AI leader OpenAI expands its Daybreak cybersecurity initiative with two new access tiers, Daybreak Blue and Daybreak Red. These tiers are specifically designed to give approved defenders the right capabilities for their work.
The update comes amid the growing threat of AI-powered cyberattacks. OpenAI says, “Threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways.” This creates a shrinking window for defenders to prepare.
Two New Access Tiers: Daybreak Blue and Daybreak Red
Daybreak Blue provides access to GPT-5.6 Sol, with safeguards tailored to legitimate cybersecurity work. It is the starting point for most defenders and is designed for activities such as vulnerability discovery, secure code review, malware analysis, incident response, patch validation, and security assessments.
Daybreak Red provides access to specialized cybersecurity models for authorized vulnerability research, exploit validation, and security testing.
GPT-5.6-Cyber: Built for Advanced Cybersecurity Tasks
A major development by OpenAI is GPT-5.6-Cyber, a specialized model built on GPT-5.6 Sol and trained for advanced cybersecurity tasks, including zero-day vulnerability discovery and the development of exploit chains. OpenAI says the model is designed to reduce refusals for certain higher-risk, dual-use cyber tasks.
In OpenAI’s internal evaluation, the Advanced Cybersecurity Completion Rate evaluation measured the reduced rate of refusals by GPT-5.6-Cyber through Daybreak Red access. In this evaluation, GPT-5.6-Cyber completed 95% of advanced cybersecurity requests compared with 1.5% for 5.6 Sol and 2% for GPT-5.6 Sol under Daybreak Blue. GPT-5.5-Cyber achieved a 57.3% completion rate.
From Benchmarks to Real-World Vulnerability Research
GPT-5.6-Cyber capabilities go beyond research benchmark performance to real-world vulnerability research. GPT-5.6-Cyber helped researchers identify two previously unknown vulnerabilities in V8, Chrome’s JavaScript engine. They could be chained together to corrupt memory, thereby escaping the V8 heap sandbox.
OpenAI’s researchers validated the findings and reported them to Google through a coordinated vulnerability disclosure. Google fixed the vulnerability and assigned it the CVE-2026-15903 identifier.
Alongside the V8 vulnerabilities, the company has used GPT-5.6-Cyber to identify high-severity issues in software ranging from databases and mobile phones to operating system kernels. Below are the mentioned ones:
- At least five vulnerabilities in a mobile operating system, including a chain from an untrusted app to local privilege escalation.
- Three severe vulnerabilities in a database, including a remote path to code execution.
- Over 400 vulnerabilities that lead to privilege escalation in a popular operating system kernel.
Access, Controls, and What’s Next for Defenders
Despite these capabilities, under the Preparedness Framework, the GPT-5.6 Sol model was assessed as having high cybersecurity capabilities but did not reach the Critical threshold. Access to Daybreak Blue and Daybreak Red is available for approved individuals and organizations with authorized work. OpenAI claims to control access through identity verification, account security monitoring, approved-use restrictions, and legal attestations.
Overall, Daybreak indicates OpenAI’s strategy of giving trusted defenders more powerful AI tools while adding controls around their use. Teams whose work includes advanced vulnerability research, red teaming, and exploit development can request access to Daybreak Red for OpenAI’s most advanced cyber models.
Read all the latest news around the tech landscape on our website.
Also Read:
Meet OpenAI’s GPT-5.5: Features, Pricing, Benchmarks & Real-World Use Cases Explained
Agentic AI Security Risks: What Enterprises Must Prepare For


