Open AI3 mins read

OpenAI’s GPT-5.6-Cyber pushes AI deeper into vulnerability research

OpenAI is expanding its Daybreak cybersecurity program with GPT-5.6-Cyber, a specialized model for security researchers that can answer sensitive cybersecurity queries, support exploit validation, and has already helped find previously unknown Chrome vulnerabilities.

What OpenAI is launching

OpenAI is expanding its Daybreak cybersecurity program with two access tiers and a specialized model called GPT-5.6-Cyber. The goal is to give defenders more time to find vulnerabilities before attackers can use AI-powered offensive tools at scale. Daybreak Blue is focused on defensive work such as vulnerability detection, malware analysis, and incident response. Daybreak Red is aimed at security researchers working on vulnerability research, exploit validation, and penetration testing.

Why GPT-5.6-Cyber matters for security teams

Advanced Cybersecurity Completion Rate chart for GPT-5.6-Cyber and related models
Image credits:OpenAI

GPT-5.6-Cyber is available through Daybreak Red and is trained for more advanced cybersecurity tasks, including finding zero-day vulnerabilities and building exploit chains. In OpenAI’s internal “Advanced Cybersecurity Completion Rate” benchmark, GPT-5.6-Cyber answered 95 percent of sensitive cybersecurity queries, while GPT-5.6 Sol with safety measures enabled reached 1.5 percent and Daybreak Blue reached 2 percent. The previous GPT-5.5-Cyber model reached 57.3 percent. The key takeaway for defenders is that access and safeguards, not just model capability, are central to how OpenAI is positioning this tool.

Access comes with verification and controls

OpenAI says access to either Daybreak tier requires identity verification, account security measures, monitoring, and legal declarations. Hardware security keys become mandatory for all Daybreak accounts on September 1, 2026. OpenAI also recommends isolated sandbox environments for security workflows and Auto-Review mode in Codex for actions that require elevated privileges. For organizations, the practical point is clear: the program is built around controlled access to capabilities that many general-purpose AI models would block.

Early results include Chrome vulnerability findings

OpenAI says GPT-5.6-Cyber analyzed V8, Chrome’s JavaScript engine, and found two previously unknown vulnerabilities that could be chained to corrupt memory and bypass the V8 heap sandbox. Google fixed the flaws after coordinated disclosure and assigned the CVE-2026-15903 designation. OpenAI also says the model found at least five vulnerabilities in a “popular mobile operating system,” including a chain that could let an app escalate restricted access to full administrator privileges. Under OpenAI’s Preparedness Framework, GPT-5.6-Cyber is rated “High” for cybersecurity capabilities but does not reach the “Critical” threshold.

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile