OpenAI's new cyber AI finds hundreds of bugs before launch
That’s one hell of a resume.

- OpenAI says GPT-5.6-Cyber found hundreds of serious software flaws before its general release.
- The model helped uncover zero-days in Chrome’s V8 engine, a mobile operating system, a database, and a kernel.
- OpenAI expanded Daybreak with Blue and Red tiers for approved defenders doing advanced cybersecurity work.
- The release highlights a growing challenge: AI may find vulnerabilities faster than organizations can fix them.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
OpenAI says its newest cyber-focused AI has already uncovered hundreds of serious software flaws, including zero-days, even before its general release.
OpenAI has expanded its Daybreak cybersecurity initiative with access to 2 new tiers and introduced GPT-5.6-Cyber, a model trained specifically for advanced security research. The company says the model can find zero-day vulnerabilities, develop exploit chains, validate fixes, and support other high-risk defensive work.
OpenAI said GPT-5.6-Cyber completed 95% of requests for advanced cybersecurity tasks in its internal Advanced Cybersecurity Completion Rate test. This is a sharp increase from the 1.5% response rate for GPT‑5.6 Sol with its normal safeguards enabled.
In addition to the high response rate, the model performed strongly on exploit-development and vulnerability-discovery tests. OpenAI quotes one partner as saying that the model completed work in less than a day that earlier models had failed to resolve after weeks of intermittent effort.
That speed is central to OpenAI's argument for expanding Daybreak.
The company says threat actors will increasingly use AI to launch attacks at unprecedented speed and scale, which leaves defenders with a fast-shrinking window to respond. It’s pushing these models as a way to put advanced AI capabilities into the hands of trusted defenders before the use of offensive AI overwhelms security teams.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Delivering on the promise
OpenAI first announced Daybreak in May as an initiative designed to help companies continuously test and secure their software.
Its initial partners included major technology and security companies, while the broader idea was to move security away from periodic testing toward continuous discovery.
The expansion now gives approved defenders access to Daybreak Blue and Daybreak Red.
Blue provides frontier general-purpose models for tasks such as vulnerability discovery, malware analysis, incident response, and secure code review. Red provides specialized purpose-trained cyber models for vulnerability research, exploit validation, and security testing.
That distinction matters because AI security tools can increasingly find vulnerabilities faster than organizations can fix them. Security experts have warned that discovery could become less of a bottleneck as models improve, with remediation becoming the bigger, harder problem.
There were clear signs of this imbalance in this latest release.
As part of the announcement, OpenAI said GPT-5.6-Cyber had already helped uncover 2 previously unknown vulnerabilities in Chrome's JavaScript V8 engine. Researchers validated the findings and reported them to Google, which fixed the issue as CVE-2026-15903.
It didn’t stop there. The model also identified at least 5 vulnerabilities in a popular mobile operating system. One of them is a chain of flaws that could let malicious apps take control of a device.
The model also found 3 critical flaws in a popular database, including one that could allow remote code execution. But the largest number came from a popular operating-system kernel, where OpenAI says the model found more than 400 vulnerabilities.
The company says it is working with Daybreak partners and open-source developers to disclose and fix those issues.