ModelsAI Safety 🇩🇪 10.08.2026 21:02

OpenAI introduces GPT-5.6-Cyber: New AI model aims to help defenders find vulnerabilities before attackers

OpenAIOpenAI
OpenAI expands its Daybreak cybersecurity program with two access tiers and the new AI model GPT-5.6-Cyber to help defenders find vulnerabilities and develop exploits early. The program now includes Daybreak Blue for defensive tasks and Daybreak Red for offensive security research, with GPT-5.6-Cyber available through the Red tier, answering 95% of sensitive security queries.
OpenAI is expanding its Daybreak program with two access tiers and a new specialized model called GPT-5.6-Cyber, designed to help defenders find vulnerabilities and develop exploits before attackers deploy AI-powered offensive tools at scale. According to OpenAI, threat actors will increasingly use AI for cyberattacks, including in fully autonomous form, shrinking the time window for defenders to prepare. An example of this was when OpenAI unintentionally had its models hack Hugging Face and other services. Daybreak Blue provides access to GPT-5.6 Sol with adjusted guardrails for authorized defensive work such as vulnerability detection, malware analysis, and incident response. Daybreak Red is aimed at security researchers conducting vulnerability research, exploit validation, and penetration testing. Access to both tiers requires identity verification, account security, monitoring, and legal declarations. Starting September 1, 2026, hardware security keys will be mandatory for all Daybreak accounts. OpenAI also recommends running security workflows in isolated sandbox environments and using the auto-review mode in Codex. GPT-5.6-Cyber, based on GPT-5.6 Sol, is available through the Red tier and answers 95% of queries in an internal benchmark called 'Advanced Cybersecurity Completion Rate', covering scenarios like exploit chain development, authentication bypass, and privilege escalation. In contrast, GPT-5.6 Sol with guardrails achieves 1.5%, with Daybreak Blue 2%, and the predecessor GPT-5.5-Cyber 57.3%. In a concrete test, only GPT-5.6-Cyber over Daybreak Red produced functional exploit code for a WebSocket authentication bypass, while other variants refused. On ExploitGym, GPT-5.6-Cyber outperforms both GPT-5.6 Sol and GPT-5.5-Cyber. OpenAI used GPT-5.6-Cyber for real vulnerability research, finding two previously unknown vulnerabilities in Chrome's V8 JavaScript engine that can be chained for memory corruption and bypassing the V8 heap sandbox; Google fixed them as CVE-2026-15903. Additionally, GPT-5.6-Cyber found at least five vulnerabilities in a 'popular mobile operating system', including a chain that could escalate app privileges to administrator. OpenAI works with Daybreak partners and the open-source community on disclosure. Under OpenAI's Preparedness Framework, GPT-5.6-Cyber is rated 'High' for cybersecurity capabilities, not reaching the 'Critical' threshold that the Astra model might achieve.
Abbreviations
CVE = Common Vulnerabilities and Exposures — Общие уязвимости и эксплойты
Source: The Decoder (DE) — original
Our earlier posts on this topic ↓
Fresh news