Press "Enter" to skip to content

OpenAI releases GPT-5.6-Cyber with expanded exploit research capabilities

OpenAI announced on Monday the launch of GPT-5.6-Cyber, a large‑language model designed specifically for cybersecurity tasks such as vulnerability research, penetration testing, and incident response. The model builds on the underlying GPT-5.6 Sol architecture but is tuned to lower refusal rates for higher‑risk, dual‑use cyber activities.

New model and access tiers

The company said GPT-5.6-Cyber is offered through a newly created access tier called Daybreak Red. Daybreak Red grants authorized firms the ability to use purpose‑trained cybersecurity models for activities that include exploit validation, authorized vulnerability research, and security testing. It follows the earlier Daybreak Blue tier, introduced as part of the Daybreak initiative in May 2026, which provides access to frontier general‑purpose models like GPT-5.6 Sol with built‑in guardrails for defensive security work.

Daybreak Blue “removes those guardrails, helping defenders get more out of the model in real‑world security tasks, including incident detection and response, investigations, vulnerability management, and security assessments,” OpenAI explained. By contrast, Daybreak Red deliberately relaxes safeguards to enable more permissive cyber‑focused interactions.

OpenAI listed a group of trusted customer partners that will receive early access to GPT-5.6-Cyber, including Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC and Sophos. The aim is to help these organizations identify and patch vulnerabilities before malicious actors can exploit them, thereby narrowing what the company calls the “defense gap.”

Performance benchmarks and findings

To quantify the model’s reduced refusal behavior, OpenAI created an internal metric named the Advanced Cybersecurity Completion Rate. The test suite measures how often the model responds to prompts involving exploit‑chain development, authentication bypass, privilege escalation and other advanced scenarios. GPT-5.6-Cyber completed 95.0 % of those requests, a stark contrast to the 1.5 % completion rate for GPT-5.6 Sol and 2.0 % when GPT-5.6 Sol is accessed via Daybreak Blue. The newer model also outperformed its predecessor GPT-5.5-Cyber, which completed 57.3 % of the same prompts.

Independent benchmark testing using the ExploitGym suite corroborated these results, showing GPT-5.6-Cyber surpassing both GPT-5.6 Sol and GPT-5.5-Cyber on a range of exploit‑development tasks. The model also demonstrated improved ability to locate and accurately assess the severity of novel zero‑day vulnerabilities, a benefit attributed to its specialized training data.

However, OpenAI noted that GPT-5.6-Cyber lags behind GPT-5.6 Sol on open‑ended tasks such as discovering vulnerabilities across a code repository, producing fully functional proof‑of‑concept exploits, and drafting comprehensive vulnerability reports. The company attributed the shortfall to the model sometimes generating “shorter, less detailed vulnerability reports.”

Among the vulnerabilities discovered by GPT-5.6-Cyber was CVE‑2026‑15903, a high‑severity (CVSS 8.8) out‑of‑bounds read/write issue in Google’s V8 JavaScript engine. The flaw could enable a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page and could be chained with another previously unknown vulnerability to escape the V8 heap sandbox. Google patched the issue in mid‑July 2026.

The model also flagged a broader set of flaws: at least five vulnerabilities in a popular mobile operating system—including a chain that elevates privileges from an untrusted app to a local admin level—three critical vulnerabilities in a widely used database that provide remote code execution paths, and more than 400 privilege‑escalation opportunities in a leading operating system kernel.

Implications for the security landscape

OpenAI positioned GPT-5.6-Cyber as a defensive tool at a time when threat actors are increasingly leveraging AI to accelerate cyber attacks. The company warned that AI agents enable cybercriminals and nation‑state hackers to outsource “grunt work,” allowing them to plan and execute attacks that are “better, bigger, and faster.” AI also shortens the timeline from vulnerability disclosure to exploitation, with attackers using generative tools to write exploits for newly disclosed flaws.

Despite the model’s strong discovery capabilities, external research indicates that current AI systems still require significant human expertise to produce reliable patches. A study cited by 1Password found that AI‑generated patches fully resolved a vulnerability without altering application behavior only 26.0 % of the time. Patches that resolved the issue but changed behavior occurred 20.1 % of the time, while 53.9 % of attempts either failed to fix the vulnerability, introduced a new one, or did both.

These findings highlight a gap: while models like GPT-5.6-Cyber excel at uncovering a wide range of security flaws, they are only effective at patching a narrow subset, potentially expanding the attack surface if flawed patches are deployed. OpenAI acknowledged that “models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment,” but argued that democratizing access to frontier intelligence for defenders is essential for accelerating and automating cyber defense.

As the cybersecurity community evaluates the trade‑offs between increased capability and reduced guardrails, the rollout of GPT-5.6-Cyber marks a notable shift in how generative AI is being integrated into both defensive and offensive security workflows.

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *