- Critical Thinking - Bug Bounty Podcast
- Posts
- [HackerNotes Ep. 194] Jev the Ranker, HTTP/3 Brute Force, and the Bug Bounty Doom Spiral
[HackerNotes Ep. 194] Jev the Ranker, HTTP/3 Brute Force, and the Bug Bounty Doom Spiral
Checking the news with new models and the shift in Bug Hunting
Hacker TL;DR
Anthropic is expanding the Cyber Verification Program to include Opus 5.5, with three tiers of trusted access topping out at the Claude Mythos models. Claude Security already ships with Mythos 5.1. The subsidized subs are the bait, and hackers are the one group with infinite token demand
Turbo Intruder 2 uses HTTP/3 over QUIC to hit 180k requests per second on plain WiFi: a 6 character alphanumeric code in ~6 hours, a 7 character one in ~9 days. The speed matters less than the bypass, and matrix parameters are where the real brute force wins live
Jev is a tiny, fast, cheap LLM that only outputs a boolean or a pick from a list. It is a ranker: rank the requests most likely to be vulnerable, rank a password list, rank a thousand attack ideas, or find the fixed line in an n-day diff. Pair it with siftrank
The economy is ugly. Salesforce is paying criticals only through year-end, PII is getting marked out of scope, and Fav found a bug touching 17 trillion Microsoft records and still got shafted on the payout

Sponsored by ThreatLocker – Privileged Access Management.
Fitting, since auth bypass and privilege escalation are the whole theme here: least privilege plus PAM are exactly what keeps a full auth bypass from turning into game over. Worth a look.
Opus 5.5, the CVP Tiers, and Turning Tokens Into Cash
Opus 5.5 landed and, as usual, is not much use for hacking out of the box. The interesting part is in Anthropic's latest blog post: the Cyber Verification Program is expanding to include Opus 5.5, with three tiers for increasingly permissive trusted access that reach the Claude Mythos models. Claude Security already ships with Mythos 5.1.
That is a real shift. Until now there was no clean way to escalate up to the less guardrailed models the way OpenAI offers a path to its red models. Communicate clearly about how you get in, then actually provide a route up to that second or third tier, and the gap closes.
The economics underneath are worth naming. The subsidized subs are bait. A single $200 sub can cost something like $10k in tokens for a heavy user, and hackers are the one group on earth with infinite demand for those tokens. We can max out the subs, turn tokens straight into cash, and come back for five or ten more.
On the guardrails side, the Daybreak toggle in the latest Codex UI is now independent from the model selector, so you run Daybreak on Luna, Terra, or Soul rather than picking it as a model. It looks less like a separate model and more like a system prompt with slightly relaxed guardrails that makes the model better at cyber. If that is all it is, the obvious move is to leak the prompt and try it on open source models.
Pro Tip: A lot of TAC access just got reset, and second accounts are getting renewal notices then bouncing at identity verification, even with the same persona and driver's license used every time before. Stay on top of renewals rather than assuming a clean account stays clean.
The Report Quality Squeeze
Following the codified-reports push from a couple of episodes back, a course correction. Codified reports that show the intended data path, then the circumvention path through the API, do establish that a security boundary exists and is being violated. The problem: not everybody lives in the API, and triagers are pushing back and asking for a plain screenshot and a video.
Reports with a recorded video still do the best by a wide margin, so it is worth the time. Having Codex or Claude Code draft the reply to a needs-more-info is convenient but sometimes lands sloppy. And there is an obvious irony: if you are using AI to answer the triager, the triager is probably using AI to triage it.
Jev Is a Ranker
Jev got the most airtime, and it deserves it. It is a very small, very fast, very cheap LLM, supposedly about as smart as Opus 4.6, with one hard constraint: it only outputs a boolean or a pick from a list. Context is limited, around 32k tokens, and it cannot produce free-form function arguments. What it can do is decide, near instantly and for almost nothing.
That constraint is less limiting than it sounds:
More options than fit in one call? Chunk them. Best of the first hundred, best of the second hundred, then a final call to compare the winners
Need to fill a function's parameters? Consecutive calls, one to pick the function, then one per parameter slot
It crawls websites by treating every link on the page as the choice set, and reportedly plays Doom on micro decisions between left, right, up, down
The frame that makes it click: Jev is a ranker, and ranking problems are everywhere. That is where the cyber value is:
Have a smart model generate a thousand attack ideas, then have Jev rank which to try first
Point it at every request in a Caido project and rank the ones most likely to be vulnerable
Feed it a thousand candidate passwords and rank the most likely for a brute force
Hand it an n-day PR diff and have it pick the vulnerable line that got patched
The pipeline: use your Codex sub for attack-vector ideation, sift and rank with Jev via siftrank, then hand the shortlist to a mid-tier model like Sonnet to implement. The counterpoint is that this tips into over-engineering fast, and sometimes the right answer is still just pointing the smartest model at the whole thing.
