OpenAI Ships GPT-5.6-Cyber, Its First Offense-Grade Hacking Model — Gated Behind ID Verification
OpenAI launched GPT-5.6-Cyber, a variant of GPT-5.6 Sol trained to find zero-days and build exploit chains, available only through the vetted Daybreak Red tier. It already found two unpatched V8 bugs, now fixed as CVE-2026-15903.
OpenAI announced GPT-5.6-Cyber on August 10, its first model explicitly trained to hunt zero-days and chain exploits. The gap between it and OpenAI’s standard model tells the whole story: on OpenAI’s internal Advanced Cybersecurity Completion Rate, GPT-5.6-Cyber answers 95.0% of advanced offensive-security prompts, versus 1.5% for standard GPT-5.6 Sol.
Access is deliberately narrow. The model exists only inside Daybreak Red, the applicant-vetted tier of OpenAI’s Daybreak defender program. Getting in requires identity verification, account security requirements, usage monitoring, approved-use restrictions, and legal attestations. Press reporting — not confirmed by OpenAI itself — names Accenture, IBM, CrowdStrike, and Cloudflare among the first trusted customer partners.
The model isn’t strictly superior across the board. On OpenAI’s own Vulnerability Discovery and Report Writing evaluation, GPT-5.6-Cyber actually scores worse than plain Sol, and Sol also beats it on ExploitBench at the standard 300-turn setting while burning fewer tokens. OpenAI’s read: GPT-5.6-Cyber trades some general capability for depth on the narrow offensive-security tasks it was tuned for — a specialist, not a strictly-better generalist.
It’s already producing real findings. OpenAI used the model to discover two previously unknown vulnerabilities in V8, Chrome’s JavaScript engine, which Google has since patched as CVE-2026-15903. That’s the pitch in miniature: an AI system finding bugs in critical infrastructure before attackers do, then routing the disclosure through a legitimate vendor patch cycle.
The launch comes days after OpenAI paused work on Astra, a separate agent, after it neared the industry’s first “critical” cyber risk rating — and a rival buildout, Nvidia’s 37-member Open Secure AI Alliance, launched in late July without OpenAI, Anthropic, or Google as members. Read together, the sequence shows OpenAI trying to have it both ways: build and gate a genuinely offense-capable model for vetted defenders, while publicly signaling caution on its more autonomous, less controllable systems. Whether ID verification and legal attestations are sufficient gatekeeping for a model built to write exploit chains is the question every security team evaluating Daybreak Red access will have to answer for itself.
Sources
Related reading
- AI Models OpenAI Pauses Work on Astra After It Nears the First-Ever 'Critical' Cyber Risk Rating
- Cybersecurity Nvidia Forms 60-Member Open Secure AI Alliance to Fight Back Against AI-Powered Attacks
- Cybersecurity Microsoft Exchange Zero-Day CVE-2026-42897 Actively Exploited — No Full Patch, Automatic Mitigation Only