OpenAI expands Daybreak with GPT-5.6‑Cyber for trusted defenders

OpenAI announced an expansion of its Daybreak program with two access tiers for approved defenders and the release of GPT‑5.6‑Cyber, a purpose-trained cybersecurity model built on GPT‑5.6 Sol. The company framed the move as a response to a narrowing window for defenders as threat actors increasingly use AI to accelerate attacks.

Two-tiered Daybreak access

Daybreak Blue provides approved users access to frontier general-purpose models, including GPT‑5.6 Sol, with fewer system-level guardrails for defensive tasks such as vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Daybreak Red is intended for authorized vulnerability research, exploit validation, and security testing, and it grants access to purpose-trained models including GPT‑5.6‑Cyber.

Evaluations and real-world findings

OpenAI reported that GPT‑5.6‑Cyber completes 95.0% of requests in an internal Advanced Cybersecurity Completion Rate metric that covers exploit-chain development, authentication bypass, and privilege escalation scenarios. By comparison, GPT‑5.6 Sol completed 1.5% of those requests, and GPT‑5.6 Sol with Daybreak Blue completed 2.0%. GPT‑5.5‑Cyber completed 57.3% on the same metric, according to OpenAI.

The company said GPT‑5.6‑Cyber also outperformed earlier models on internal benchmarks such as ExploitGym and a zero-day discovery dataset, while noting GPT‑5.6 Sol can be more token-efficient on some exploit-development tasks. OpenAI reported that researchers used GPT‑5.6‑Cyber to discover multiple high-severity issues during product testing, including two V8 vulnerabilities that were reported and fixed as CVE-2026-15903, plus additional vulnerabilities across mobile operating systems, databases, and kernels.

Access controls and operational safeguards

OpenAI described a set of controls for Daybreak: identity verification, account security, monitoring, approved-use restrictions, and legal attestations. The company said it will require hardware security keys for all individual Daybreak accounts starting September 1, 2026, and is encouraging use of Codex auto-review mode, sandboxing, scoped permissions, and enhanced monitoring to limit risky actions.

OpenAI recommended Daybreak Blue as the starting point for most defenders and said teams needing advanced vulnerability research or exploit development can request Daybreak Red access through its partner program. The announcement emphasized continued work on monitoring, alignment training, and additional safety measures for future Daybreak releases.


Original source: OpenAI News

Leave a Comment