OpenAI announced a major expansion of its Daybreak cybersecurity initiative on August 10, introducing GPT-5.6-Cyber — a purpose-built model for authorized vulnerability research, exploit validation, and security testing.
The new model, built on GPT-5.6 Sol, achieves a 95.0% completion rate on advanced cybersecurity tasks including exploit-chain development, authentication bypass, and privilege escalation. That's a dramatic improvement over the standard GPT-5.6 Sol model, which completes just 1.5% of such requests, and even the previous GPT-5.5-Cyber at 57.3%.
The Daybreak program now offers two access tiers: Daybreak Blue provides frontier general-purpose models with tailored safeguards for defensive security work, while Daybreak Red gives access to purpose-trained cybersecurity models like GPT-5.6-Cyber for more advanced authorized work.
OpenAI has already used the model to find real vulnerabilities. GPT-5.6-Cyber discovered two previously unknown vulnerabilities in Chrome's V8 JavaScript engine that could be chained to corrupt memory and escape the V8 heap sandbox. Google assigned the findings as CVE-2026-15903, a high-severity vulnerability. The model has also identified at least five vulnerabilities in a popular mobile operating system, three critical vulnerabilities in a popular database, and over 400 privilege escalation vulnerabilities in a popular operating system kernel.
Early access partners including SpecterOps, SentinelOne, and Palo Alto Networks have reported significant improvements in their security workflows. "GPT-5.6-Cyber is materially improving our specialist vulnerability-research workflows," said Jared Atkinson, CTO of SpecterOps.




