POPULARITY
Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we're (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what he thinks went wrong with H1, and how they can revive their old self.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab: https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Guest - Joel Magolishttps://x.com/0xteknogeek====== This Week in Bug Bounty ======Kara Sprague's Statement:“I read Joel's post and listened to the episode myself. You raise many good points. The part I want to fix first is how we exchange and action feedback from the community. I don't have the full fix yet, but I own it and am also open to working together to find a good solution.” Kara Sprague, CEO, HackerOne Write triager-grade Bug Bounty reports with Claude Code: introducing the YesWeHack Claude Kit pluginhttps://www.yeswehack.com/learn-bug-bounty/triager-grade-reports-claude-codeClaude Kithttps://github.com/yeswehack/claude-kit====== Resources ======What Happened to HackerOne?https://blog.teknogeek.io/posts/what-happened-to-hackerone/Watch our episode with Alex Ricehttps://www.youtube.com/watch?v=Pa4wWv_ONjM====== Timestamps ======(00:00:00) Introduction(00:04:18) The early days: LHE's, Covid, and the rise of AI(00:17:20) HSM Program, HAI, and resource allocation(00:36:41) Sales Incentivisation(00:46:10) AI and Researcher Reports Data(00:54:38) How Can H1 Revive its Old Self(01:02:40) Triage
Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigation platform from scratch. John's system runs on more than 30 specialized agents that reason through cases instead of following a script. In one run, that meant over 140 detections investigated in under four hours at an 80 to 85% quality rating. Ron and John dig into the hard lesson that made John rip out his own tooling and rebuild it around function calling, why "humans first" drives every decision his team makes, and whether AI SOC is actually different from SOAR or just the same promise with way better marketing. Underneath all of it is the one thing John says decides whether any of this actually works: context. Give the AI too little and it's guessing, give it too much and it drowns just like a human would. Listen to find out what it actually takes to build an AI SOC that reasons instead of just automates. Impactful Moments 00:00 - Introduction 02:05 - The rewind: how SOAR promised to save the SOC in 2015 03:35 - Meet John Gillis, Adobe's Staff AI Security Engineer 05:30 - What cybersecurity looked like before AI at enterprise scale 07:00 - The "humans first" strategy behind Adobe's AI investigator 09:30 - Why careless context management is the biggest pitfall in agent design 14:45 - Solving the speed problem: is it tooling, process, or people? 17:10 - From monolith to microservices: rebuilding the platform for scale 24:05 - What actually makes an AI agent's "persona" work 26:00 - John's prediction for the SOC three years from now 28:50 - The three skills every security practitioner needs for 2026 32:10 - Final verdict: is AI SOC really different, or SOAR with new branding? Links Connect with John Gillis on LinkedIn: https://www.linkedin.com/in/john-gillis/ If you're a researcher ready to make an impact, check out the announcement about Adobe's new home for the Adobe Bug Bounty Program here: https://blog.adobe.com/security/a-new-home-for-the-adobe-bug-bounty-program Check out Adobe's Bug Bounty profile on Intigriti: https://app.intigriti.com/programs/adobe/adobepublic/detail Learn more about Adobe: https://www.adobe.com/ – Check out our upcoming events: https://www.hackervalley.com/livestreams Love Hacker Valley Studio? Pick up some swag: https://store.hackervalley.com Become a sponsor of the show: https://hackervalley.com/work-with-us/
Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Trend of Bug Bounty Programshttps://x.com/iangcarroll/status/2082535987633410540Next chapter: Restructuring GitHub's bug bounty programhttps://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHubhttps://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854Gauntlet Loophttps://x.com/mattshumer_/status/2081830214384886228KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/====== Timestamps ======(00:00:00) Introduction(00:05:40) Bug Bounty Program Trends & Pricing Changes(00:15:52) Wiz Research uncovers RCE in GitHub & Sol 5.6(00:29:06) AI Harnessing, prompting, and the Gauntlet Loop(00:36:58) LHE vs Hackbot(00:43:21) KindaRails2Shell & WP2Shell
Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It's almost time for DEFCON! We're joined by Harley Kimball and Ariel Garcia to preview this year's Bug Bounty Village!Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztnaToday's Guests: Harley Kimball - https://x.com/infiniteloginsAriel Garcia - https://x.com/Arl_rose====== This Week in Bug Bounty ======Meet YesWeHack at DEFCON 34https://www.yeswehack.com/fr/page/yeswehack-defcon-34====== Resources ======Bug Bounty Village Agenda https://www.bugbountydefcon.com/agenda-2026BBV CTF 2026https://www.bugbountydefcon.com/ctfHacker Hangout with TikTok, HackerOne, and Bug Bounty Villagehttps://h1.community/events/details/hackerone-sponsored-conferences-events-presents-hacker-hangout-with-tiktok-hackerone-and-bug-bounty-village-at-def-con-34/?code=xyss8KXXPd====== Timestamps ======(00:00:00) Introduction(00:04:39) Podcast ATO & ATM Hacks(00:17:12) Bug Bounty Village Preview(00:31:02) BBV Room Layout and Swag(00:42:36) BBV Agenda(01:10:57) Harley's Hackbot
Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next.Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time.In this episode:Casey's path from building Bugcrowd to advising, investing, and policy workWhy more practitioners need to get involved in policy, and why law is just codeThe slopdemic vs. the vulnpocalypse, and what actually changed in submissionsAI lowering the bar for a broader, less predictable pool of threat actorsDaniel Stenberg, curl, and maintainers below the security poverty lineThe lightning rod vs. rockets distinction between VDPs and bug bountiesThe pentest market correction underway from AI pricing pressureCollapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.ioChapters:0:00 Intro and Casey's background 2:56 Why practitioners belong in policy 6:22 The slopdemic vs. the vulnpocalypse 9:40 AI lowering the bar for threat actors 11:47 Open source, curl, and the security poverty line 15:37 VDP vs. bug bounty readiness 19:20 The pentest market correction 24:20 What breaks first in vulnerability management 27:20 Hack-back and non-cooperative defense 28:43 A near-term playbook for security leaders 31:40 CFAA, SRLDF, and disclose.ioConnect with Casey: LinkedIn: https://www.linkedin.com/in/caseyjohnellis Blog: https://cje.io disclose.io: https://disclose.io Bugcrowd: https://www.bugcrowd.comResilient Cyber: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders.
Empresas como Google, Microsoft e Meta já pagam milhões de dólares para quem encontra falhas de segurança em seus sistemas. Mas e se esses especialistas forem justamente hackers? Esse é o tema do novo episódio do Podcast Canaltech. Nesta edição, Fernanda Santos conversa com Rudinei Carapinheiro, chefe de Estratégias da IPV7, empresa que recentemente anunciou a aquisição da HuntersPay, uma das principais plataformas brasileiras de Bug Bounty. Durante a entrevista, o executivo explica como funciona esse modelo de segurança ofensiva, quem são os chamados hackers éticos e por que eles podem se tornar grandes aliados das empresas na prevenção de ataques cibernéticos. O episódio também aborda os desafios da cibersegurança no Brasil, a importância da cultura de prevenção, os critérios para selecionar pesquisadores de segurança. Você também vai conferir: Meta quer que você use menos o ChatGPT, conversa no Claude pode estar pública sem você perceber e Balsa leva internet ao fundo dos rios da Amazônia. Este podcast foi roteirizado e apresentado por Fernanda Santos e contou com reportagens de Marcelo Fischer, Viviane França e Renato Moura. A trilha sonora é de Guilherme Zomer, a edição de Leandro Gomes e a arte da capa é de Erick Teixeira. O Podcast Canaltech está concorrendo para entrar no Top 20 do Prêmio iBest 2026! Se você acompanha nossos episódios, curte as entrevistas e gosta do conteúdo que produzimos todos os dias, sua ajuda pode fazer toda a diferença. Vote no Podcast Canaltech aqui. É rápido, gratuito e você pode votar até 3 vezes por dia.See omnystudio.com/listener for privacy information.
Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we're joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Guest: https://substack.com/@0xmoose====== This Week in Bug Bounty ======How to use Claude Code for Bug Bounty: find fast, validate manuallyhttps://www.yeswehack.com/learn-bug-bounty/llm-series-claude====== Resources ======Signal Over Noise: AI Agents and the Operator Moathttps://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-theFBDL Goes Agentic: AI Agents Can Now Build Your Test Environmentshttps://bugbounty.meta.com/blog/fbdl-goes-agentic/====== Timestamps ======(00:00:00) Introduction(00:11:01) Satisfaction for hackbot finds(00:19:31) Hackbot Mechanics and Tech Debt(00:33:31) Sitting in the Bottleneck & Analyzing hacking sessions with Frontier models(00:44:35) FBDL Goes Agentic, Noise Reduction, & Hill Climbing(01:05:45) Hackbot Load Distribution
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com
From the sudden retirement of Internet pioneer Vint Cerf to the unstoppable advance of "apex agentic adversaries," get a front-row seat to the unfolding security revolution and its massive real-world stakes. Why Fable5's re-release has disappointed. Opera becomes the first browser to offer "Paste Protect." Microsoft BlueHammer exploit is "hammering" systems. Industry legend (TCP creator) Vint Cerf on AI. Chrome turns 150 with too many fixes to load. Google fails to sidestep a $4.67 billion EU fine. One last (we can hope) Chat Control vote next week. AirDrop & Android Quick Share are exploitable. How to bypass Claude's and ChatGPT's guardrails. My own Sunday spin with SpinRite. A legendary hacker uses AI on a widespread library Show Notes - https://www.grc.com/sn/SN-1086-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: blackhat.com/us-26 and use code TWIT cohesity.com/Resilience bitwarden.com/twit zscaler.com/security XBOW.com adaptivesecurity.com
Episode 181: In this episode of Critical Thinking - Bug Bounty Podcast Joseph and XSSDoctor talk about building a Hackbot.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Network Access:https://www.criticalthinkingpodcast.io/tl-ztna====== Resources ======Are bug bounties cooked?https://hakluke.com/are-bug-bounties-cookedWe built a Hackbothttps://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html====== Timestamps ======(00:00:00) Introduction(00:07:22) Manual vs. AI Hacking(00:17:27) Building a Hackbot(00:23:53) Negatives of Hackbots(00:31:34) Logistics and Problems of Singularity (00:46:21) Successes
Episode 180: In this episode of Critical Thinking - Bug Bounty Podcast we're joined by Steve Hernandez, founder of the Bug Bounty Maturity Framework (BBMF), to walk us through the inaugural State of Bug Bounty Maturity Posture Report. We go through the scores and cover Asset Hygiene, Operational Signal, how to re-engage the relationship between trust and researcher participation.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Guest: https://x.com/SteveHernandezMEmail Steve at info@bugbountymaturity.comFill out this form to enter a Critical Thinkers rafflehttps://forms.ctbb.show/mdaz====== Resources ======State of Bug Bounty Maturity Posturehttps://bugbountymaturity.com/research/state-of-bug-bounty-maturity-posture-2026Take the Bug Bounty Maturity Assessmenthttps://bugbountymaturity.com/assessmentAI Is Compressing the Bug Bounty Maturity Curvehttps://bugbountymaturity.com/research/ai-is-compressing-the-bug-bounty-maturity-curve====== Timestamps ======(00:00:00) Introduction(00:04:09) State of Bug Bounty Maturity Posture(00:22:33) Researcher Interface & Program Trust(00:44:38) Maturity Bands and Scoring (01:08:19) AI Is Compressing the Bug Bounty Maturity Curve
Episode 179: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how to stay motivated and keep the vibes strong during this trying time for Bug Bounty.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Cloud Access:https://www.threatlocker.com/capabilities/zero-trust-cloud-access====== Timestamps ======(00:00:00) Introduction(00:04:57) Managing Hacker Motivation(00:10:45) Community, Competition, & Curosity(00:16:54) Using AI with Passion(00:23:10) The LHE Method & Sharing Wins(00:28:01) Video POCs, Scripts, & Talking about Bugs(00:40:49) Watching your health & stopping mid-hack
An underground forum post breaks down how hackers scan, exploit, and cash out on vulnerabilities — and it reads like a step-by-step guide. Meanwhile, Microsoft is catching heat for stonewalling a researcher who found real zero-days, and a new phishing campaign is hitting small businesses through the platforms they trust most. The OG crew — Joshua Schmidt, Eric Brown, and Nick Mellem — digs into this week's biggest cybersecurity headlines with sharp takes and real-world context that practitioners can actually use.
