<p><span style="background-color: transparent;">Episode 161: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gives us some quick hits regarding CSRF and Cross Consumer Attacks, and also touches on some breaking questions surrounding HackerOne</span></p><p><br></p><p><span style="background-color: transparent;">Follow us on twitter at: </span><a href="https://x.com/ctbbpodcast" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/ctbbpodcast</a></p><p><span style="background-color: transparent;">Got any ideas and suggestions? Feel free to send us any feedback here: </span><a href="mailto:info@criticalthinkingpodcast.io" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">info@criticalthinkingpodcast.io</a></p><p><span style="background-color: transparent;">Shoutout to</span><a href="https://twitter.com/realytcracker" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);"> YTCracker</a><span style="background-color: transparent;"> for the awesome intro music!</span></p><p><br></p><p><br></p><p><span style="background-color: transparent;">====== Links ======</span></p><p><span style="background-color: transparent;">Follow your hosts Rhynorater, rez0 and gr3pme on X:&nbsp;</span></p><p><a href="https://x.com/Rhynorater" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/Rhynorater</a></p><p><a href="https://x.com/rez0__" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/rez0__</a></p><p><a href="https://x.com/gr3pme" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/gr3pme</a></p><p><br></p><p><span style="background-color: transparent;">Critical Research Lab:</span></p><p><a href="https://lab.ctbb.show/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://lab.ctbb.show/</a><span style="background-color: transparent;">&nbsp;</span></p><p><br></p><p><span style="background-color: transparent;">====== Ways to Support CTBBPodcast ======</span></p><p><span style="background-color: transparent;">Hop on the CTBB Discord at </span><a href="https://ctbb.show/discord" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/discord</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</span></p><p><br></p><p><span style="background-color: transparent;">You can also find some hacker swag at </span><a href="https://ctbb.show/merch" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/merch</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">Today's Sponsor: Join Justin at Zero Trust World in March and get $200 off registration with Code </span><strong style="background-color: transparent;">ZTWCTBB26</strong></p><p><a href="https://ztw.com/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ztw.com/</a></p><p><br></p><p><span style="background-color: transparent;">====== This Week in Bug Bounty ======</span></p><p><br></p><p><span style="background-color: transparent;">AS Watson</span></p><p><a href="https://app.intigriti.com/programs/aswatson/watsons/detail" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://app.intigriti.com/programs/aswatson/watsons/detail</a></p><p><br></p><p><span style="background-color: transparent;">YesWeHack 2026 Report</span></p><p><a href="https://choose.yeswehack.com/bug-bounty-report-2026-trends-and-key-insights-yeswehack?utm_source=youtube&amp;utm_medium=sponsor-critical-thinking&amp;utm_campaign=yeswehack-report-2026" target="_blank" style="color: rgb(0, 120, 212);">https://choose.yeswehack.com/bug-bounty-report-2026-trends-and-key-insights-yeswehack?utm_source=youtube&amp;utm_medium=sponsor-critical-thinking&amp;utm_campaign=yeswehack-report-2026</a><span style="color: rgb(0, 120, 212);">&nbsp;</span></p><p><br></p><p><span style="background-color: transparent;">====== Resources ======</span></p><p><br></p><p><span style="background-color: transparent;">PhoneLeak: Data Exfiltration in Gemini via Phone Call</span></p><p><a href="https://blog.starstrike.ai/posts/phoneleak-data-exfiltration-in-gemini-via-phone-call/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://blog.starstrike.ai/posts/phoneleak-data-exfiltration-in-gemini-via-phone-call/</a></p><p><br></p><p><span style="background-color: transparent;">Max's Tweet about decreasing bounties</span></p><p><a href="https://x.com/0xw2w/status/2020788164378427483" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/0xw2w/status/2020788164378427483</a></p><p><br></p><p><span style="background-color: transparent;">HackerOne General Terms and Conditions</span></p><p><a href="https://www.hackerone.com/terms/general" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.hackerone.com/terms/general</a></p><p><br></p><p><span style="background-color: transparent;">Research Review #-2: RCE in Google's AI code editor Antigravity (sudi)</span></p><p><a href="https://www.youtube.com/watch?v=JqvJSF2UMyY" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.youtube.com/watch?v=JqvJSF2UMyY</a></p><p><br></p><p><span style="background-color: transparent;">====== Timestamps ======</span></p><p><span style="background-color: transparent;">(00:00:00) Introduction</span></p><p><span style="background-color: transparent;">(00:03:26) YesWeHack 2026 Report</span></p><p><span style="background-color: transparent;">(00:09:12) CSRF Realizations &amp; Data Exfiltration in Gemini via Phone Call</span></p><p><span style="background-color: transparent;">(00:14:38) 7urb0's Youtube, HackerOne decreasing bounties and Section&nbsp; &nbsp; 3.1 controversy.</span></p><p><span style="background-color: transparent;">(00:19:06) Cross Consumer Attacks</span></p><p><br></p><p><br></p>

Critical Thinking - Bug Bounty Podcast

[email protected] (Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme))

Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil

FEB 12, 202624 MIN
Critical Thinking - Bug Bounty Podcast

Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil

FEB 12, 202624 MIN

Description

Episode 161: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gives us some quick hits regarding CSRF and Cross Consumer Attacks, and also touches on some breaking questions surrounding HackerOneFollow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Today's Sponsor: Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26https://ztw.com/====== This Week in Bug Bounty ======AS Watsonhttps://app.intigriti.com/programs/aswatson/watsons/detailYesWeHack 2026 Reporthttps://choose.yeswehack.com/bug-bounty-report-2026-trends-and-key-insights-yeswehack?utm_source=youtube&utm_medium=sponsor-critical-thinking&utm_campaign=yeswehack-report-2026 ====== Resources ======PhoneLeak: Data Exfiltration in Gemini via Phone Callhttps://blog.starstrike.ai/posts/phoneleak-data-exfiltration-in-gemini-via-phone-call/Max's Tweet about decreasing bountieshttps://x.com/0xw2w/status/2020788164378427483HackerOne General Terms and Conditionshttps://www.hackerone.com/terms/generalResearch Review #-2: RCE in Google's AI code editor Antigravity (sudi)https://www.youtube.com/watch?v=JqvJSF2UMyY====== Timestamps ======(00:00:00) Introduction(00:03:26) YesWeHack 2026 Report(00:09:12) CSRF Realizations & Data Exfiltration in Gemini via Phone Call(00:14:38) 7urb0's Youtube, HackerOne decreasing bounties and Section    3.1 controversy.(00:19:06) Cross Consumer Attacks