OpenAI Bolsters Daybreak With GPT-5.5-Cyber

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI released an improved GPT-5.5-Cyber model to trusted defenders as part of its Daybreak initiative, calling it its 'strongest model yet for finding and helping patch software vulnerabilities' with deeper analysis across large codebases.
- OpenAI updated its Codex Security plugin to enable deep scans, severity reports, attack path tracing, threat modeling, and codebase-specific patch generation, plus triage of existing findings from scanners, advisories, bug-bounty reports, and ticketing systems.
- OpenAI launched Patch the Planet in partnership with Trail of Bits to secure open-source projects, with initial participants including cURL, NATS Server, pyca/cryptography, Sigstore, aiohttp, the Go project, freenginx, Python, and python.org.
- Daybreak has already surfaced dozens of vulnerabilities, including 8 kernel pointer info-leak PoCs and 24 local privilege escalation exploits in the Linux Kernel, 34 vulnerabilities and 7 LPE PoCs in FreeBSD, 5 exploitable Chrome V8 bugs, 10 Apple Safari vulnerabilities, and a WebAssembly flaw in Firefox.
- OpenAI noted a 29-year-old flaw in the Squid web proxy (CVE-2026-47729, aka Squidbleed) that can leak cleartext HTTP requests, illustrating that AI models can now flag security issues that might have otherwise stayed hidden.
- The bottleneck in cybersecurity has shifted from finding vulnerabilities to patching them, as frontier models accelerate discovery and overwhelm maintainers with an ever-increasing volume of bugs needing verification, triage, and fixes.
- Intelligence agencies from Australia, Canada, New Zealand, the U.K., and the U.S. warned that advanced AI models will exceed current industry expectations within 'months, not years,' fundamentally transforming offensive and defensive cyber capabilities.
Why it matters: The bottleneck has flipped from finding bugs to fixing them, and OpenAI is putting frontier AI tools directly in the hands of open-source maintainers — the people who secure the shared infrastructure the rest of the stack depends on. By naming specific projects (cURL, Python, Go, Sigstore) and specific vulnerability counts, OpenAI is making a concrete capacity claim: defenders can now close the gap that AI-accelerated discovery is opening.




