Critical Thinking - Bug Bounty Podcast
A deeply technical podcast where elite bug bounty hunters deconstruct high-impact vulnerabilities and hacking methodologies with their peers.
This is an expert-level podcast for practicing security researchers. The hosts, themselves active hackers, interview top-tier bug hunters to dissect their specific tools, thought processes, and the complex bug chains behind their most significant finds. Episodes often use a guest's blog post or research as a visual guide, making it a masterclass in offensive security methodology.
“Unlike broader cybersecurity podcasts, this show maintains a relentless focus on the 'how' of offensive security. The hosts are peers of their guests, enabling deeply collaborative and technical conversations that feel more like a lab session than a standard interview.”
Who hosts this show
Hosted by full-time bug bounty hunters Justin Gardner (Rhynorater), Joseph Thacker (rez0), and Brandyn Murtagh (gr3pme), Critical Thinking is a "by hackers, for hackers" podcast. It focuses on the technical details of bug bounty tips, write-up explanations, and the latest hacking techniques. The hosts, who are active and accomplished researchers themselves, engage in peer-to-peer conversations with top-tier guests to dissect their tools, thought processes, and most significant vulnerability discoveries.
Credentials & credits
- Justin Gardner: Full-time Bug Bounty Hunter, Host of Critical Thinking Podcast, former Penetration Tester.
- Joseph Thacker: Full-time Bug Bounty Hunter, AI Red Teamer, Startup Advisor, Speaker at BlackHat & DEFCON.
- Brandyn Murtagh: Co-host of Critical Thinking Podcast.
Other ventures
- Justin Gardner: Advisor at Caido, Hacker at CRITSoftware.
- Joseph Thacker: Advisor for Ethiack, Starstrike AI, and Caido; HackerOne Advisory Board Member.
- Critical Research Lab (by the podcast).
- CTBB Pentests (by the podcast).
When new episodes drop
- 01Google bugs hidden in plain sightJun 26, 2026 · 39s
- 02AI = monkey with machine gunJun 25, 2026 · 31s
- 03State of Bug Bounty Maturity Posture Report (Ep. 180)Jun 25, 2026 · 1h 13m
- 04Bit flipping: always worth a tryJun 24, 2026 · 34s
- 05Maintaining Motivation in Post-AI Bug Bounty World (Ep. 179)Jun 18, 2026 · 47 min
- 06$600k in 6 months - BruteCat's Google Hacking Story (Ep. 178)Jun 11, 2026 · 1h 24m
- 072x Google RCE with VRP Legend Brutecat (Ep. 177)Jun 4, 2026 · 1h 25m
- 08600+ CVEs on Adobe AEM with Jim Green (GreenJam) (Ep. 176)May 28, 2026 · 1h 51m
Notable episodes
- 01$600k in 6 months - BruteCat's Google Hacking Story (Ep. 178)
A deep dive into how researcher Arvin Shivram (brutcat) used a custom, AI-driven system to earn over $600,000 in bounties from Google in a few months, detailing his methodology for hacking Google's API infrastructure at scale.
- 022x Google RCE with VRP Legend Brutecat (Ep. 177)
Guest 'brutcat' details a complex bug chain that led to two Remote Code Execution (RCE) vulnerabilities in Google's production environment, earning a $148,000 bounty and showcasing advanced hacking techniques.
- 03State of Bug Bounty Maturity Posture Report (Ep. 180)
An interview with Steve Hernandez, creator of the Bug Bounty Maturity Framework, that provides rare insight into the program-side of bug bounty, discussing what makes programs effective and how they view researchers.
What you'll be asked on this show
The interview style is collaborative and conversational, with hosts often sharing their own experiences hacking the same targets as the guests. They typically open by asking a guest to 'Tell me about a bug,' grounding the discussion in a concrete story. From there, they deconstruct the process with specific 'how' and 'why' questions about tooling, automation (especially AI), and strategy. The hosts' own expertise allows them to probe technical nuances and create a high-level, peer-to-peer dialogue rather than a simple Q&A.
Typically a multi-host format, often with a guest, for long-form (60-90+ min) episodes. The discussion is highly technical, frequently using screen sharing to walk through blog posts, code, or bug reports, making the video format essential. There are also occasional guest-less episodes where the hosts discuss the meta-game, motivation, and psychology of hacking.
Questions the host keeps coming back to
12 cataloguedIf you're going on this show as a guest, expect some version of each of these. Each note explains when the host reaches for it.
backstory
1- Q.01
“Can you tell me about a bug you've found?”
This is a signature opening used to immediately ground the conversation in a practical, hands-on story.
origin
1- Q.01
“How did you get into hacking or a specific bug bounty program?”
The host asks this to establish the guest's origin story and their initial motivations.
craft
2- Q.01
“Did you build a specific system or custom tool for this?”
This question is used to dig into the guest's unique tooling and automation workflows.
- Q.02
“Have you read the [specific technical document, e.g., SRE handbook] cover to cover?”
Used to gauge the depth of a guest's background research on a target.
technique
3- Q.01
“How are you using AI to find leads or automate your process?”
A frequent question to explore how guests are leveraging modern AI in their hacking methodology.
- Q.02
“When you mention [technical detail], can you clarify what you mean?”
The hosts interject with these questions to ensure technical accuracy and clarity for the audience.
- Q.03
“How do you determine if a specific auth mechanism is working?”
