OpenAI Introduces GPT 5.6 Cyber Through Daybreak Red For Advanced Security Research

OpenAI Introduces GPT 5.6 Cyber Through Daybreak Red For Advanced Security Research

OpenAI has introduced GPT 5.6 Cyber, a cybersecurity focused artificial intelligence model designed to support vulnerability research, penetration testing, exploit validation, and incident response. The new model is built on GPT 5.6 Sol and has been specifically trained to improve performance across advanced cybersecurity tasks while reducing refusals for certain higher risk dual use activities related to exploit development. According to OpenAI, GPT 5.6 Cyber is being made available through Daybreak Red, a dedicated access tier that provides approved organizations with controlled access to purpose built cybersecurity models for authorized security testing and research. The release expands the company’s Daybreak initiative, which aims to equip trusted security organizations with advanced AI capabilities to help identify and remediate vulnerabilities before they can be exploited.

OpenAI stated that GPT 5.6 Cyber builds upon GPT 5.5 Cyber, which was introduced in June 2026, and delivers significantly improved performance on specialized cybersecurity workflows. To measure the model’s willingness to complete advanced cybersecurity requests, the company developed an internal benchmark called Advanced Cybersecurity Completion Rate. The evaluation measures responses related to exploit chain development, authentication bypass, privilege escalation, and similar advanced security scenarios. According to OpenAI, GPT 5.6 Cyber completed 95 percent of these requests compared with only 1.5 percent for GPT 5.6 Sol and 2 percent when accessed through Daybreak Blue. GPT 5.5 Cyber completed 57.3 percent of the same requests. Benchmark testing using ExploitGym also indicated that GPT 5.6 Cyber outperformed both GPT 5.6 Sol and GPT 5.5 Cyber in exploit development and advanced security research tasks. The company also noted improvements in identifying and accurately assessing the severity of previously unknown zero day vulnerabilities, although the model was found to generate shorter and less detailed vulnerability reports than GPT 5.6 Sol during open ended vulnerability research.

OpenAI disclosed that GPT 5.6 Cyber has already assisted in identifying several significant software vulnerabilities. Among them is CVE 2026 15903, an out of bounds read and write vulnerability in Google’s V8 JavaScript engine with a CVSS score of 8.8. The flaw could allow a remote attacker to execute arbitrary code inside a sandbox through a crafted HTML page and could be combined with another previously unknown vulnerability discovered by the model to escape the V8 heap sandbox. Google addressed the issue in a security update released during July 2026. OpenAI also reported that the model helped identify at least five vulnerabilities in a widely used mobile operating system, including a chain leading from an untrusted application to local privilege escalation, three critical vulnerabilities in a popular database that could enable remote code execution, and more than 400 privilege escalation vulnerabilities affecting a widely deployed operating system kernel. The company emphasized that these discoveries demonstrate the model’s ability to support advanced defensive security research when used within approved environments.

GPT 5.6 Cyber is available only through Daybreak Red, while Daybreak Blue continues to provide access to GPT 5.6 Sol with security guardrails designed for defensive cybersecurity activities. OpenAI explained that Daybreak Red is intended for specialized engagements such as penetration testing and exploit validation under controlled conditions. Access is currently limited to trusted partners including Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC, and Sophos. OpenAI acknowledged that models with reduced safeguards carry additional risks if misused, but stated that expanding access to trusted cybersecurity professionals is necessary to strengthen cyber defense capabilities. At the same time, the company cited independent research showing that while AI models have become increasingly effective at discovering vulnerabilities, they still require significant human expertise when generating reliable software patches, reinforcing the need for experienced security professionals to oversee remediation efforts.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment