OpenAI Unveils GPT-5.6-Cyber to Revolutionize Cybersecurity

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
OpenAI Unveils GPT-5.6-Cyber to Revolutionize Cybersecurity
OpenAI is expanding its Daybreak cybersecurity program with two new access levels and a dedicated AI model called GPT-5.6-Cyber, designed to assist security professionals in identifying vulnerabilities and developing exploits at an early stage.
The program is divided into two branches: Daybreak Blue focuses on defensive tasks such as malware analysis, while Daybreak Red is geared towards offensive security research.
Through the Red level, users gain access to GPT-5.6-Cyber, a model specifically trained for offensive security purposes, capable of responding to nearly all sensitive security queries that are typically blocked by other AI models.
OpenAI asserts that threat actors will increasingly use AI for cyberattacks, including fully autonomous attacks. The preparation window for defenders is narrowing. Ironically, the best example of this comes from OpenAI itself, when its own models accidentally hacked Hugging Face and other services after weeks of maneuvering on internal forums.
Daybreak is designed to give defenders a head start. The program now includes two access levels. Daybreak Blue allows users to access GPT-5.6 Sol with tailored protections for authorized defense work such as vulnerability detection, malware analysis, and incident response. Daybreak Red targets security researchers conducting research on vulnerabilities, exploit validation, and penetration testing.
To access either level, identity verification, account security measures, monitoring, and legal statements are required. Hardware security keys will become mandatory for all Daybreak accounts starting September 1, 2026. OpenAI also recommends running security workflows in isolated sandbox environments and using the Auto-Review mode in Codex, which checks actions requiring elevated privileges before execution.
GPT-5.6-Cyber Responds to 95% of Sensitive Security Queries
The new model GPT-5.6-Cyber is available through the Daybreak Red level. It is based on GPT-5.6 Sol and has been specifically trained to perform better on tasks such as discovering zero-day vulnerabilities and building exploit chains. According to OpenAI, the model rarely refuses security-related queries that other models block by default.
GPT-5.6-Cyber responds to 95% of sensitive cybersecurity queries in an internal benchmark. The standard model GPT-5.6 Sol blocks nearly all of these queries due to its protections.
In an internal benchmark called "Advanced Completion Rate in Cybersecurity," GPT-5.6-Cyber responds to 95% of queries covering scenarios such as exploit chain development, authentication bypass, and privilege escalation. GPT-5.6 Sol with security measures enabled achieves only 1.5%. With Daybreak Blue, it reaches 2%. The previous model, GPT-5.5-Cyber, manages 57.3%.
In a specific test, the models were tasked with developing a WebSocket authentication bypass for an internal admin panel. Only GPT-5.6-Cyber on Daybreak Red produced functional exploit code. All other variants refused to respond. On ExploitGym, a benchmark that measures models' ability to turn known vulnerabilities into functional exploits, GPT-5.6-Cyber outperforms both GPT-5.6 Sol and GPT-5.5-Cyber.
The Model Has Already Found Two Unknown Vulnerabilities in Chrome
OpenAI has also utilized GPT-5.6-Cyber for real-world vulnerability research. The company claims that the model analyzed V8, Chrome's JavaScript engine, and discovered two previously unknown vulnerabilities that can be chained to corrupt memory and bypass the V8 memory sandbox. Google has patched these flaws following coordinated disclosure and assigned them the designation CVE-2026-15903.
GPT-5.6-Cyber is also reported to have found at least five vulnerabilities in a "popular mobile operating system." One of these is a chain of flaws that would allow an application to escalate its normally restricted access rights to full administrator privileges, thereby taking control of the device. OpenAI is collaborating with Daybreak partners and the open-source community to disclose and fix these issues.
As part of OpenAI's Preparedness Framework, GPT-5.6-Cyber has been rated "High" for its cybersecurity capabilities but does not reach the "Critical" threshold. The recently announced model Astra is "potentially" expected to achieve this critical level. Given that GPT-5.6-Cyber is already a specialized and optimized model and does not yet reach the critical level, the trajectory is clear: AI's cybersecurity capabilities are rapidly increasing with each new generation.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.