TLDRocket
Sign in

OpenAI expands Daybreak cybersecurity research program

SiliconANGLE Maria Deutscher Covered by 7 sources

OpenAI just opened more of its cybersecurity research program to defenders. The twist: it now has a stronger model for attack-style testing, plus tighter access controls.

Based on reporting by SiliconANGLE, Maria Deutscher — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

OpenAI is widening Daybreak, its cybersecurity research program that lets vetted professionals use its models for vulnerability work. The program started in May. Today, OpenAI added two new access tiers, Daybreak Blue and Daybreak Red, and said it will tighten the guardrails that keep unauthorized users out.

The basic idea is simple. OpenAI’s public models are filtered to block most cybersecurity prompts. Daybreak lifts many of those limits, which lets participants use the company’s models to automate the slow, repetitive parts of vulnerability research. The available models include OpenAI’s flagship GPT-5.6 Sol algorithm.

Daybreak Blue is the entry point. OpenAI says it’s meant for most defenders, and it can scan code for vulnerabilities, check whether patches behave the way they should, and analyze outside files such as malware. It does not go as far as deciding whether a newly found flaw can actually be exploited.

That more aggressive work sits with Daybreak Red, which runs on a custom model called GPT-5.6-Cyber. OpenAI built it to handle advanced cybersecurity tasks such as finding zero-day vulnerabilities, but it also trained the model to refuse especially risky requests. Customers can’t use it to look for weak points in production systems.

OpenAI says the custom model is not just broader, but stronger. On a benchmark that measures how often a model refuses advanced cybersecurity prompts, the public GPT-5.6 Sol completed 1.5% of requests, Daybreak Blue completed 2%, and GPT-5.6-Cyber completed 95%. On another benchmark, ExploitGym2, GPT-5.6-Cyber scored slightly higher than GPT-5.6 Sol. OpenAI says its engineers have already used it to uncover two high-severity Chrome vulnerabilities and three critical flaws in an unnamed popular database.

The new access tiers come with more control at the gate. Starting next month, participants will have to sign in with hardware security keys, and OpenAI is adding monitoring designed to catch unauthorized activity.

My take — AI-written commentary, not fact-checked reporting

This is the part of AI that actually matters: models being pushed into boring, dangerous, useful work instead of demo theater. OpenAI is doing the right thing by splitting defender tools from exploit-heavy access and by making the login wall uglier, not prettier. That’s not anti-hacker; that’s basic adulthood.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.