AI News

OpenAI Launches GPT-5.6-Cyber for Vetted Security Researchers

OpenAI Gates GPT 5.6 Cyber Behind New Daybreak Red Tier

OpenAI has rolled out GPT-5.6-Cyber, a new AI model built specifically for advanced cybersecurity work. This tool targets tasks like vulnerability research, exploit validation, penetration testing, red teaming, incident response, and security testing. As of now regular users aren’t getting direct access, and the AI giant is currently only sharing it with approved defenders through its Daybreak program.

OpenAI says the approach reflects cyber threats accelerating as attackers adopt AI. The company frames it as putting frontier capability with trusted defenders before attackers deploy offensive AI at scale. Approved partners can use these models in security products, managed services, and customer work, but only under strict conditions like identity checks, monitoring, defined scopes, legal requirements, and human oversight.

OpenAI Expands Daybreak with Two Access Levels

There are now two tiers in the Daybreak program: Daybreak Blue and Daybreak Red, each geared for a different intensity of cybersecurity work.OpenAI lists GPT-5.6-Cyber at $12.50 per million input tokens and $75 per million output, against $5 and $30 for Sol in the same Daybreak pricing table.

Daybreak Blue lets defenders use frontier general-purpose models like GPT-5.6 Sol, with protections in place for authorized defensive security. OpenAI suggests most defenders start here. The model can help with things like finding vulnerabilities, secure code review, malware analysis, incident response, vulnerability management, investigations, security assessments, and patch validation.

Daybreak Red is the more specialized track. It provides access to dedicated cybersecurity models meant for advanced work: vulnerability research, exploit validation, and security testing. That’s where GPT-5.6-Cyber comes in.

OpenAI says GPT-5.6-Cyber builds on GPT-5.6 Sol, improving at specialized cybersecurity jobs, like zero-day vulnerability hunting and developing exploit chains. It is also trained to refuse fewer high-risk, dual-use requests where the work is authorised. OpenAI notes that Sol declines many such prompts, including penetration testing against production systems, even with system-level guardrails lifted. The results show up in OpenAI’s internal Advanced Cybersecurity Completion Rate test, which tracks how often the models finish advanced tasks like exploit-chain development, authentication bypass, and privilege escalation. GPT-5.6-Cyber completed 95% of these requests, against GPT-5.5-Cyber’s 57.3%. GPT-5.6 Sol, running in Daybreak Blue, managed just 2%, and with standard safeguards, only 1.5%. Under OpenAI’s Preparedness Framework, the model is rated High for cybersecurity capability, below the Critical threshold that would trigger further restrictions.

GPT-5.6-Cyber Finds Vulnerabilities in Real Software

OpenAI also reports that GPT-5.6-Cyber has already done real vulnerability research. In one case, researchers used the model to analyze V8, Chrome’s JavaScript engine, and found two previously unknown vulnerabilities. They discovered that these could be chained together to corrupt memory and break out of the V8 heap sandbox. OpenAI worked with Google on disclosure, and Google fixed one of the problems, tracking it as CVE-2026-15903.

According to OpenAI, CVE-2026-15903 was a high-severity flaw in V8’s optimizing compiler. The compiler skipped a security check when converting values to integers, which meant an undefined value could suddenly become a huge number. If that number was used as an array index, the compiler might assume it was safe and skip bounds checking. That let an attacker read or overwrite memory that belonged to other objects, and potentially run arbitrary code in Chrome’s sandbox. Escaping the heap sandbox required a second vulnerability, and OpenAI says GPT-5.6-Cyber found that one too.

OpenAI adds that the model found at least five vulnerabilities in a major mobile operating system, including a chain allowing an untrusted app to escalate privileges locally, three critical remote code execution flaws in a widely used database, and more than 400 privilege-escalation vulnerabilities in a popular OS kernel. The company did not name any of these products.

OpenAI’s tests show that GPT-5.6-Cyber isn’t always better than GPT-5.6 Sol at every cybersecurity task. On ExploitGym, where agents try to turn known vulnerabilities into real exploits for code execution in controlled scenarios, GPT-5.6-Cyber did better than GPT-5.6 Sol and GPT-5.5-Cyber. But in internal tests for vulnerability discovery and report-writing, GPT-5.6-Cyber didn’t perform as well as GPT-5.6 Sol, it often wrote shorter, less detailed reports.

Who Can Access GPT-5.6-Cyber

On ExploitBench, GPT-5.6 Sol won in the standard 300-turn setting. When the limit was increased to 600 turns, the performance gap between models narrowed. Daybreak access remains tightly controlled. OpenAI says only approved individuals and organizations doing authorized security work get in, and they face requirements like identity verification, account security, monitoring, approved-use controls, and legal attestations.

The controls arrive weeks after OpenAI disclosed that two of its models escaped a sandboxed environment during internal cyber testing, exploited a zero-day, and reached Hugging Face’s production systems before being contained. That incident involved models running with safeguards deliberately relaxed for evaluation. GPT-5.6-Cyber is a model shipped with reduced refusals by design, which places more weight on the identity checks, monitoring, and hardware key requirements than on the model’s own guardrails.

Daybreak customers using Codex are encouraged to turn on auto-review mode, which checks any action needing high-level permissions before allowing it. Starting September 1, 2026, every individual Daybreak account will need to use hardware security keys. Approved partners include Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps. Supported security vendors are Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare. OpenAI is also inviting new cybersecurity providers and consultants to apply for the Daybreak Cyber Partner program, which keeps GPT-5.6-Cyber access inside a controlled security framework.

Devanshi Kashyap
Devanshi is a curious learner who enjoys exploring new ideas and expressing creativity through art.
You may also like
More in:AI News