
Anthropic is using Claude Mythos 5 to scan code, rate vulnerabilities, and support partner security tools.
OpenAI is expanding its Daybreak cybersecurity program with GPT-5.6-Cyber, a specialized model for security researchers that can answer sensitive cybersecurity queries, support exploit validation, and has already helped find previously unknown Chrome vulnerabilities.

OpenAI is expanding its Daybreak cybersecurity program with two access tiers and a specialized model called GPT-5.6-Cyber. The goal is to give defenders more time to find vulnerabilities before attackers can use AI-powered offensive tools at scale. Daybreak Blue is focused on defensive work such as vulnerability detection, malware analysis, and incident response. Daybreak Red is aimed at security researchers working on vulnerability research, exploit validation, and penetration testing.

GPT-5.6-Cyber is available through Daybreak Red and is trained for more advanced cybersecurity tasks, including finding zero-day vulnerabilities and building exploit chains. In OpenAI’s internal “Advanced Cybersecurity Completion Rate” benchmark, GPT-5.6-Cyber answered 95 percent of sensitive cybersecurity queries, while GPT-5.6 Sol with safety measures enabled reached 1.5 percent and Daybreak Blue reached 2 percent. The previous GPT-5.5-Cyber model reached 57.3 percent. The key takeaway for defenders is that access and safeguards, not just model capability, are central to how OpenAI is positioning this tool.
OpenAI says access to either Daybreak tier requires identity verification, account security measures, monitoring, and legal declarations. Hardware security keys become mandatory for all Daybreak accounts on September 1, 2026. OpenAI also recommends isolated sandbox environments for security workflows and Auto-Review mode in Codex for actions that require elevated privileges. For organizations, the practical point is clear: the program is built around controlled access to capabilities that many general-purpose AI models would block.
OpenAI says GPT-5.6-Cyber analyzed V8, Chrome’s JavaScript engine, and found two previously unknown vulnerabilities that could be chained to corrupt memory and bypass the V8 heap sandbox. Google fixed the flaws after coordinated disclosure and assigned the CVE-2026-15903 designation. OpenAI also says the model found at least five vulnerabilities in a “popular mobile operating system,” including a chain that could let an app escalate restricted access to full administrator privileges. Under OpenAI’s Preparedness Framework, GPT-5.6-Cyber is rated “High” for cybersecurity capabilities but does not reach the “Critical” threshold.

Anthropic is using Claude Mythos 5 to scan code, rate vulnerabilities, and support partner security tools.
Orion Hindawi returns as Tanium CEO as the cybersecurity company responds to AI-driven software shifts.

U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.