Interested in going full-time bug bounty? Check out our blueprint!

Videos

Aug. 28, 2025

How We Do AI-Assisted Whitebox Review, New CSPT (Ep. 137)

Episode 137: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gardner and Joseph Thacker reunite to talk about AI Hacking Assistants, CSPT and cache deception, and a bunch of tools like ch.at, Slice, Ebka, and more. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions?…

View more
Aug. 26, 2025

How XBOW Works is INCREDIBLE - Watch the episode here: https://youtu.be/rvA8IbyogJ0

#hacking #bugbounty #podcast #bugbountytips #infosec #aihacking #xbow

View more
Aug. 25, 2025

XBOW = URL + Attack type → HACK - Watch the episode here: https://youtu.be/rvA8IbyogJ0

#hacking #bugbounty #podcast #bugbountytips #infosec #aihacking #XBOW

View more
Aug. 21, 2025

Hacking Cluely, AI Prod Sec, and How To Not Get Sued with Jack Cable (Ep. 136)

Episode 136: In this episode of Critical Thinking - Bug Bounty Podcast, Joseph Thacker sits down with Jack Cable to get the scoop on a significant bug in Cluely’s desktop application, as well as the resulting drama. They also talk about Jack’s background in government cybersecurity initiatives, and the legal…

View more
Aug. 19, 2025

Helping y'all is what keeps us going! =)

#hacking #bugbounty #podcast #bugbountytips #infosec

View more
Aug. 17, 2025

From DUPES to making a living from bug bounties -- Full episode: https://youtu.be/NI-eXMlXma4

#hacking #bugbounty #podcast #bugbountytips #infosec

View more
Aug. 15, 2025

Have you tried their CTF at DEFCON? Tell us how you did!

#hacking #bugbounty #bugbountytips #websecurity #infosec #CTF #DEFCON #BugBountyVillage

View more
Aug. 14, 2025

Akamai's Ryan Barnett on WAFs, Unicode Confusables, and Triage Stories (Ep. 135)

Episode 135: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Ryan Barnett for a deep dive on WAFs. We also recap his Exploiting Unicode Normalization talk from DEFCON, and get his perspective on bug hunting from his time at Akamai. Follow us on twitter…

View more
Aug. 12, 2025

This is HOW and WHY the Bug Bounty Village was created

#hacking #bugbounty #bugbountytips #websecurity #infosec #BBV #DEFCON #BugBountyVillage

View more
Aug. 4, 2025

XBOW - AI Hacking Agent and Human in the Loop with Diego Jurado (Ep. 134)

Episode 134: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Diego Jurado to give us the scoop on XBOW. We cover a little about its architecture and approach to hunting, the challenges with hallucinations, and the future of AI in the BB landscape. Diego also…

View more
Aug. 2, 2025

Command Injection in Vertex AI

#hacking #bugbounty #bugbountytips #websecurity #infosec #vertex #google #googlehacking #AISecurity #AIHacking

View more
Aug. 1, 2025

The AI Infinite Money Glitch 💸

#hacking #bugbounty #bugbountytips #websecurity #infosec #moneyglitch #AIHacking #AISecurity

View more
July 31, 2025

Building Hacker Communities - Bug Bounty Village, getDisclosed, and the LHE Squad (Ep. 133)

Episode 133: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Harley and Ari from H1 to talk some about community management roles within Bug Bounty, as well as discuss the evolution of Bug Bounty Village at DEFCON, and what they’ve got in store this year.…

View more
July 29, 2025

Free-After-Use or Web Cache Deception?

#hacking #bugbounty #bugbountytips #websecurity #infosec #webcachedeception #cachedeception

View more
July 28, 2025

Nesting Tags to Break Sanitisers... 🍕

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
July 26, 2025

[Hacker x AI] vs. [Hacker + AI]

#hacking #bugbounty #bugbountytips #websecurity #infosec #AIHacking #AISecurity

View more
July 25, 2025

Exploiting fetchLater() with Redirect Chaining

#hacking #bugbounty #bugbountytips #websecurity #infosec #fetchLater

View more
July 24, 2025

Archive Testing Methodology with Mathias Karlsson (Ep.132)

Episode 132: In this episode of Critical Thinking - Bug Bounty Podcast, Justin Gardner is joined by Mathias Karlsson to discuss vulnerabilities associated with archives. They talk about his new tool, Archive Alchemist, and explore topics like the significance of Unicode paths, symlinks, and TAR before they end up talking…

View more
July 22, 2025

Clever Way to Weaponise AI Retrieval Systems

#hacking #bugbounty #bugbountytips #websecurity #infosec #AI #RAG

View more
July 21, 2025

OBS Websockets to RCE Research

#hacking #bugbounty #bugbountytips #websecurity #infosec #websocket #OBS #RCE

View more
July 19, 2025

THIS is How You Bypass IP Allow-lists

#hacking #bugbounty #bugbountytips #websecurity #infosec

View more
July 18, 2025

Reverse Engineering JSON Request Bodies with Caido Shift

Using Caido's new AI plugin Shift, it is a breeze to reverse JSON request bodies. #bugbounty #appsec #https #javascript

View more
July 17, 2025

SL Cyber Writeups, Metastrategy & Orphaned Github Commits (Ep. 131)

Episode 131: Christmas in July HACKING STYLE -SL Cyber Writeups, Bug Bounty Metastrategy, and Orphaned Github Commits Episode 131: In this episode of Critical Thinking - Bug Bounty Podcast we're covering Christmas in July with several banger articles from Searchlight Cyber, as well as covering things like Raycast for Windows,…

View more
July 11, 2025

URL Normalization Gone Wrong

#hacking #bugbounty #bugbountytips #websecurity #infosec #SSRF

View more