaningful https://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actions ====== Resources ====== Caido Skills https://github.com/caido/skills/pull/22 Hunting For AWS Cognito Security Misconfigurations https://www.yassineaboukir.com/talks/NahamConEU2022.pdf X MCP https://docs.x.com/tools/mcp US South Summer Sessions: Hack the Heat https://h1.community/events/details/hackerone-us-south-hackerone-club-presents-us-south-summer-sessions-hack-the-heat/ ====== Timestamps ====== (00:00:00) Introduction (00:08:31) WPM Bug & Wayback to Guest Bearer (00:18:42) GraphQL Hackbot Finds, Fable Updates, & AI's #1 Mission (00:29:45) MCP, US South H1 Event, & AI Sandbox Escapes

  9. Episode 181: Bug Bounty Singularity from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jul 2, 202652 min

    Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Zero Trust Network Access https://www.criticalthinkingpodcast.io/tl-ztna ====== Resources ====== Are bug bounties cooked? https://hakluke.com/are-bug-bounties-cooked We built a Hackbot https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html ====== Timestamps ====== (00:00:00) Introduction (00:07:22) Manual vs. AI Hacking (00:17:27) Building a Hackbot (00:23:53) Negatives of Hackbots (00:31:34) Logistics and Problems of Singularity (00:46:21) Successes

  10. Episode 180: State of Bug Bounty Maturity Posture Report from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jun 25, 20261 hr 12 min

    Episode 180: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Steve Hernandez, founder of the Bug Bounty Maturity Framework (BBMF), to walk us through the inaugural State of Bug Bounty Maturity Posture Report. We go through the scores and cover Asset Hygiene, Operational Signal, how to re-engage the relationship between trust and researcher participation. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Guest: https://x.com/SteveHernandezM Email Steve at info@bugbountymaturity.com Fill out this form to enter a Critical Thinkers raffle https://forms.ctbb.show/mdaz ====== Resources ====== State of Bug Bounty Maturity Posture https://bugbountymaturity.com/research/state-of-bug-bounty-maturity-posture-2026 Take the Bug Bounty Maturity Assessment https://bugbountymaturity.com/assessment AI Is Compressing the Bug Bounty Maturity Curve https://bugbountymaturity.com/research/ai-is-compressing-the-bug-bounty-maturity-curve ====== Timestamps ====== (00:00:00) Introduction (00:04:09) State of Bug Bounty Maturity Posture (00:22:33) Researcher Interface & Program Trust (00:44:38) Maturity Bands and Scoring (01:08:19) AI Is Compressing the Bug Bounty Maturity Curve

  11. Episode 179: Maintaining Motivation in Post-AI Bug Bounty World from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jun 18, 202646 min

    Episode 179: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how to stay motivated and keep the vibes strong during this trying time for Bug Bounty. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Zero Trust Cloud Access https://www.criticalthinkingpodcast.io/tl-ztca ====== Timestamps ====== (00:00:00) Introduction (00:04:57) Managing Hacker Motivation (00:10:45) Community, Competition, & Curosity (00:16:54) Using AI with Passion (00:23:10) The LHE Method & Sharing Wins (00:28:01) Video POCs, Scripts, & Talking about Bugs (00:40:49) Watching your health & stopping mid-hack

  12. Episode 178: 600k in ~3 months - BruteCat pt 2 from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jun 11, 20261 hr 23 min

    Episode 178: In this episode of Critical Thinking - Bug Bounty Podcast we’re back with BruteCat to finish up our discussion on hacking Google. This week we hit AI. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Guest: https://x.com/brutecat ====== Resources ====== Hacking Google with AI https://brutecat.com/articles/hacking-google-with-ai/ ====== Timestamps ====== (00:00:00) Introduction (00:03:07) Discovery Docs Refresher & AI at BugSWAT Mexico (00:30:49) Auth & Enumeration of Referer and Origin (00:45:59) Pwning Google Stories (01:09:32) Batch Execute & GraphQL

  13. Episode 177: 2x Google RCE with VRP Legend Brutecat from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Jun 4, 20261 hr 25 min

    Episode 177: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by BruteCat to talk about his journey hacking Google Cloud, Gmail, Youtube, and Google Phone. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Zero Trust Cloud Access https://www.criticalthinkingpodcast.io/tl-ztca Today’s Guest: https://x.com/brutecat ====== Resources ====== StubZero: $148,337 RCE in Google Cloud Production https://brutecat.com/articles/google-cloud-rce/ Leaking the email of any YouTube user for $10,000 https://brutecat.com/articles/leaking-youtube-emails/ Disclosing YouTube Creator Emails for a $20k Bounty https://brutecat.com/articles/youtube-creator-emails/ Leaking the phone number of any Google user https://brutecat.com/articles/leaking-google-phones/ ====== Timestamps ====== (00:00:00) Introduction (00:29:14) 2nd RCE in Application Integration (00:39:55) BruteCat's Background & RCE Follow-up Questions (00:48:02) Google VRP and Youtube Bugs (01:10:17) Google Phone Leak (01:18:36) Discovery Docs and Episode 178 Teaser

  14. Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam) from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    May 28, 20261 hr 50 min

    Episode 176: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by top Adobe hacker Jim Green to deep-dive AEM. We talk through Sling selectors, Permissions, and how to spot AEM Red Flags. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Sponsor: Adobe. Earn more for AI bugs with Adobe’s new AI Tier! https://blog.adobe.com/security/adobe-expands-bug-bounty-program-to-incentivize-ai-security-research Also don’t forget to also grab a 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report. Expires June 30, 2026. ====== This Week in Bug Bounty ====== Scaling Bug Bounty triage in the AI era ( https://www.yeswehack.com/security-best-practices/scaling-bug-bounty-triage-ai ) The AI impact: a triager’s perspective https://www.intigriti.com/blog/business-insights/the-ai-impact-a-triagers-perspective ====== Resources ====== Sling Selectors - The Key to Unlocking AEM's Attack Surface https://greenjam.co.uk/blog/sling-selectors/ Just a Moment CTF https://poc.greenjam.co.uk/just-a-moment.html General XSS jquery .text() https://poc.greenjam.co.uk/text-xss.html URL XXS Challenge https://poc.greenjam.co.uk/url-xss.html ====== Timestamps ====== (00:00:00) Introduction (00:04:35) Background and AEM Bug (00:17:40) Sling Selectors & the Tech Stack (00:38:14) Permissions & Apache Sling Resolution (01:01:37) The Bugs & AEM Red Flags (01:31:55) Moment in Time CTF (01:40:38) General XSS jquery .text() (01:45:45) URL XXS Challenge

  15. Episode 175: Rhyno’s Hackbot Setup, Sick Bugs, and ZDI Drama from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    May 21, 202649 min

    Episode 175: In this episode of Critical Thinking - Bug Bounty Podcast we’re comparing Hackbot setups and results. We also talk about some of the recent ZDI drama, as well as the importance of freaking beautiful POCs Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Zero Trust Cloud Access https://www.criticalthinkingpodcast.io/tl-ztca ====== Resources ====== Another day, another universal linux LPE https://x.com/v12sec/status/2054491454064746629 ZDI Drama https://x.com/ryotkak/status/2052881664909660521 Orange Tsai Bug on Edge https://x.com/thezdi/status/2054868495888777266 Chompie's Exploit in NV Container Toolkit https://x.com/chompie1337/status/2054882193055601140 GitHub Security April bug bounty stats https://x.com/GitHubSecurity/status/2054274356403138932 ====== Timestamps ====== (00:00:00) Introduction (00:02:14) q param prompt injection & Mobile CSPT (00:14:17) Admin API Key MegaCrit (00:17:13) Hackbots (00:37:10) Pretty POCs and ZDI Drama (00:44:48) GitHub Security April Stats

  16. Episode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.5 from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    May 14, 20261 hr 9 min

    Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Need a Pentest? We just launched CTBB Pentests! https://pentest.ctbb.show/ Hack full time? Check out the Full-Time Hunter’s Guild! https://ctbb.show/fthg ====== This Week in Bug Bounty ====== COST, AI frontier models and more: A measured take on the future of security testing https://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testing Common AI misconceptions debugged! https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportion BountySync + Social https://luma.com/bountysync_social ====== Resources ====== Ghosts of Encryption Past https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/ tessl Skill Optimizer https://tessl.io/registry/tessl/skill-optimizer/0.8.0 The Internet Is Falling Down, Falling Down, Falling Down https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ High Fidelity Check for the cPanel Authentication Bypass https://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/ Achieving Deterministic Prompt Injection Through Client-Side Feedback Loops https://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/ GPT-5.5: Mythos-Like Hacking, Open To All https://xbow.com/blog/mythos-like-hacking-open-to-all Remote Command Execution in Google Cloud with Single Directory Deletion https://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&utm_medium=referral ====== Timestamps ====== (00:00:00) Introduction (00:09:20) AMPScript (00:25:10) Tessl Skill Optimizer (00:33:07) cPanel & WHM Authentication Bypass (00:40:46) Advice for Bug Bounty Programs (00:50:07) Prompt Injection Through Client-Side Feedback Loops (00:54:37) GPT 5.5 (01:01:00) Remote Command Execution in Google Cloud