Aimed at understanding the initial steps and nuances of testing complex authentication systems.
process
3- Q.01
“How do you decide when to combine bugs into one report versus splitting them up?”
This question seeks to understand the guest's strategic approach to reporting and bounty optimization.
- Q.02
“What were the main takeaways from your research or report?”
Used to get a high-level summary of a guest's findings before diving into the details.
- Q.03
“What's your preferred method for parsing complex data like discovery docs?”
This question focuses on the specific, practical tools and scripts guests use in their reconnaissance phase.
mindset
1- Q.01
“How do you stay organized with this level of scale and complexity?”
Asked when a guest describes a large-scale operation, to understand their personal workflow and information management.
money
1- Q.01
“Was the bounty for that bug considered high quality or abuse by the program?”
This question probes the interaction with the bug bounty program and how they valued a specific find.
Signature segments
- · "Tell me about a bug..." opening segment
Topics covered repeatedly
Who gets booked here
Elite, practicing bug bounty hunters and security researchers known for high-impact findings on major platforms like Google and Adobe, or creators of influential industry tools and frameworks. Guests are expected to go deep on technical details.
- Steve Hernandezon State of Bug Bounty Maturity Posture Report (Ep. 180)
- Arvin Shivram (brutcat)on $600k in 6 months - BruteCat's Google Hacking Story (Ep. 178)
- Jim Green (GreenJam)on 600+ CVEs on Adobe AEM with Jim Green (GreenJam) (Ep. 176)
Where to find this show
Audience & reach
Estimated: The audience of professional security researchers and pentesters makes it a prime channel for B2B cybersecurity tool companies (e.g., ThreatLocker), training platforms, and bug bounty platforms.
Subscriber and view counts are pulled live from YouTube and re-verified on a 30-day cycle. Listener estimates for the RSS feed aren't published here unless they're host-verified.
Pitch this show
i•••@•••.comFree: limited reveals · Pro: unlimited reveals + CSV export
You’re only charged when we return a verified hit.
People also ask
- Who are the hosts of the podcast?
- The main hosts are Justin Gardner (Rhynorater), Joseph Thacker (rez0), and Brandyn Murtagh (gr3pme), all of whom are active security researchers.
- What is the format of the show?
- It's a long-form interview and discussion podcast. Most episodes feature a guest who is an expert hacker, deconstructing their methods. Some episodes are guest-less discussions between the hosts on topics like motivation and industry trends.
- Is this podcast suitable for beginners?
- The content is highly technical and assumes a strong foundational knowledge of web application security. It is best suited for intermediate to advanced practitioners.
- Where can I listen to the podcast?
- The podcast is available on major platforms like Apple Podcasts and Spotify, with the primary video version on their YouTube channel, '@criticalthinkingpodcast'.
- Is the podcast still active?
- Yes, the podcast releases new episodes regularly, typically on a weekly basis.
Built from the show's public RSS feed, YouTube, the host's own websites, and the cited sources below. Computed and AI-extracted fields are labelled. Facts only — no private info, no fabrication, no transcripts republished.
Sources & how this page was built
This page is AI-assisted, grounded in the public sources cited below, and host-verifiable. We publish facts only; we do not republish transcripts. If anything here is wrong, the host can claim and correct the page above.Model: gemini-2.5-pro · high confidence
- [01]Critical Thinking - Bug Bounty Podcast on Apple Podcastspodcasts.apple.com
- [02]Justin Gardner (Rhynorater) Official Websiterhynorater.github.io
- [03]Joseph Thacker (rez0) Official Websiterez0.blog
- [04]Critical Thinking - Bug Bounty Podcast YouTube Channelyoutube.com
- [05]Justin Gardner (Rhynorater) on HackerOnehackerone.com
- [06]Bug Bounty Maturity Framework (Steve Hernandez)bugbountymaturity.com
- [07]Brutecat Security (Arvin Shivram)brutecat.com
Podcasts like Critical Thinking - Bug Bounty Podcast
DIVE Studios / 다이브 스튜디오
A media company and podcast network where K-pop idols and Korean-American artists discuss culture, careers, and personal identity.
PARANORMAL EXPERIENCE
PARANORMAL EXPERIENCE
Um podcast brasileiro de longa duração onde dois apresentadores entrevistam médiuns, mentores e especialistas sobre suas experiências paranormais e estruturas espirituais.
Saad Rashid - YouTube Automation
Saad Rashid
A Pakistani host interviews creators of 'faceless' YouTube channels, breaking down their niche strategies, AI workflows, and revenue generation.
The History Guy: History Deserves to Be Remembered
A history storyteller who narrates short, engaging videos about forgotten events and figures, typically in 15 minutes or less.
Silicon Valley Girl
Silicon Valley Girl
An entrepreneur interviews the founders and scientists building the next wave of AI to uncover practical strategies for career and business growth.
The Arena
The Arena
A daily sports debate show where 3-time NBA All-Star Gilbert Arenas and a panel of former pros give unfiltered takes on basketball news.
Shallu Nisha Podcast
Shallu Nisha
A long-form interview podcast exploring the careers and business of North Indian digital creators, artists, and entrepreneurs.
Backstage with Millionaires
Pankaj Chauhan
A weekly news show and documentary-style channel breaking down the biggest stories and trends in the Indian startup and venture capital ecosystem.