Sunday, Aug 23 | --:--
Back to home

OpenAI Expands Daybreak with GPT‑5.6‑Cyber for Trusted Defenders

On August 10, 2026, OpenAI expanded its Daybreak cyber program into Daybreak Blue and Daybreak Red access tiers and introduced GPT‑5.6‑Cyber—a purpose-trained cybersecurity model that completes 95% of advanced dual-use cyber requests in internal tests versus 1.5% for GPT‑5.6 Sol—after using the model to find Chrome V8 zero-days patched as CVE-2026-15903.

Tech Insights Reporter 6 min read San Francisco, CA
Cover illustration for OpenAI Expands Daybreak with GPT‑5.6‑Cyber for Trusted Defenders

TLDR

OpenAI on August 10, 2026 published “Expanding Daybreak as the Cyber Defense Window Narrows,” splitting trusted cyber access into Daybreak Blue and Daybreak Red and launching GPT‑5.6‑Cyber—a cybersecurity-specialized model built on GPT‑5.6 Sol. Blue unlocks Sol with defensive-security-calibrated safeguards; Red adds purpose-trained cyber models for authorized vulnerability research and exploit validation. On an internal Advanced Cybersecurity Completion Rate eval, GPT‑5.6‑Cyber completes 95.0% of advanced dual-use cyber requests versus 1.5% for Sol and 57.3% for GPT‑5.5‑Cyber. OpenAI says the model helped find two previously unknown V8 issues chained toward heap-sandbox escape, disclosed to Google and fixed as CVE-2026-15903.

What shipped

Item Detail (OpenAI Security primary)
Daybreak Blue Frontier general models (GPT‑5.6 Sol) with safeguards tailored for authorized defensive work: vuln discovery, secure code review, malware analysis, IR, patch validation
Daybreak Red Purpose-trained cyber models for authorized exploit validation, red-team research, advanced security testing
GPT‑5.6‑Cyber Built on Sol; trained to reduce refusals and improve exploit-chain / zero-day research workflows
Refusal metric 95.0% completion on Advanced Cybersecurity Completion Rate vs 1.5% Sol, 2.0% Sol+Blue, 57.3% GPT‑5.5‑Cyber
ExploitGym GPT‑5.6‑Cyber outperforms Sol and GPT‑5.5‑Cyber on turning known vulns into working exploits (internal hardened setup)
Real findings CVE-2026-15903 (Chrome V8 high-severity); additional claimed finds: ≥5 mobile OS issues, 3 critical database vulns, 400+ kernel privilege-escalation issues (disclosure ongoing)
Preparedness Assessed High cyber capability, below Critical (same band as Sol; not Astra Critical territory)
Access Approved individuals and orgs only; identity verification, monitoring, legal attestations; hardware security keys required for individual Daybreak accounts from September 1, 2026
Codex guidance Push toward auto-review mode over full-access; updated Codex safety docs

OpenAI explicitly states GPT‑5.6‑Cyber was not involved in the earlier Hugging Face evaluation incident and is not the model planned for an unrestricted public cyber free-for-all.

Product-line placement

Distinct from Astra Critical cyber pause (Aug 7 Preparedness threshold) and GPT‑5.6 Sol / Luna free-tier (Aug 6 consumer retune). Daybreak is the trusted-access cyber product line: distribution of capability under identity gates, not a ChatGPT default model switch. Do not dual-date secondary Aug 8–9 wire recaps of the Aug 7 Astra post as this ship.

Why this story matters

Frontier labs are racing to arm defenders without flooding the open internet with Critical-class cyber agents. Daybreak Red’s 95% “completion” figure is a refusal metric, not a guarantee of exploit quality—but real CVE disclosure and partner quotes (e.g. SpecterOps) make this more than a blog benchmark. Watch: system card publication; how Blue vs Red enrollment scales; whether AWS and other cloud paths (shipped Aug 11) become the enterprise default; and how rivals answer with their own trusted cyber programs.

Sources

Prior Coverage

Earlier Times of AI reporting on this thread.

Scroll to continue reading