  17. Episode 173: Bug Bounty is Dead and AI Killed it. from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    May 7, 20261 hr 1 min

    Episode 173: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about the negative effects that AI is having on the Bug Bounty scene as a whole. Is it over, or are we so back? Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Zero Trust Cloud Access https://www.criticalthinkingpodcast.io/tl-ztca ====== Resources ====== We want your feedback on this! https://forms.ctbb.show/future_of_bug_bounty Evolving the Android & Chrome VRPs for the AI Era https://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-era Paid Submissions? https://x.com/d0rsky/status/2047744193976742120 Keep the Robots Out of the Gym https://danielmiessler.com/blog/keep-the-robots-out-of-the-gym Is my data used for model training? https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training ====== Timestamps ====== (00:00:00) Introduction (00:06:28) Network effects of Bug Bounty (00:31:55) Hopium/Copium (00:47:21) The Great Training Data Debate

  18. Episode 172: Source Code Review Meta Analysis from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Apr 30, 202651 min

    Episode 172: In this episode of Critical Thinking - Bug Bounty Podcast trying out a new structure of episode: a Meta Analysis of sorts of many Source Code Review techniques. This episode features tips gathered from Shubs, Rafax, and FSI. Justin highlights best approaches, patterns, and common pitfalls. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today’s Sponsor: Adobe - Get 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report. Expires June 30, 2026. ====== This Week in Bug Bounty ====== Open-source security testing: the Bug Bounty guide to code analysis https://www.yeswehack.com/learn-bug-bounty/open-source-guide-code-analysis?utm_source=youtube&utm_medium=sponsor-critical-thinking&utm_campaign=open-source-guide-code-analysis ====== Resources ====== Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke) https://slcyber.io/research-center/abusing-windows-net-quirks-and-unicode-normalization-to-exploit-dnn-dotnetnuke/#:~:text=across%20different%20languages.-,A%20MUST%2DKNOW%20BEHAVIOUR%20OF%20PATH.COMBINE,-Another%20key%20implementation ====== Timestamps ====== (00:00:00) Introduction (00:06:49) Tracing Data Flow, knowing where your playload is landing, and developer mistakes. (00:17:33) Mapping the software (00:24:46) Sniffing for blood (00:31:54) Common Patterns and Pitfalls

  19. Episode 171: Path-Scoped Cookie Hacks with Uppercase & Post-based Raw Protobuf XSS from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Apr 23, 202622 min

    Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking ages Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Sponsored by ThreatLocker - Ringfencing https://www.criticalthinkingpodcast.io/tl-rf ====== Resources ====== The ultimate Bug Bounty guide to OS command injection vulnerabilities https://www.yeswehack.com/learn-bug-bounty/ultimate-guide-os-command-injection?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-os-command-injection Critical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validation https://www.yeswehack.com/news/auth-bypass-wordpress-azure-plugin?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-wordpress-bypass-plugin Aituglo featured on YWH https://www.yeswehack.com/community/developer-aituglo-bug-bounty-story Adobe will be sponsoring Ekoparty in Miami and hosting a live hacking event on May 21st https://ekoparty.org/ekoparty-miami-2026-super-live-hacking-event/ ====== Resources ====== SVG clickjacking https://lyra.horse/blog/2025/12/svg-clickjacking/ ====== Timestamps ====== (00:00:00) Introduction (00:06:35) Protobuff XSS (00:12:51) Leaking Age & CSPTs (00:15:59) Capital Letters and Clickjacking

  20. Episode 170: Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways from Critical Thinking - Bug Bounty Podcast, opens in a new tab

    Apr 16, 202632 min

    Episode 170: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph their trip to Korea with some quick takeaways from the LHE. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! ====== Timestamps ====== (00:00:00) Introduction (00:01:41) Google LHE Debrief (00:09:27) Old AI Exfils & AI report writing (00:18:14) Human Tokens (00:26:13) Protoscope & Caido Websocket Repeater

Ranking source

Apple Podcasts rankings via the Mato Topic Intelligence Platform.

Observed September 20, 2026.

Apple and Apple Podcasts are trademarks of Apple Inc., registered in the U.S. and other countries.

Pairs with

What to do with a chart

01ShowsThe shows Mato publishesEvery public Mato show, its episodes, and the Apple placements it holds.02AI talentPick the voice before the formatThe live roster of hosts, each with samples you can listen to before you commit.03How it worksFrom an idea to a published episodeWhat Mato does between the brief and the feed, step by step.

Steal the structure, not the show

Bring this source into Mato to read its transferable patterns, then turn them into an original show for your own audience.

Hear a Mato showCreate a show inspired by this