Critical Thinking - Bug Bounty Podcast cover art

Critical Thinking - Bug Bounty Podcast

Critical Thinking - Bug Bounty Podcast

By: Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
Listen for free

About this listen

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

Critical Thinking Podcast
Episodes
  • Episode 154: Starting a Pentesting Company on Top of Bug Bounty
    Dec 25 2025

    Episode 154: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and Brandyn talk through the transition from Bug Bounty hunting to Pentesting. We cover diversifying income streams, the challenges of pricing for Pentests, legal considerations, and what Bug Hunters can bring to the Pentesting world

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:03:36) Starting a Pentesting Company

    (00:12:25) Advantages of Pentesting as a Bug Bounty Hunter

    (00:29:03) Pricing, Sales, and knowing your Market/Worth

    (00:36:21) Compliance in Pentests & Rapid-Fire Takaways

    Show More Show Less
    41 mins
  • Episode 153: Hacking the Robots of the Future: Hardware, AI, and Bug Bounties with Matt Brown
    Dec 18 2025

    Episode 153: In this episode of Critical Thinking - Bug Bounty Podcast Matt Brown returns to talk with us about hacking robots, IOT hackbots, and his Zero-to-Hero Hardware Hacking Guide.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    You can also find some hacker swag at https://ctbb.show/merch!

    Today’s Guest: Matt Brown

    • https://x.com/nmatt0
    • https://github.com/BrownFineSecurity/iothackbot

    ====== Resources ======

    KeeYees USB Logic Analyzer Device

    Saleae logic analyzer

    XGecu

    Hardware Hacking Tutorial by Make Me Hack

    UART and SPI firmware extraction

    UART Root Shell on Linux Router

    UART Shell Jail and Unlocked Bootloader

    Chinese IP Camera Firmware Extraction

    Chip-Off Firmware Extraction

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:01:22) Incremental Session Token Story and Matt Brown Intro

    (00:10:42) Hardware Bug Bounty Scene & AI on Devices

    (00:24:30) Hacking Human Robot

    (00:41:33) Zero-to-Hero Hardware Hacking Guide

    (01:01:47) IOT Hackbot

    Show More Show Less
    1 hr and 17 mins
  • Episode 152: GeminiJack and Agentic Security with Sasi Levi
    Dec 11 2025

    Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prompt Injection is a real Vuln.

    Follow us on twitter at: https://x.com/ctbbpodcast

    Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io

    Shoutout to YTCracker for the awesome intro music!

    ====== Links ======

    Follow your hosts Rhynorater, rez0 and gr3pme on X:

    https://x.com/Rhynorater

    https://x.com/rez0__

    https://x.com/gr3pme

    ====== Ways to Support CTBBPodcast ======

    Hop on the CTBB Discord at https://ctbb.show/discord!

    We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

    CHeck out our New Christmas Swag at https://ctbb.show/merch!

    Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control

    https://ctbb.show/tl-ec

    And Noma Security! https://noma.security/

    Today’s Guest: https://x.com/sasi2103

    ====== This Week in Bug Bounty ======

    Vercel Platform Protection

    Dedicated HackerOne program for Vercel WAF

    YesWeHack Open Source Programs

    Android recon for Bug Bounty hunters

    ====== Resources ======

    Sasi's Tweet from 2015

    ForcedLeak: AI Agent risks exposed in Salesforce AgentForce

    Is Prompt Injection a Vulnerability?

    ====== Timestamps ======

    (00:00:00) Introduction

    (00:09:16) Google Vertex AI Bug

    (00:29:28) Sasi's Background and Bug Bounty Journey

    (00:38:55) Resources for AI and Agentic Security Methodology

    (00:50:34) ForcedLeak

    (01:02:06) Is Prompt Injection a Vuln?

    Show More Show Less
    1 hr and 22 mins
No reviews yet
In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.