We do subs at $25, $10, and $5, premium subscribers get access to:
– Hackalongs: live bug bounty hacking on real programs, VODs available
– Live data streams, exploits, tools, scripts & un-redacted bug reports
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
Turbo Intruder 2 and the HTTP/3 Brute Force Math
PortSwigger dropped Turbo Intruder 2, optimizing requests further using HTTP/3, a UDP based protocol over QUIC. Skip the handshakes, stop dealing with streams the same way, and the numbers get absurd: 100k requests per second over normal WiFi, no dedicated VPS, with a best result of 180k per second.
Run the math and "not brute forceable" gets a rewrite. A 6 character alphanumeric code falls in ~6 hours, a 7 character one in ~9 days, case insensitive, assuming the server actually responds that fast.
The honest hot take: it is hard to remember the last time anyone genuinely needed 100k requests in a second. FFUF has been enough for years. The real value is that this makes rate limits and code brute forcing viable again, and brute forcing a verification code is behind a long line of Meta account takeovers. Dumb attack, huge impact when it lands.
The technique worth stealing is the rate-limit bypass. When rate limiting is tied to a specific endpoint, matrix parameters (the semicolon parameters in the path, the Spring ones) can break the mapping. If the WAF does not treat the path with an added matrix parameter as the same endpoint, every rotation of the parameter gives a fresh rate limit while the request still hits the same backend. Rotate, dodge the limit, brute force what was never meant to be brute forceable.
The Doom and Gloom Section
Programs are getting overrun, pausing, and shutting down. The headline is Salesforce moving to criticals-only from September 25 through December 31, a full quarter. Call it the "high, no bounty" problem: so many bugs get downgraded to high for UI-required, non-critical-asset, or mitigating-condition reasons, and going from a decent critical payout straight to zero at the high line almost breaks the bug economy. Every financially motivated hunter either skips it, holds their highs until January, or marks everything critical.
It gets worse. PII is being marked out of scope, per a screenshot Nathan Jones posted of a report closed with exactly that reasoning (not Salesforce, but the same energy). Hacking a program where even mediums are out of scope is risky. A medium is often a $700 bug, not nothing, and a high that would have been $2k dropping to a medium over 0.1 CVSS means you walk away with zero.
The forecast is the interesting part. Pentesting currently pays disproportionately well because hacking agents find more than humans ever could, faster. Within a year or two that flips: once the easy layer is cleaned out and companies run agents internally, pentesting becomes a commodity anyone can do by pointing Codex at a scope, and the price bottoms out. Bug bounty goes the other way, because companies will still pay well for the crazy bugs the agents cannot find, so per-bug payouts climb. The longer arc is a swing back to tester-guided AI hacking, where human and model go deep into one app together instead of yeeting a million agents at fresh scope.
Fav and the 17 Trillion Microsoft Records
The standout finding, with a blog on the way, is Fav's Microsoft bug. Without spoiling it, the writeup could have exposed something on the order of 17 trillion records: Bing searches, Copilot data, and more. Had a bad actor found it first, the impact would have been in the millions or tens of millions from lawsuits, extortion, and the class action that follows a public release.
The frustrating part is the payout. Microsoft's table tops out around $20k, and even after the genuinely good move to pay all crits regardless of prior scope, this one felt like a shafting. It sharpens a recurring debate: if you attack an out-of-scope asset that has access to an in-scope asset's data, and you prove impact through it, that should pay. The asymmetry is the tell. Nobody expects a payout when an out-of-scope asset does not touch anything in scope, so the reverse should hold. And unless the company could not have secured it short of dropping the third party, they have usually also misconfigured something, over-trusted a vendor, or installed it wrong.
Threat Modeling Still Wins
Three reports on a long-awaited program came back downgraded to low when they should not have been, all $100 lows, plus a fourth that paid a $50 bonus. Then the comment on one landed: this is only exploitable if the victim's computer was already owned. Fair. And one bad self-own makes the triager feel justified on the rest of their calls.
Threat modeling is still where the meat is. Twenty minutes sitting with the AI, saying here are the JavaScript files, here are the docs, here is how I set up these five accounts and objects, try this and this, is when the good stuff falls out. It is easy now to point a hackbot at something, never understand the threat model, get deceived by an incorrect one, and collect an N/A. The harness and the human guidance around the model matter as much as the model.
Resources
Turbo Intruder 2 and HTTP/3 - the writeup behind the 180k requests per second numbers and the brute force math
Jev by TypeSafe AI - the System One model announcement, choice, score, and boolean primitives
siftrank - noperator's ranking tool built on Jev
How I Could've Accessed 17 Trillion Microsoft Records - Fav's Microsoft writeup, watch for the full drop
That's it for the week, keep hacking!
