OpenAI Releases GPT-5.6-Cyber for Exploit Research
OpenAI has launched GPT-5.6-Cyber, a specialized model that completes 95% of exploit requests to help authorized security researchers stay ahead of rapidly evolving cyber threats.

OpenAI has expanded its Daybreak cybersecurity initiative with the launch of GPT-5.6-Cyber, a purpose-trained model designed to help defenders keep pace with AI-assisted attackers. To deploy this technology safely, OpenAI is restructuring the program into two distinct access tiers. The Daybreak Blue tier gives approved defenders access to the flagship GPT-5.6 Sol model with its standard cybersecurity guardrails removed, making it suitable for tasks like malware analysis and patch validation. Meanwhile, the Daybreak Red tier provides authorized red teamers and exploit researchers with access to the highly specialized GPT-5.6-Cyber model.
The new cyber-focused model represents a massive leap in cooperation for offensive security tasks, addressing long-standing complaints about high refusal rates from frontier AI models. On OpenAI's internal Advanced Cybersecurity Completion Rate benchmark, which tests responses to exploit-chain development and privilege escalation, GPT-5.6-Cyber successfully completed 95.0% of requests. In comparison, the standard GPT-5.6 Sol model completed just 1.5%, and the Daybreak Blue tier only reached 2.0%. The new model also significantly outperforms its predecessor, GPT-5.5-Cyber, which had a completion rate of 57.3%.
In real-world testing, the model has already demonstrated its capabilities by identifying two chained Chrome V8 vulnerabilities, tracked as CVE-2026-15903, alongside more than 400 kernel privilege escalation bugs, all of which were responsibly disclosed. To secure this powerful tool, OpenAI is mandating strict access controls. All individual Daybreak members must adopt a hardware-backed passkey by September 1, 2026, or risk losing their advanced access.
For security practitioners, this release offers a highly cooperative assistant capable of validating exploits and testing defenses without the friction of constant safety refusals. Commercial security vendors are also poised to integrate these capabilities directly into their workflows. Industry partners including Accenture, IBM, CrowdStrike, Cisco, and Palo Alto Networks have already been cleared to embed the Daybreak models into their own commercial security products.
This is our own summary of reporting by AlphaSignal



