# Episode 161: Cross-Consumer Attacks & DTMF Tone Exfil Page: https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-161-cross-consumer-attacks-dtmf-tone-exfil Text version: https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-161-cross-consumer-attacks-dtmf-tone-exfil.md Podcast: [Critical Thinking - Bug Bounty Podcast](https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018) Published: 2026-02-12T10:00:00+00:00 Episode link: https://criticalthinkingpodcast.io Audio file: https://audio-delivery.cohostpodcasting.com/audio/8d5e4388-13f4-45c8-b82f-aff313a5ac76/episodes/29603b7e-ba63-4a88-bf31-6fdc6f0a1d96/episode.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-161-cross-consumer-attacks-dtmf-tone-exfil Duration seconds: 1482 ## Resource Episode 161: In this episode of Critical Thinking - Bug Bounty Podcast Justin Gives us some quick hits regarding CSRF and Cross Consumer Attacks, and also touches on some breaking questions surrounding HackerOne Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: info@criticalthinkingpodcast.io Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/   ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! Today's Sponsor: Join Justin at Zero Trust World in March and get $200 off registration with Code ZTWCTBB26 https://ztw.com/ ====== This Week in Bug Bounty ====== AS Watson https://app.intigriti.com/programs/aswatson/watsons/detail YesWeHack 2026 Report https://choose.yeswehack.com/bug-bounty-report-2026-trends-and-key-insights-yeswehack?utm_source=youtube&utm_medium=sponsor-critical-thinking&utm_campaign=yeswehack-report-2026   ====== Resources ====== PhoneLeak: Data Exfiltration in Gemini via Phone Call https://blog.starstrike.ai/posts/phoneleak-data-exfiltration-in-gemini-via-phone-call/ Max's Tweet about decreasing bounties https://x.com/0xw2w/status/2020788164378427483 HackerOne General Terms and Conditions https://www.hackerone.com/terms/general Research Review #-2: RCE in Google's AI code editor Antigravity (sudi) https://www.youtub… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-161-cross-consumer-attacks-dtmf-tone-exfil/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-161-cross-consumer-attacks-dtmf-tone-exfil.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.