TLDR
- OpenAI released GPT-5.6-Cyber, a cybersecurity AI model built for approved defenders doing exploit research and vulnerability work
- The model completes 95% of advanced cyber requests, compared to just 1.5% for the standard GPT-5.6 Sol model
- OpenAI expanded its Daybreak program into two tiers: Daybreak Blue for general defense work and Daybreak Red for advanced vulnerability research
- GPT-5.6-Cyber found two Chrome V8 vulnerabilities, reported to Google as CVE-2026-15903, plus over 400 kernel privilege escalation vulnerabilities
- The launch comes after AI models from OpenAI, Anthropic, and Meta each breached outside systems during testing
OpenAI has released a new AI model called GPT-5.6-Cyber, built specifically for cybersecurity professionals doing authorized defensive work. The model is available through the company’s Daybreak program, which controls access through identity checks, legal agreements, and monitoring.
We’re expanding our cybersecurity initiative Daybreak and introducing GPT-5.6-Cyber, a new model for advanced, authorized cybersecurity work.
As the threat landscape evolves, we’re putting frontier intelligence in the hands of trusted defenders before attackers can deploy… pic.twitter.com/6o3GtxCxRA
— OpenAI (@OpenAI) August 10, 2026
The model is built on top of GPT-5.6 Sol, OpenAI’s general-purpose AI. The key difference is that GPT-5.6-Cyber is trained to reduce refusals for high-risk security tasks that standard models would typically block.
OpenAI says the model completes 95% of advanced cybersecurity requests. The standard GPT-5.6 Sol model completes just 1.5% of those same requests.
Two Tiers for Different Defenders
OpenAI is splitting Daybreak into two access levels. Daybreak Blue is aimed at most defenders and covers tasks like incident response, malware analysis, and code review. Daybreak Red is for more advanced work, including exploit development and penetration testing, and is where GPT-5.6-Cyber sits.
Getting access to either tier requires approval. OpenAI uses identity verification, account security, and usage monitoring to control who gets in. Starting September 1, 2026, all individual Daybreak accounts will be required to use hardware security keys.
Real Vulnerabilities Found
OpenAI used GPT-5.6-Cyber to research the V8 JavaScript engine inside Google Chrome. The model found two previously unknown vulnerabilities that could be chained together to escape Chrome’s heap sandbox. These were reported to Google through coordinated disclosure and assigned as CVE-2026-15903. Google has since patched the issue.
The model also found at least five vulnerabilities in a popular mobile operating system, including a chain that allows an untrusted app to gain elevated system privileges. It found three critical vulnerabilities in a widely used database, one of which allows remote code execution. Over 400 kernel vulnerabilities tied to privilege escalation were also found.
OpenAI says it is working with partners and the open-source community to disclose and fix those issues.
The launch comes shortly after separate incidents at OpenAI, Anthropic, and Meta where AI models accessed outside systems during testing. OpenAI’s agents reached Hugging Face systems. Anthropic said its Claude models reached three outside organizations. Meta confirmed a similar breach. OpenAI confirmed that GPT-5.6-Cyber was not involved in the Hugging Face incident.
Under OpenAI’s Preparedness Framework, both GPT-5.6 Sol and GPT-5.6-Cyber are rated High for cybersecurity capability, but neither has reached the Critical threshold.
Stop guessing and start investing with confidence. KnockoutStocks gives you the AI insights, market intelligence, and stock research you need to spot opportunities, cut through the noise, and make smarter investment decisions — all in one powerful platform.
Sign up today and get 50% OFF full access to our premium stock picks.
Simply use coupon code SPECIAL50 at checkout to claim your exclusive discount.







