Episode

Episode 163: Best Technical Takeaways from Portswigger Top 10 2025

Podcast
Critical Thinking - Bug Bounty Podcast
Published
Feb 26, 2026
Duration seconds
4103
Processing state
not_requested
Canonical source
https://criticalthinkingpodcast.io
Audio
https://audio-delivery.cohostpodcasting.com/audio/8d5e4388-13f4-45c8-b82f-aff313a5ac76/episodes/37070408-7a44-42f4-9513-dfc0bbf5294b/episode.mp3
JSON
/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-163-best-technical-takeaways-from-portswigger-top-10-2025
Markdown
/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-163-best-technical-takeaways-from-portswigger-top-10-2025.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/critical-thinking-bug-bounty-podcast-5951018/episodes/episode-163-best-technical-takeaways-from-portswigger-top-10-2025/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/critical-thinking-bug-bounty-podcast-5951018/episode-163-best-technical-takeaways-from-portswigger-top-10-2025.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Episode 163: In this episode of Critical Thinking - Bug Bounty Podcast It’s that time of year again! We’re looking at the Portswigger Research list of top 10 web hacking techniques of 2025. Follow us on twitter at: https://x.com/ctbbpodcast Got any ideas and suggestions? Feel free to send us any feedback here: [email protected] Shoutout to YTCracker for the awesome intro music! ====== Links ====== Follow your hosts Rhynorater, rez0 and gr3pme on X:  https://x.com/Rhynorater https://x.com/rez0__ https://x.com/gr3pme Critical Research Lab: https://lab.ctbb.show/   ====== Ways to Support CTBBPodcast ====== Hop on the CTBB Discord at https://ctbb.show/discord ! We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc. You can also find some hacker swag at https://ctbb.show/merch ! ====== Resources ====== Parser Differentials: When Interpretation Becomes a Vulnerability https://www.youtube.com/watch?v=Dq_KVLXzxH8 XSS-Leak: Leaking Cross-Origin Redirects https://blog.babelo.xyz/posts/cross-site-subdomain-leak/ Playing with HTTP/2 CONNECT https://blog.flomb.net/posts/http2connect/ Next.js, cache, and chains: the stale elixir https://zhero-web-sec.github.io/research-and-things/nextjs-cache-and-chains-the-stale-elixir SOAPwn: Pwning .NET Framework Apps Through HTTP Client Proxies And WSDL https://watchtowr.com/wp-content/uploads/SOAPwnwatchtowr_soappwn-research-whitepaper_10-12-2025.pdf Cross-Site ETag Length Leak https://blog.arkark.dev/2025/12/26/etag-length-leak Lost in Translation: Exploiting Unicode Normalization https://www.youtube.com/watch?v=ETB2w-f3pM4 ORM Leaking More Than You Joined For https://www.elttam.com/blog/leaking-more-than-you-joined-f…