OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI launched GPT-5.6-Cyber, built on GPT-5.6 Sol and trained to find zero-day vulnerabilities and develop exploit chains with reduced refusals for dual-use cyber tasks, available through a new Daybreak Red tier.
- GPT-5.6-Cyber completes 95.0% of advanced cybersecurity requests — including exploit-chain development, authentication bypass, and privilege escalation — versus just 1.5% for GPT-5.6 Sol and 2.0% under Daybreak Blue, per OpenAI's internal Advanced Cybersecurity Completion Rate benchmark.
- GPT-5.6-Cyber discovered CVE-2026-15903, an out-of-bounds read/write V8 JavaScript engine flaw (CVSS 8.8) that Google patched in mid-July 2026 and that can be chained with another unknown vulnerability to escape the V8 heap sandbox.
- OpenAI provided early access to ten trusted partners — Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC, and Sophos — to identify and patch vulnerabilities before attackers exploit them.
- GPT-5.6-Cyber also flagged at least five vulnerabilities in a mobile OS, three critical flaws in a database, and over 400 privilege-escalation issues in an OS kernel, though it produces shorter, less detailed vulnerability reports than GPT-5.6 Sol.
- 1Password research found LLM-generated patches fully resolve the underlying vulnerability only 26.0% of the time, while 53.9% of patches fail to resolve it, introduce a new vulnerability, or both — underscoring that discovery outpaces remediation.
- OpenAI acknowledged that models running with reduced safeguards carry risks beyond standard usage, including from misuse or misalignment, but said democratizing frontier intelligence for defenders is crucial to accelerating cyber defense.
Why it matters: OpenAI is handing a vulnerability-finder that nails 95% of exploit requests to ten major security vendors — but with 1Password showing LLM patches only work 26% of the time, defenders are gaining a far better flaw-spotter than flaw-fixer, widening the gap between finding and actually fixing vulnerabilities.
Ask SkimNews




