<p><span style="background-color: transparent;">Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike.</span></p><p><br></p><p><span style="background-color: transparent;">Follow us on twitter at: </span><a href="https://x.com/ctbbpodcast" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/ctbbpodcast</a></p><p><span style="background-color: transparent;">Got any ideas and suggestions? Feel free to send us any feedback here: </span><a href="mailto:info@criticalthinkingpodcast.io" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">info@criticalthinkingpodcast.io</a></p><p><span style="background-color: transparent;">Shoutout to</span><a href="https://twitter.com/realytcracker" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);"> YTCracker</a><span style="background-color: transparent;"> for the awesome intro music!</span></p><p><br></p><p><span style="background-color: transparent;">====== Links ======</span></p><p><span style="background-color: transparent;">Follow your hosts Rhynorater, rez0 and gr3pme on X:&nbsp;</span></p><p><a href="https://x.com/Rhynorater" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/Rhynorater</a></p><p><a href="https://x.com/rez0__" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/rez0__</a></p><p><a href="https://x.com/gr3pme" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://x.com/gr3pme</a></p><p><br></p><p><span style="background-color: transparent;">Critical Research Lab:</span></p><p><a href="https://lab.ctbb.show/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://lab.ctbb.show/</a><span style="background-color: transparent;">&nbsp;</span></p><p><br></p><p><span style="background-color: transparent;">====== Ways to Support CTBBPodcast ======</span></p><p><span style="background-color: transparent;">Hop on the CTBB Discord at </span><a href="https://ctbb.show/discord" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/discord</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</span></p><p><br></p><p><span style="background-color: transparent;">You can also find some hacker swag at </span><a href="https://ctbb.show/merch" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/merch</a><span style="background-color: transparent;">!</span></p><p><br></p><p><span style="background-color: transparent;">Need a Pentest? We just launched CTBB Pentests!</span></p><p><a href="https://pentest.ctbb.show/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://pentest.ctbb.show/</a></p><p><br></p><p><span style="background-color: transparent;">Hack full time? Check out the Full-Time Hunter’s Guild!</span></p><p><a href="https://ctbb.show/fthg" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://ctbb.show/fthg</a></p><p><br></p><p><span style="background-color: transparent;">====== This Week in Bug Bounty ======</span></p><p><span style="background-color: transparent;">COST, AI frontier models and more: A measured take on the future of security testing</span></p><p><a href="https://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testing" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testing</a></p><p><br></p><p><span style="background-color: transparent;">Common AI misconceptions debugged!</span></p><p><a href="https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportion" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportion</a></p><p><br></p><p><span style="background-color: transparent;">BountySync + Social</span></p><p><a href="https://luma.com/bountysync_social" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://luma.com/bountysync_social</a></p><p><br></p><p><span style="background-color: transparent;">====== Resources ======</span></p><p><span style="background-color: transparent;">Ghosts of Encryption Past</span></p><p><a href="https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/</a></p><p><br></p><p><span style="background-color: transparent;">tessl Skill Optimizer</span></p><p><a href="https://tessl.io/registry/tessl/skill-optimizer/0.8.0" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://tessl.io/registry/tessl/skill-optimizer/0.8.0</a></p><p><br></p><p><span style="background-color: transparent;">The Internet Is Falling Down, Falling Down, Falling Down</span></p><p><a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/</a></p><p><br></p><p><span style="background-color: transparent;">High Fidelity Check for the cPanel Authentication Bypass</span></p><p><a href="https://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/</a></p><p><br></p><p><span style="background-color: transparent;">Achieving Deterministic Prompt Injection Through Client-Side Feedback Loops</span></p><p><a href="https://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/</a></p><p><br></p><p><span style="background-color: transparent;">GPT-5.5: Mythos-Like Hacking, Open To All</span></p><p><a href="https://xbow.com/blog/mythos-like-hacking-open-to-all" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://xbow.com/blog/mythos-like-hacking-open-to-all</a></p><p><br></p><p><span style="background-color: transparent;">Remote Command Execution in Google Cloud with Single Directory Deletion</span></p><p><a href="https://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&amp;utm_medium=referral" target="_blank" style="background-color: transparent; color: rgb(17, 85, 204);">https://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&amp;utm_medium=referral</a></p><p><br></p><p><span style="background-color: transparent;">====== Timestamps ======</span></p><p><span style="background-color: transparent;">(00:00:00) Introduction</span></p><p><span style="background-color: transparent;">(00:09:20) AMPScript</span></p><p><span style="background-color: transparent;">(00:25:10) Tessl Skill Optimizer</span></p><p><span style="background-color: transparent;">(00:33:07) cPanel &amp; WHM Authentication Bypass</span></p><p><span style="background-color: transparent;">(00:40:46) Advice for Bug Bounty Programs</span></p><p><span style="background-color: transparent;">(00:50:07) Prompt Injection Through Client-Side Feedback Loops</span></p><p><span style="background-color: transparent;">(00:54:37) GPT 5.5</span></p><p><span style="background-color: transparent;">(01:01:00) Remote Command Execution in Google Cloud</span></p>

