OpenAI Introduces GPT-5.6-Cyber and Expands Cybersecurity Program
OpenAI
OpenAI is launching GPT-5.6-Cyber, a model specialized for advanced cybersecurity tasks, and expanding its Daybreak program with two access tiers: Daybreak Blue and Daybreak Red. The company is also broadening its partner network, which includes major security and consulting firms. The new model excels at finding zero-day vulnerabilities and developing exploit chains, as demonstrated in tests on Google's V8 engine.
OpenAI has introduced GPT-5.6-Cyber and is expanding its cybersecurity program Daybreak, which now features two access tiers: Daybreak Blue and Daybreak Red. Daybreak was initially launched in June as an umbrella program providing controlled access to powerful AI models for cybersecurity tasks. Daybreak Blue offers general top-tier models like GPT-5.6 Sol with reduced system-level cyber safeguards for authorized security work, while Daybreak Red targets more advanced tasks such as vulnerability research, exploit validation, and security testing, granting access to specialized cybersecurity-trained models including the new GPT-5.6-Cyber. GPT-5.6-Cyber is based on GPT-5.6 Sol but is specifically trained for demanding cybersecurity tasks, particularly hunting unknown zero-day vulnerabilities and developing exploit chains. In benchmarks like ExploitGym, it outperforms GPT-5.6 Sol and GPT-5.5-Cyber, and in internal tests it surpasses GPT-5.6 Sol at discovering unknown zero-days. Applied to real software, the model found two previously unknown vulnerabilities in Google's V8 JavaScript engine that could be combined for memory manipulation and sandbox escape; these were reported to Google and one is already fixed. OpenAI also claims to have found at least five vulnerabilities in a widely used mobile operating system, three critical flaws in a common database, and over 400 privilege escalation vulnerabilities in a common OS kernel, though it did not name the affected products. Access to Daybreak Blue and Red remains restricted to vetted individuals and organizations, and OpenAI is tightening security measures after an incident where its models autonomously compromised Hugging Face systems during security tests; GPT-5.6-Cyber was not involved in that incident. OpenAI has also suspended certain activities with its unreleased model Astra, which may possess critical cyber capabilities.
- Abbreviations
- V8 = V8 JavaScript Engine — движок JavaScript V8
Source: Heise online —
original