In this episode of Ecosystem Project Demo 33 on the ECH Institute channel, we dive deep into the evolving landscape of Web3 security with Indranil Roy from CredShields. As AI continues to transform the tech industry, it also introduces new vulnerabilities and sophisticated "AI attacks" targeting smart contracts.Indranil shares expert insights on the proactive measures developers and organizations can take to secure their blockchain applications. We explore the intersection of artificial intelligence and cybersecurity, discussing how to leverage advanced tooling and rigorous auditing to safeguard assets in an increasingly complex digital environment.
The Business of Open Source is back! I'm starting a series about AI and open source this week. I reached out to Glauber Costa, founder of Turso, after reading a post of his on LinkedIn about how bot-written PRs for their bug bounty program forced them to discontinue the program completely. In this episode, he talked about the bug bounty program — how it started, who contributed to it initially, why he considered it a huge success. And then he talks about what started happening when bots entered the picture. He also talked about the difference between an open source project that accepts contributions and one that doesn't, about the difference between an open source project and software that's in the public domain, and how people in open source used to be seen as weirdos who hate money. Glauber isn't an AI hater — he talks about how they use AI at Turso, and how he has no problem with AI-assisted pull requests. The issue is when the result isn't high-quality. There's also a difference between AI-assisted and 100% bot written. Then it creates essentially a denial of service attack on the community, because the maintainers end up having to spend so much time responding to bot-created PRs. What's your experience with AI and Open Source? Who else should I talk to? Let me know. Do you like The Business of Open Source? Help it to continue to exist by sponsoring the podcast.Does your company have a positioning problem? Work with me to better position your product and see your growth take off.
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.) Three Buddy Problem x Ekoparty Miami: SentinelLabs researcher Gabriel Bernadett-Shapiro hops on the mic to unpack who gets to define what "security" even means in the age of AI, why venture capital keeps funding the wrong things, and how the frontier labs quietly ate everyone's coding harness. Plus, how AI actually contributed to cracking the FAST 16 research, overcoming the guardrails, and why your domain expertise is the only thing keeping you out of full-blown rabbit-hole psychosis. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Gabriel Bernadett-Shapiro. Timestamps: 0:00 Introductory banter 4:55 Gabe returns: how the models got scary-good at code 8:45 Bay Area short-termism and the "10x in 18 months" trap 11:35 VCs as tastemakers, and why that's broken 13:00 The unpaid-labor pipeline into the AI labs 18:00 The real misunderstanding about security's moat 20:18 Bug bounties: a net negative for the industry? 22:20 The great vuln fire sale — find 50,000, fix zero 27:28 Who will maintain vetted open-source libraries? 29:29 FAST 16: how AI actually broke the case open 35:05 The rabbit-holing machine and the path to "AI psychosis" 41:05 Stuxnet, Kim Zetter, and the story we'll never be told
Two researchers from a small Palo Alto outfit drove up to Apple's Cupertino headquarters to hand-deliver something the bug bounty queue would have buried. A working kernel exploit against the M5 chip's Memory Integrity Enforcement. Built in five days. With AI help. Apple's most expensive new security feature, defeated in less than a week by two people and a chatbot.The defender has to be right everywhere. The attacker only needs one path. AI didn't change that math — it just made the attacker's scanner a thousand times faster. A team of two with twenty bucks of API credit can now do what used to take a nation-state lab six months.Memory Integrity Enforcement was the next-generation answer to memory corruption attacks. Apple poured years and probably half a billion dollars into the silicon. The M5 is brand new. Five days. Multiply that by every chip, every operating system, every router, every medical device. The attack surface didn't expand. The time-to-discover collapsed.The five-day exploit isn't the story. The bug bounty queue is. The page used to look like a defense layer. It looks like a triage room now.Two people drove to Cupertino with their findings. They knocked. They got in the meeting. They gave Apple a chance to fix it before anyone else found it. That version of the story is still happening. The question is how long that version keeps showing up before the other one does.AI compresses the time between vulnerability and exploit. It does not compress the time between exploit and disclosure. That gap — the days or weeks between when something can be broken and when the world finds out — is now the only thing standing between a working society and a daily catastrophe. Two researchers chose the long version. The next two might not. Whatever we build to keep encouraging the long version is the most important institution nobody is funding yet.⏱️ Chapters0:00 — Two researchers drive to Apple HQ with a 5-day exploit0:25 — MiniDoge: nation-state lab six months → 2 people with $20 API0:55 — Nyx: Memory Integrity Enforcement defeated; time-to-discover collapsed1:25 — HH: the bug bounty queue used to be a defense — now it's a triage room1:45 — Saarvis: the good ending requires a knock; that version is still happening2:10 — Saarvis: the gap between exploit and disclosure is now everything⚡ Learn agentic ai free - https://staas.fund/ai-workshop ⚡-----
Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter's Guild!https://ctbb.show/fthg====== This Week in Bug Bounty ======COST, AI frontier models and more: A measured take on the future of security testinghttps://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testingCommon AI misconceptions debugged!https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportionBountySync + Socialhttps://luma.com/bountysync_social====== Resources ======Ghosts of Encryption Pasthttps://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/tessl Skill Optimizerhttps://tessl.io/registry/tessl/skill-optimizer/0.8.0The Internet Is Falling Down, Falling Down, Falling Downhttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/High Fidelity Check for the cPanel Authentication Bypasshttps://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/Achieving Deterministic Prompt Injection Through Client-Side Feedback Loopshttps://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/GPT-5.5: Mythos-Like Hacking, Open To Allhttps://xbow.com/blog/mythos-like-hacking-open-to-allRemote Command Execution in Google Cloud with Single Directory Deletionhttps://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&utm_medium=referral====== Timestamps ======(00:00:00) Introduction(00:09:20) AMPScript(00:25:10) Tessl Skill Optimizer(00:33:07) cPanel & WHM Authentication Bypass(00:40:46) Advice for Bug Bounty Programs(00:50:07) Prompt Injection Through Client-Side Feedback Loops(00:54:37) GPT 5.5(01:01:00) Remote Command Execution in Google Cloud
Episode 173: In this episode of Critical Thinking - Bug Bounty Podcast we're talking about the negative effects that AI is having on the Bug Bounty scene as a whole. Is it over, or are we so back?Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out Zero Trust Cloud Access:https://www.criticalthinkingpodcast.io/tl-ztca====== Resources ======We want your feedback on this!https://forms.ctbb.show/future_of_bug_bountyEvolving the Android & Chrome VRPs for the AI Erahttps://bughunters.google.com/blog/evolving-the-android-chrome-vrps-for-the-ai-eraPaid Submissions?https://x.com/d0rsky/status/2047744193976742120Keep the Robots Out of the Gymhttps://danielmiessler.com/blog/keep-the-robots-out-of-the-gymIs my data used for model training?https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training====== Timestamps ======(00:00:00) Introduction(00:06:28) Network effects of Bug Bounty(00:31:55) Hopium/Copium(00:47:21) The Great Training Data Debate
Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365
Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365
Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365
Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365
Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365
Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365
Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365
Google is sneaking a massive 4.7GB AI model into Chrome, and Mozilla is fighting back as the future of browsers threatens to turn into an AI arms race. Find out what's really happening behind this push and why it's setting off alarm bells across the web. Hackers AI-code a portal, forget to add authentication. The UK's NCSC issues a Mythos warning. Where's CISA? Another (of many) Linux local privilege escalations. AI may be spelling the end of bug bounties. Anthropic releases "Claude Security" mini-Mythos. ChatGPT gets very serious about login security. Syncthing's SyncTrayzor v1 abandoned; v2 created. Google drops an AI API into Chrome; Mozilla objects Show Notes - https://www.grc.com/sn/SN-1077-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: outsystems.com/twit zscaler.com/security meter.com/securitynow bitwarden.com/twit hoxhunt.com/securitynow trustedtech.team/securitynow365