Critical Thinking - Bug Bounty Podcast

[email protected] (Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme))

Episode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.5

MAY 14, 202669 MIN
Critical Thinking - Bug Bounty Podcast

Episode 174: Saving Bug Bounty Programs + AMPScript, tessl & GPT-5.5

MAY 14, 202669 MIN

Description

Episode 174: In this episode of Critical Thinking - Bug Bounty Podcast we follow up from last episode with some advice for BB platforms, as well as cover a slew of writeups from Searchlight Cyber, watchTowr, and Starstrike.Follow us on twitter at: https://x.com/ctbbpodcastGot any ideas and suggestions? Feel free to send us any feedback here: [email protected] to YTCracker for the awesome intro music!====== Links ======Follow your hosts Rhynorater, rez0 and gr3pme on X: https://x.com/Rhynoraterhttps://x.com/rez0__https://x.com/gr3pmeCritical Research Lab:https://lab.ctbb.show/ ====== Ways to Support CTBBPodcast ======Hop on the CTBB Discord at https://ctbb.show/discord!We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.You can also find some hacker swag at https://ctbb.show/merch!Need a Pentest? We just launched CTBB Pentests!https://pentest.ctbb.show/Hack full time? Check out the Full-Time Hunter’s Guild!https://ctbb.show/fthg====== This Week in Bug Bounty ======COST, AI frontier models and more: A measured take on the future of security testinghttps://www.yeswehack.com/security-best-practices/cost-mythos-future-security-testingCommon AI misconceptions debugged!https://www.intigriti.com/blog/business-insights/common-misconceptions-debugged#trend-3-validity-ratios-remain-constant-ai-slop-isnt-rising-as-a-proportionBountySync + Socialhttps://luma.com/bountysync_social====== Resources ======Ghosts of Encryption Pasthttps://slcyber.io/research-center/ghosts-of-encryption-past-salesforce-exacttarget/tessl Skill Optimizerhttps://tessl.io/registry/tessl/skill-optimizer/0.8.0The Internet Is Falling Down, Falling Down, Falling Downhttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/High Fidelity Check for the cPanel Authentication Bypasshttps://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/Achieving Deterministic Prompt Injection Through Client-Side Feedback Loopshttps://blog.starstrike.ai/posts/achieving-deterministic-prompt-injection-through-client-side-feedback-loops/GPT-5.5: Mythos-Like Hacking, Open To Allhttps://xbow.com/blog/mythos-like-hacking-open-to-allRemote Command Execution in Google Cloud with Single Directory Deletionhttps://flatt.tech/research/posts/remote-command-execution-in-google-cloud-with-single-directory-deletion/?utm_source=bugbountydaily.com&utm_medium=referral====== Timestamps ======(00:00:00) Introduction(00:09:20) AMPScript(00:25:10) Tessl Skill Optimizer(00:33:07) cPanel & WHM Authentication Bypass(00:40:46) Advice for Bug Bounty Programs(00:50:07) Prompt Injection Through Client-Side Feedback Loops(00:54:37) GPT 5.5(01:01:00) Remote Command Execution in Google Cloud