Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways (Ep. 170)

Claude Code + Tmux, Websockets, and Other Korea LHE Takeaways (Ep. 170)

Source: YouTube · Critical Thinking - Bug Bounty Podcast · published Apr 16, 2026 · 32:52

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: The hosts discuss insights from recent Google and HackerOne live hacking events, emphasizing how direct collaboration with engineers accelerates bug discovery, the efficiency gains and cognitive trade-offs of using AI tools like Cloud Code, and critical bug bounty strategies regarding reporting quality and self-advocacy 0:00-0:54, 0:54-end.

Key Takeaways:
• Collaborating directly with Google engineers creates an iterative "hot and cold" feedback loop, significantly accelerating the identification of loopholes in AI logic and exploit development 0:00-0:15.
• Using Cloud Code with Tmux grants full control over reverse shells and speeds up codebase navigation, though it may reduce long-term personal comprehension of exploit mechanics 0:54-end.
• New exfiltration vectors include binary/boolean data encoding and HTML injection, which can yield high impact from minimal output, especially when AI has broad document access 0:54-end.
• Recording immediate POC videos is now essential for triage efficiency, as AI-generated reports often fail to convey impact clearly and cannot forge authentic video evidence 0:54-end.
• Hackers must advocate for themselves using "mouth tokens," leveraging live event access to discuss bugs directly with triagers and secure accurate severity assessments 0:54-end.
• Technical deep dives covered Protobuf manipulation via protoscope, OAuth grant scope expansion bugs in SDKs, and vulnerabilities in WebSocket and webhook architectures 0:54-end.

The episode emphasizes that while AI tools accelerate technical execution, succe

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

We're just kind of playing this kind of cat and mouse game of like does this do what Justin really wants it to do, you know, or what kind of loopholes could they potentially see into the plan? >> hot cold? Yeah, exactly. Yeah, it's like exactly. Warmer, warmer, warmer. Marco Polo. >> [music] >> What's the point of hacking when you can just, you know, critical thing, right? >> [laughter] >> Oh. Yeah. Dude. >> [music] >> Dude. Dude. >> [sighs] >> Exhausted at the end of Yeah, dude, I'm kind of jet lagged as heck for this episode right now, but we owe the people something, you know? Yeah, we were walking back to our rooms. Event's over and we're like, oh, we haven't recorded yet. >> Yeah, we we went out for like um for like what is that? >> Korean barbecue. >> Korean barbecue, man. Uh I ate s…