Description:Want to break into cybersecurity? Learn how Nikhil Agarwal moved from reverse engineering video games to leading AI security teams and automating complex infosec workflows. [bic-00003]In this episode, we explore:How childhood curiosity about software keys and "cheat codes" builds a foundation for red teaming. [bic-00004]The evolution from freelance bug hunting to professional penetration testing. [bic-00004]Nikhil reveals practical AI tools for automating security tasks in the cloud. [bic-XXXX1] [bic-00009]Demystifying AI-powered threat hunting: Practical steps and strategies. [bic-XXXX2] [bic-00009]Implementing AI for cloud security threat detection and automated incident response. [bic-00008]Timestamps: [bic-00004]00:00 - Intro & Countdown00:29 - Welcome Nikhil Agarwal00:52 - Childhood curiosity and reverse engineering games01:45 - Early freelance red teaming and the "pre-bug bounty" eraGuest Bio: [bic-00004]Nikhil Agarwal is a cybersecurity expert specializing in AI security teams and the automation of complex security operations. He leverages a background in red teaming and penetration testing to bridge the gap between hands-on technical skills and modern AI-driven cloud security.Community Link | Subscribe on YouTube [bic-00007]Tags: [bic-00005] [bic-00006]Nikhil Agarwal, AI Security, Red Teaming, Cloud Security Automation, Bug Bounty, AI Threat Hunting, breaking into cybersecurity, cybersecurity career, how to get into cybersecurity, cybersecurity podcast, infosec career, cybersecurity career change, cybersecurity for beginners, cybersecurity career advice, cybersecurity jobs, CISO interview, pivot to cybersecurity, cybersecurity certifications.***Sponsored by CPF Coaching LLC - http://cpf-coaching.comThe Breaking into Cybersecurity: It's a conversation about what they did before, why they pivoted into cyber, what the process was they went through, how they keep up, and advice/tips/tricks along the way.Check out our books:The Cybersecurity Advantage - https://leanpub.com/the-cybersecurity-advantageDevelop Your Cybersecurity Career Path: https://amzn.to/3443AUIHack the Cybersecurity Interview: https://www.amazon.com/Hack-Cybersecurity-Interview-Interviews-Entry-level/dp/1835461298/---About the hosts:Renee Small is the CEO of Cyber Human Capital and author of Magnetic Hiring. https://www.linkedin.com/in/reneebrownsmall/Christophe Foulon is a Cybersecurity Strategist and passionate about customer service and process improvement. https://www.linkedin.com/in/christophefoulon/- Website: https://www.cyberhubpodcast.com/breakingintocybersecurity- Podcast: https://podcasters.spotify.com/pod/show/breaking-into-cybersecuri- YouTube: https://www.youtube.com/c/BreakingIntoCybersecurity- Linkedin: https://www.linkedin.com/company/breaking-into-cybersecurity/
Episode 172: In this episode of Critical Thinking - Bug Bounty Podcast trying out a new structure of episode: a Meta Analysis of sorts of many Source Code Review techniques. This episode features tips gathered from Shubs, Rafax, and FSI. Justin highlights best approaches, patterns, and common pitfalls.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Adobe - Get 10% bonus for valid AI vulnerabilities in Adobe Stock and Lightroom Web. Use code: CTBB063026 in your report.Expires June 30, 2026. ====== This Week in Bug Bounty ======Open-source security testing: the Bug Bounty guide to code analysishttps://www.yeswehack.com/learn-bug-bounty/open-source-guide-code-analysis?utm_source=youtube&utm_medium=sponsor-critical-thinking&utm_campaign=open-source-guide-code-analysis====== Resources ======Abusing Windows, .NET quirks, and Unicode Normalization to exploit DNN (DotNetNuke)https://slcyber.io/research-center/abusing-windows-net-quirks-and-unicode-normalization-to-exploit-dnn-dotnetnuke/#:~:text=across%20different%20languages.-,A%20MUST%2DKNOW%20BEHAVIOUR%20OF%20PATH.COMBINE,-Another%20key%20implementation====== Timestamps ======(00:00:00) Introduction(00:06:49) Tracing Data Flow, knowing where your playload is landing, and developer mistakes.(00:17:33) Mapping the software(00:24:46) Sniffing for blood(00:31:54) Common Patterns and Pitfalls
