OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming

August 10, 2026

OpenAI has expanded its Daybreak program to give vetted security defenders deeper access to frontier AI models, introducing two access tiers—Daybreak Blue and Daybreak Red—alongside a new specialized model, GPT-5.6-Cyber, purpose-built for exploit validation, vulnerability research, and red teaming.

The move is a direct response to a widening gap between attacker and defender capabilities, as OpenAI warns that threat actors will increasingly use AI to launch cyberattacks at unprecedented speed and scale, including fully autonomous operations.

Daybreak Blue is designed as the recommended entry point for most defenders, offering access to GPT-5.6 Sol with safeguards tailored for authorized defensive work such as vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.

Daybreak Red goes further, unlocking purpose-trained cybersecurity models for advanced vulnerability research, exploit validation, and security testing under stricter vetting.

OpenAI Expands Daybreak Cyber

The core of Daybreak Red is GPT-5.6-Cyber, built on GPT-5.6 Sol but specifically trained to improve performance on tasks like zero-day discovery and exploit-chain development while reducing refusals on legitimate but high-risk dual-use security prompts, such as penetration testing production systems.

OpenAI’s internal Advanced Cybersecurity Completion Rate benchmark, which measures willingness to assist with exploit-chain development, authentication bypass, and privilege escalation tasks, shows GPT-5.6-Cyber completing 95% of such requests compared to just 1.5% for the standard safeguarded GPT-5.6 Sol and 2% under Daybreak Blue access.

That marks a substantial jump from its predecessor, GPT-5.5-Cyber, which completed only 57.3% of comparable requests, addressing persistent complaints from security researchers about excessive model refusals during legitimate work.

Beyond benchmark performance, OpenAI used GPT-5.6-Cyber to investigate Chrome’s V8 JavaScript engine and uncovered two previously unknown vulnerabilities that could be chained together to corrupt memory and escape the V8 heap sandbox.

The findings were disclosed to Google through coordinated vulnerability disclosure and patched as CVE-2026-15903, a high-severity flaw where the V8 optimizing compiler skipped a safety check during integer conversion, potentially allowing attackers to execute arbitrary code inside Chrome’s sandbox.

The model has also been credited with finding at least five vulnerabilities in a popular mobile operating system, three critical flaws in a widely used database, and over 400 privilege-escalation issues in a popular operating system kernel, with disclosures ongoing.

Under OpenAI’s Preparedness Framework, both GPT-5.6 Sol and GPT-5.6-Cyber were assessed as reaching the “High” cybersecurity capability threshold but remained below the “Critical” threshold.

OpenAI clarified that GPT-5.6-Cyber was not involved in the previously disclosed Hugging Face security incident. To mitigate misuse risks tied to reduced safeguards, OpenAI is mandating hardware security keys for all individual Daybreak accounts starting September 1, 2026, pushing Codex users toward auto-review mode instead of full-access mode, and rolling out enhanced monitoring in the coming weeks.

Access to Daybreak Blue and Red is restricted to approved individuals and organizations conducting authorized security work, gated by identity verification, monitoring, and legal attestations.

OpenAI recommends sandboxing workflows, scoping permissions tightly, and maintaining human oversight for higher-risk tasks.

Security firms including SpecterOps have already reported significant workflow acceleration, with SpecterOps CTO Jared Atkinson noting the model resolved specialist vulnerability-research work in under a day that had previously taken weeks. Organizations interested in Daybreak Red can apply through OpenAI’s partner program.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Original article can be found here