OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window
VulnOpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats. Daybreak now has two access levels. Blue gives approved defenders access to frontier general-purpose models such as GPT-5.6 Sol for authorized defensive work, while Red provides specialized cyber models for more advanced activities, including vulnerability research, exploit validation, and security testing. OpenAI said GPT-5.6-Cyber is designed to reduce refusals on higher-risk security tasks while improving its ability to conduct exploit development and vulnerability research. In an internal evaluation measuring how often models responded to advanced cybersecurity requests rather than refusing them, GPT-5.6-Cyber completed 95% of requests, compared with 2% for GPT-5.6 Sol under Daybreak Blue. The company has also used GPT-5.6-Cyber to investigate real-world software. OpenAI said the model uncovered two previously unknown flaws in Google’s V8 JavaScript engine. Used together, the flaws could enable memory corruption and an escape from V8’s heap sandbox. The findings were reported to Google through coordinated vulnerability disclosure. OpenAI categorized GPT-5.6-Cyber as reaching the “High” threshold for cybersecurity capability under its Preparedness Framework, but not the “Critical” threshold. Access to Daybreak is limited to approved individuals and organizations, with controls including identity verification and monitoring. OpenAI will also require all individual Daybreak accounts to use hardware security keys beginning September 1, 2026. Pressure on vulnerability response The immediate concern for security leaders is how quickly those capabilities could compress the time available to identify and remediate vulnerabilities.“CISOs should assume that the time between vulnerability discovery and exploitation will continue to shrink as advanced AI models accelerate vulnerability research, exploit validation, attack path analysis, and remediation activities,” said Biswajeet Mahapatra, principal analyst at Forrester. Mahapatra said the larger change is not necessarily the emergence of entirely new offensive capabilities, but the ability of attackers and defenders to perform existing tasks faster and at greater scale. “This increases pressure on organizations to move from periodic vulnerability management to continuous exposure management,” Mahapatra added. Keith Prabhu, founder and CEO of Confidis, also argued that models such as GPT-5.6-Cyber may accelerate vulnerability discovery and weaponization without fundamentally shifting the attacker-defender balance, because attackers and defenders are likely to gain access to broadly similar capabilities Governance for high-risk cyber AI Enterprises using frontier cybersecurity AI models should impose tighter internal access controls, isolate them in air-gapped or highly restricted environments, and maintain comprehensive logging, monitoring, and anomaly detection, according to Lian Jye Su, chief analyst at Omdia. Mahapatra said identity verification, monitoring, sandboxing, and restricted access are necessary but not sufficient. Enterprises should also require formal authorization for high-risk activities, retain human oversight, and review model outputs before they are acted on. “Governance should focus not only on controlling access to the model but also on managing how model-generated findings, exploit chains, and recommendations are validated, approved, and acted upon before they affect production environments,” Mahapatra said. Measuring effectiveness Anand Joshi, managing director of market research firm JP Data, argued that the acceleration could give enterprises an advantage if they adopt the technology quickly. He pointed to zero-day discovery as one of the most immediate enterprise uses for specialized cyber models. Prabhu identified vulnerability triage, secure code review, patch validation, incident investigation, and attack-surface analysis as other near-term applications. But greater detection capability could compound a familiar problem for security teams already struggling with more findings than they can remediate. “Most security teams already face more findings than they can address, so success should not be measured by the number of vulnerabilities identified,” Mahapatra said. Su similarly cautioned against treating vulnerability volume as a measure of success. “The focus should be on continuous posture improvement and limiting downstream impact,” Su said. CISOs should look for shorter exposure windows, Mahapatra said, along with faster remediation of critical flaws and fewer exploitable exposures. He added that vulnerability severity should be considered alongside exploit likelihood, the importance of the affected business system, and the context in which it is exposed.
Read full story at CSO Online →