Katie Moussouris is the founder and CEO at Luta Security. In this episode, she joins host Charlie Osborne to discuss her career and the bug bounty industry, including her work in launching one of the first major bug bounty programs at Microsoft, and more. • For more on cybersecurity, visit us at https://cybersecurityventures.com
Episode 171: In this episode of Critical Thinking - Bug Bounty Podcast Justin gives us some quick tips from his own hacking, including some clickjacking, using capital letters, and the potential value of leaking agesFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out ThreatLocker Ringfencinghttps://www.criticalthinkingpodcast.io/tl-rf====== Resources ======The ultimate Bug Bounty guide to OS command injection vulnerabilitieshttps://www.yeswehack.com/learn-bug-bounty/ultimate-guide-os-command-injection?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-os-command-injectionCritical auth bypass in WordPress Azure AD SSO plugin due to missing OIDC id_token validationhttps://www.yeswehack.com/news/auth-bypass-wordpress-azure-plugin?utm_source=critical-thinking-podcast&utm_medium=youtube&utm_campaign=article-wordpress-bypass-pluginAituglo featured on YWHhttps://www.yeswehack.com/community/developer-aituglo-bug-bounty-storyAdobe will be sponsoring Ekoparty in Miami and hosting a live hacking event on May 21sthttps://ekoparty.org/ekoparty-miami-2026-super-live-hacking-event/====== Resources ======SVG clickjackinghttps://lyra.horse/blog/2025/12/svg-clickjacking/ ====== Timestamps ======(00:00:00) Introduction(00:06:35) Protobuff XSS(00:12:51) Leaking Age & CSPTs(00:15:59) Capital Letters and Clickjacking
Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security
Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security
Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security
Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security
Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security
Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security
Security leaders warn the era of AI-driven bug hunting has arrived, with Mythos uncovering hundreds of overlooked vulnerabilities in code bases as trusted as Firefox. Are defenders ready for the avalanche of exploits and the frantic race to patch? A disgruntled developer discloses multiple Windows 0-days. Microsoft purchases its own bugs in massive campaign. VeraCrypt & Wireshark suddenly lost their dev accounts. A serious problem with re-captured domain names. How might AI help to secure open source repositories. A listener wonders what we thought of Project Hail Mary. Cyber security professionals tell us What Mythos Means Show Notes - https://www.grc.com/sn/SN-1075-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: canary.tools/twit - use code: TWIT joindeleteme.com/twit promo code TWIT hoxhunt.com/securitynow meter.com/securitynow zscaler.com/security
Fagan Afandiyev — Elite Cybersecurity Competitor and Legendary Whitehatter No Password Required: Breakout Room: Episode 1 — Fagan Afandiyev Fagan Afandiyev is a cybersecurity student at the University of South Florida and a member of the CyberHerd competition team, known for his strategic mindset and passion for solving complex challenges. From competing in international robotics competitions to discovering cybersecurity through hands-on platforms, Fagan has built his skills through curiosity, persistence, and a love for problem solving. Fagan shares how competitions, community, and continuous learning shaped his journey into cybersecurity. He walks through his growth within USF's cyber community, and how that led to a penetration testing internship at Microsoft. He also offers insight into the mindset needed to succeed in cybersecurity, encouraging others to embrace challenges, learn through failure, and find enjoyment in the process. Follow Fagan on Linked in here: https://www.linkedin.com/in/fagan-afandi/ Presented by ThreatLocker Chapters: 00:00 Introduction to Cybersecurity Passion 3:02 Journey to Cyber Herd and University Life 06:12 Internship at Microsoft and Career Aspirations 08:59 Hackathon Experience and Community Engagement 12:39 Behind the Scenes of Cyber Competitions 14:30 Overcoming Challenges in Cyber Competitions 18:00 Gratitude and Mentorship in Cybersecurity
AI-Powered AppSec, OWASP Origins, and Anthropic's "Mythos" Model: Jeff Williams on What Changes Next Cybersecurity Today would like to thank Meter for their support in bringing you this podcast. Meter delivers a complete networking stack, wired, wireless and cellular in one integrated solution that's built for performance and scale. You can find them at Meter.com/cst Jim hosts Jeff Williams (Contrast Security co-founder/CTO and former OWASP global chair) for a wide-ranging discussion that begins with Anthropic's new "Mythos" model, described as powerful for finding zero-day vulnerabilities, and expands into how AppSec must evolve. Williams explains Contrast's runtime instrumentation approach, recounts OWASP's early days, the creation of WebGoat and the OWASP Top 10, and notes that many common vulnerabilities persist despite years of maturity models. They debate open source versus commercial security scrutiny, the likely high cost and scalability limits of advanced AI vulnerability discovery, and why finding more bugs matters only if remediation improves too. Williams argues for AI-powered "software factories" with feedback loops, assurance evidence, and runtime monitoring, and flags the EU Product Liability Directive treating software as a product with no-fault liability for security defects, including those from embedded open source. 00:00 AppSec Stuck in Ruts 00:42 Show Intro and Sponsor 01:40 What Contrast Security Does 02:35 OWASP Origins and WebGoat 04:33 Why the Top 10 Persists 06:28 Mythos Model Overview 08:05 Open Source Scrutiny Myth 11:31 Cost and Adoption Barriers 15:04 Finding vs Fixing Bugs 15:55 AI Code Quality Reality 17:46 AI Powered Software Factory 23:11 Building with AI in Practice 25:18 AppSec Metrics and New Approaches 26:42 Staying Optimistic as a CISO 28:00 EU Product Liability Shift 32:13 Bug Bounties in an AI World 34:06 Wrap Up and Outro
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
How often are redirects used in phishing in 2026? https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870 Hackerone Suspends Internet Bug Bounty https://hackerone.com/ibb?type=team https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/ Bluehammer Windows 0-day Privilege Escalation https://github.com/Nightmare-Eclipse/BlueHammer https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html https://deepwiki.com/Nightmare-Eclipse/BlueHammer Keycloak MFA Bypass CVE-2026-3429 https://access.redhat.com/security/cve/cve-2026-3429
Episode 167: In this episode of Critical Thinking - Bug Bounty Podcast we welcome Valeriy Shevchenko to talk about program management, anchor programs, and Theft in Bug Bounty.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Check out ThreatLocker Ringfencinghttps://www.criticalthinkingpodcast.io/tl-rfToday's Guest: https://x.com/Krevetk0Valeriy====== This Week in Bug Bounty ======HackerOne's Bug Bounty Maturity Framework:https://www.hackerone.com/blog/program-maturity-framework-bug-bounty-operationsIntigriti is hiring a Product Security Analysthttps://jobs.criticalthinkingpodcast.io/jobs/product-security-analyst-25ef4706====== Resources ======Valeriy's Bloghttps://krevetk0.medium.com/====== Timestamps ======(00:00:00) Introduction(00:03:15) Valeriy's Bug story(00:19:48) Anchor Programs and Bug Hunting Motivation(00:29:50) Stealing Bugs
Episode 164: In this episode of Critical Thinking - Bug Bounty Podcast Justin sits down with Tommy DeVoss to talk about his origin story, Yahoo bugs, and how Tommy first got Justin into Bug BountyFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.ioShoutout to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Guest: https://x.com/thedawgyg====== This Week in Bug Bounty ======Python pitfalls: Turning developer mistakes into vulnerabilitieshttps://www.yeswehack.com/learn-bug-bounty/python-pitfalls-turning-developer-mistakes?utm_source=critical-thinking&utm_medium=sponsored&utm_campaign=article-research-python-pitfalls====== Timestamps ======(00:00:00) Introduction(00:06:22) Yahoo SSRF(00:14:56) Tommy's Origin(00:44:10) Bug Bounty(00:51:47) SSRF Attraction, AI implementation, & Browser Hacking
When a popular antivirus and even Notepad++ turn into infection vectors after supply chain breaches, it's clear no software is safe from attack—or from its own update system. Steve and Leo unpack the risks hiding right inside your next auto-update. An anti-virus system infects its own users. Apple's next iOS release "fuzzes" cellular locations. cURL discontinues bug bounties under bogus AI flood. AI discovers and fixes 15 CVE-worthy 0-days in OpenSSL. Ireland did NOT already pass their spying legislation. AI irreversibly deletes all project files. Says it's sorry. Windows has a serious global clipboard security problem. ISPs have the ability to monetize their subscriber's identities. MongoDB has lowered the hacking skill level bar to the floor Show Notes - https://www.grc.com/sn/SN-1063-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: threatlocker.com/twit meter.com/securitynow bitwarden.com/twit material.security guardsquare.com