Rephonic
Artwork for Critical Thinking
Bug Bounty
Bug Bounty Hunting
Bug Bounty Programs
Cybersecurity
Live Hacking Events
Threatlocker
Portswigger
XSS
Google
Hackerone
AI Security
Hacking Techniques
Prompt Injection
XSS Vulnerabilities
Vulnerabilities
Cross-Site Scripting (XSS)
Web Security
Artificial Intelligence
Automation
Javascript

A "by Hackers for Hackers" podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest hacking techniques.

PublishesWeeklyEpisodes192Founded4 years ago
Number of ListenersCategory
Technology

Listen to this Podcast

Artwork for Critical Thinking

Latest Episodes

Episode 192: In this episode of Critical Thinking - Bug Bounty Podcast Justin lays out some goals and tips on PoC Creation.

Follow us on twitter at: x.com/ctbbpodcast

Got any ideas and suggestions? Feel free to send us any feedback here: in... more

YouTube

Episode 191: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph talk about successes in scaling their hackbots, and brainstorm possible ways to stretch their AI subscriptions.

Follow us on twitter at: x.com/ctbbpodca... more

YouTube

Episode 190: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joseph do a little life-coaching session to make sure they’re both still aligned with their bug bounty goals. They also talk about Claude vs Codex, amount vs impact, an... more

YouTube

Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revi... more

YouTube

Key Facts

Accepts Guests
Accepts Sponsors
Contact Information
Podcast Host
Number of Listeners
Find out how many people listen to this podcast per episode and each month.

Similar Podcasts

People also subscribe to these shows.

Hacked
HackedHacked
Risky Business
Risky BusinessRisky Business Media
Risky Bulletin
Risky BulletinRisky Business Media
Risky Business Features
Risky Business FeaturesRisky Business Media
Darknet Diaries
Darknet DiariesJack Rhysider

Recent Guests

Joel Margolis
Former HackerOne engineer and Bug Bounty researcher, return guest
Independent researcher / former HackerOne engineer
Episode: Episode 189: What Happened to HackerOne with Joel Margolis
Ads Dawson
Bug bounty researcher and creator of a HackBot harness
Independent researcher/CTBB guest
Episode: Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)
Jim Green
Adobe AEM security researcher, top bug hunter known as GreenJam
Adobe
Episode: Episode 176: 600+ CVEs on Adobe AEM with Jim Green (GreenJam)
XSS Doctor
A cardiologist turned bug bounty researcher and a longtime hackalong organizer
CTPB community / Bug Bounty researcher
Episode: Episode 168: XSSDoctor - Client-side Path Traversal Research
Valeriy Kravetko
Bug bounty researcher and investigator discussed as a guest on the show
SEMrush
Episode: Episode 167: Stealing Bugs with Valeriy Shevchenko
Tommy DeVoss
veteran hacker turned bug bounty researcher and educator
Independent security researcher / Bug Bounty hunter
Episode: Episode 164: Tommy DeVoss: From Black Hat to Bug Bounty LEGEND
Darby Hopkins
Security Engineer at Google Cloud
Google Cloud
Episode: Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins
Michael Cote
Security Engineer at Google Cloud
Google Cloud
Episode: Episode 159: Avoiding Downgrades on Google Cloud VRP with Cote and Darby Hopkins
Enrique HyperDude
Experienced hacker with a focus on kernel exploits and Pwn2Own
CoffinSec
Episode: Episode 157: Crushing Pwn2Own & H1 with Kernel Driver Exploits

Hosts

Rezo
Co-host and security researcher active in bug bounty discussions
Justin
Host of the show, introduces guests and guides conversations

Reviews

4.9 out of 5 stars from 569 ratings
  • You know

    Too many annoying vocal tics

    Apple Podcasts
    3
    TestTickler
    United Statesa month ago
  • My First BUG REPORT!!!!!

    seriously, I cannot thank you guys enough for what you do. I've been cramming episodes and doing labs and building my setup. I just submitted my first report on hackerone! im really nervous but also REALLY EXCITED!!! THANK YOU SO MUCH

    Audible
    5
    Yusuf
    United States2 months ago
  • The absolute bug & ai bounty goats.

    Podcast Addict
    5
    Ryot
    6 months ago
  • Solid!

    Real advice from real hackers. Every show links super sick articles and has either an interview or a unique concept to talk about, such as maximizing collaborations or doing well at live hacking events.

    The depth of knowledge about client-side security bugs is mind boggling to me. Much of the information in this podcast on client side concepts is very hard to find.

    One of the shows hosts is very much Christian and isn’t afraid to show it. Gotta love that ✝️❤️

    Apple Podcasts
    5
    Maxwell 'Strikeout' Dulin
    United Statesa year ago
  • A much needed resource

    The podcast and the community gave me a kind of plausibility structure, a mental model, where I could genuinely see myself being successful. And once I had that, I started consistently investing time. And it paid off.

    Apple Podcasts
    5
    Evan Connelly
    United Statesa year ago

Listeners Say

Key themes from listener reviews, highlighting what works and what could be improved about the show.

Strong community sentiment with fans returning episode after episode.
A few comments note room for improvement in audio quality and pacing.
Many reviews highlight the insights from guests and the value of actionable write-ups.
Listeners praise deep technical content and practical tooling tips.

Chart Rankings

How this podcast ranks in the Apple Podcasts, Spotify and YouTube charts.

Apple Podcasts
#143
Canada/Technology
Apple Podcasts
#64
Italy/Technology
Apple Podcasts
#229
France/Technology
Apple Podcasts
#43
United Arab Emirates/Technology
Apple Podcasts
#70
South Korea/Technology
Apple Podcasts
#148
Poland/Technology

Talking Points

Recent interactions between the hosts and their guests.

Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)
Q: Ads, can you share how your HackBot uses smaller models to achieve high bug discovery rates?
Ads explains that the system relies on a mix of open-source and smaller models, assembled into a pipeline (harness) with modular skills, which achieves high velocity without needing frontier models; the ROI comes from lower infrastructure costs and effective triage through design patterns like reflection and verifier chains.
Episode 177: 2x Google RCE with VRP Legend Brutecat
Q: What specifically made the Google APIs and Discovery Docs a rich target for investigations?
BruteCat explains that protobuf endpoints, the way Google maps APIs to RPCs, and the availability of draft and discovery docs allowed him to systematically understand and test internal RPCs, obtain raw proto definitions, and identify misconfigurations that exposed sensitive data across Google services.
Episode 168: XSSDoctor - Client-side Path Traversal Research
Q: What are the most surprising findings from your eight-framework study?
One of the biggest surprises was how some frameworks consistently decode certain encodings by default, while others require explicit handling; notably, React and Next.js exhibit unique behaviors around useParams and await params, which can lead to secondary context path traversal when server-side routing is involved.
Episode 168: XSSDoctor - Client-side Path Traversal Research
Q: How did you approach researching client-side path traversals across different frameworks?
I started by building lab environments for each framework, testing path, query, and hash parameters, then used AI iteratively to locate the code paths, decode behaviors, and identify where URL-encoded values get decoded or retained, finally tracing the data flow from the URL to API calls and back-end validation.
Episode 167: Stealing Bugs with Valeriy Shevchenko
Q: What can platforms do to protect researchers' intellectual property?
Suggestions include limiting who can join the initial report, adding verifiable watermarks or markers, and enabling controlled sharing so dupes or collaborators cannot easily claim ownership or reveal the full exploit path.

Audience Metrics

Listeners, social reach, demographics and more for this podcast.

Listeners per Episode
Gender Skew
Location
Interests
Professions
Age Range
Household Income
Social Media Reach

Frequently Asked Questions About Critical Thinking

What is Critical Thinking about and what kind of topics does it cover?

This show consistently centers on bug bounty deep-dives, AI-assisted tooling for vulnerability discovery, and the economics of researcher workflows. Episodes frequently explore live hacking events, platform program changes, and practical triage and reporting strategies, with guests ranging from top bug bounty researchers to AI tooling experts. A notable thread is how AI copilots and automation shape research throughput, scope management, and payout dynamics, alongside hands-on technical breakdowns of high-impact bugs and mature defense lessons. The format blends technical how-tos, industry gossip, and real-world operating advice, making it valuable for practitioners who want actionable insights and a sense of where bug bounty and security r... more

Where can I find podcast stats for Critical Thinking?

Rephonic provides a wide range of podcast stats for Critical Thinking. We scanned the web and collated all of the information that we could find in our comprehensive podcast database. See how many people listen to Critical Thinking and access YouTube viewership numbers, download stats, audience demographics, chart rankings, ratings, reviews and more.

How many listeners does Critical Thinking get?

Rephonic provides a full set of podcast information for four million podcasts, including the number of listeners. View further listenership figures for Critical Thinking, including podcast download numbers and subscriber numbers, so you can make better decisions about which podcasts to sponsor or be a guest on. You will need to upgrade your account to access this premium data.

What are the audience demographics for Critical Thinking?

Rephonic provides comprehensive predictive audience data for Critical Thinking, including gender skew, age, country, political leaning, income, professions, education level, and interests. You can access these listener demographics by upgrading your account.

How many subscribers and views does Critical Thinking have?

To see how many followers or subscribers Critical Thinking has on Spotify and other platforms such as Castbox and Podcast Addict, simply upgrade your account. You'll also find viewership figures for their YouTube channel if they have one.

Which podcasts are similar to Critical Thinking?

These podcasts share a similar audience with Critical Thinking:

1. Hacked
2. Risky Business
3. Risky Bulletin
4. Risky Business Features
5. Darknet Diaries

How many episodes of Critical Thinking are there?

Critical Thinking launched 4 years ago and published 192 episodes to date. You can find more information about this podcast including rankings, audience demographics and engagement in our podcast database.

How do I contact Critical Thinking?

Our systems regularly scour the web to find email addresses and social media links for this podcast. We scanned the web and collated all of the contact information that we could find in our podcast database. But in the unlikely event that you can't find what you're looking for, our concierge service lets you request our research team to source better contacts for you.

Where can I see ratings and reviews for Critical Thinking?

Rephonic pulls ratings and reviews for Critical Thinking from multiple sources, including Spotify, Apple Podcasts, Castbox, and Podcast Addict.

View all the reviews in one place instead of visiting each platform individually and use this information to decide if a show is worth pitching or not.

How do I access podcast episode transcripts for Critical Thinking?

Rephonic provides full transcripts for episodes of Critical Thinking. Search within each transcript for your keywords, whether they be topics, brands or people, and figure out if it's worth pitching as a guest or sponsor. You can even set-up alerts to get notified when your keywords are mentioned.

What guests have appeared on Critical Thinking?

Recent guests on Critical Thinking include:

1. Joel Margolis
2. Ads Dawson
3. Jim Green
4. XSS Doctor
5. Valeriy Kravetko
6. Tommy DeVoss
7. Darby Hopkins
8. Michael Cote

To view more recent guests and their details, simply upgrade your Rephonic account. You'll also get access to a typical guest profile to help you decide if the show is worth pitching.

Find and pitch the right podcasts

We help savvy brands, marketers and PR professionals to find the right podcasts for any topic or niche. Get the data and contacts you need to pitch podcasts at scale and turn listeners into customers.
Try it free for 7 days