Skip to content

Podcasts

Critical Thinking - Bug Bounty Podcast

Hosted by Justin Gardner & Joseph Thacker & Brandyn Murtagh

Full-time bug bounty hunters trading techniques, write-ups, and payout war stories every week.

Mixed format Weekly 60+ min· ~193 episodes· Started 2023
Level
Expert, assumes deep technical background
Status
Active, last episode
Who's behind it
Independent, Justin Gardner and co-hosts source
Last verified
No transcripts

Listed underAppSecOffensive security

Editorial take

The most technical weekly show for web hackers. Justin Gardner (Rhynorater), Joseph Thacker (Rez0), and Brandyn Murtagh (gr3pme) are full-time bounty hunters, and episodes are dense with technique: client-side path traversal, OAuth gadgets, cache bugs, XS-Leaks, DOMPurify bypasses, and how they wire AI agents into their hunting. Guest episodes with researchers like James Kettle are some of the best recorded conversations about how web security research is done. The format alternates host-only technique episodes (often 25 to 45 minutes) with long guest sessions that can run past two hours. The honest limitation: it assumes you already know Burp, the browser security model, and bug bounty jargon, and a share of airtime goes to platform drama and the hosts' bounty economics.

Last hand-checked 2026-09-30.

Listen if you …

  • hunt bugs on HackerOne, Bugcrowd, or Intigriti, or want to
  • do web penetration testing and want current client-side and auth techniques
  • want to hear how working researchers use AI agents in offensive work

Skip if you …

  • you are new to web security, the show assumes Burp and browser internals
  • you want defensive or program-level guidance, this is attacker technique

Start with these 3 episodes

  1. 01

    Episode 147: Stupid Simple Hacking Workflow Tips

    · 59 min · Practitioner

    Practical habits the hosts wish they had learned sooner. The most approachable way to meet the three of them.

  2. 02

    Episode 110: Oauth Gadget Correlation and Common Attacks

    · 50 min · Expert

    A typical technique episode: how real OAuth flaws get chained into account takeover.

  3. 03

    Episode 139: James Kettle - Pwning in Prod & How to do Web Security Research

    · 142 min · Expert

    Long, but the best conversation on how original web security research gets done, from PortSwigger's research director.

About the show

Critical Thinking is a weekly bug bounty podcast billed as "by hackers for hackers". It was started in January 2023 by Justin Gardner; Joseph Thacker joined as co-host in January 2025 and Brandyn Murtagh in October 2025.

Episodes cover bug bounty tips, explanations of published write-ups, and new hacking techniques, mostly in web and client-side security. Host-only episodes alternate with long interviews with notable researchers and live hacking event winners.

Notable guests

  • James Kettle
  • Jorian Woltjer
  • Joel Margolis
  • Tommy DeVoss
  • Jack Cable
  • Mathias Karlsson
  • Kevin Mizu
  • Ryan Barnett
  • Aaron Costello
  • Sasi Levi

If Critical Thinking - Bug Bounty Podcast works for you, these likely will too.