OpenAI expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a model built for vulnerability research, as AI-driven cyberattacks increase, TechCrunch and The Decoder reported Monday.
Daybreak now runs in two tiers. Daybreak Blue gives approved defenders access to GPT-5.6 Sol with adjusted safeguards for vulnerability discovery, secure code review, malware analysis, incident response and patch validation, according to TechCrunch. Daybreak Red adds exclusive access to GPT-5.6-Cyber for vulnerability research, exploit validation and security testing.
GPT-5.6-Cyber, built from GPT-5.6 Sol, answered 95% of sensitive cybersecurity queries in OpenAI's internal benchmark, covering exploit development, authentication bypass and privilege escalation, compared with 1.5% for the standard model with its safety measures active, The Decoder reported.
The model found two previously unknown vulnerabilities in Chrome's V8 JavaScript engine that could be chained together, and at least five vulnerabilities in a mobile operating system, including a privilege escalation flaw, according to The Decoder's account of OpenAI's disclosure.
Access to GPT-5.6-Cyber is limited for now to trusted partners including Accenture, IBM, Crowdstrike and Cloudflare, TechCrunch reported. Starting Sept. 1, Daybreak Red will require identity verification, legal declarations and mandatory hardware security keys, according to The Decoder.
The expansion comes as threat actors increasingly use AI to run attacks at greater speed and scale, TechCrunch reported, pointing to recent AI-related security incidents including a breach at Hugging Face.
For builders, the model's own exploit discoveries are the real signal here. A frontier lab just showed a model finding chainable browser and mobile bugs faster than a restricted partner list can absorb them, which means any team shipping internet-facing software should assume attackers get comparable tooling well before Daybreak Red's waitlist reaches them.