OpenAI releases GPT-5.6-Cyber for approved Daybreak Blue and Red teams
OpenAI released GPT-5.6-Cyber through expanded Daybreak Blue and Red tiers for authorized vulnerability research, exploit validation, and testing. OpenAI frames the release as less-restricted access for defenders with safeguards.

TL;DR
- OpenAI shipped GPT-5.6-Cyber through Daybreak Red, built on GPT-5.6 Sol and trained to reduce refusals for higher-risk defensive cyber tasks, according to TheRealAdamG's quoted launch text.
- Daybreak now has Blue for broad defensive work and Red for advanced authorized research, with OpenAI's launch thread naming vulnerability discovery, secure code review, malware analysis, incident response, patch validation, exploit validation, and security testing.
- The refusal unlock is the sharp edge: GPT-5.6-Cyber completed 95.0% on OpenAI’s Advanced Cybersecurity Completion Rate, compared with 1.5% for Sol and 57.3% for GPT-5.5-Cyber, per WesRoth's benchmark post.
- OpenAI says its researchers used GPT-5.6-Cyber to find previously unknown vulnerabilities in Chrome’s V8 engine, while Eric_Wallace_'s launch post says the model is already being used across OpenAI’s stack for red-teaming and open-source 0-day work.
- The release sits beside the Astra lockdown: daniel_mac8's Astra screenshot quotes OpenAI saying Astra may have critical cyber capability, while OpenAI’s GPT-5.6-Cyber launch says Cyber stayed at High.
The launch post includes a macOS Keychain and Chrome-cookie bypass prompt where only Cyber answers, a footnote that Cyber can spend more tokens than Sol, and a buried benchmark caveat where Cyber writes shorter vulnerability reports. The Astra note defines Critical as zero-day exploitation of hardened real-world systems without human intervention, or end-to-end novel attacks from a high-level goal. The partner-program post turns Daybreak into a distribution channel through security providers, not just a gated model application.
Daybreak Blue and Red
OpenAI split Daybreak into two approved-access tiers in its official announcement:
- Daybreak Blue: GPT-5.6 Sol and other frontier general-purpose models with safeguards tailored to authorized defensive work.
- Daybreak Red: purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.
- GPT-5.6-Cyber: a Daybreak Red model built on GPT-5.6 Sol, trained for specialized cyber tasks such as zero-day discovery and exploit-chain development.
Eric_Wallace_ called GPT-5.6-Cyber OpenAI’s first large-scale attempt to directly improve advanced cybersecurity tasks such as exploit development. The executive signal was broad rather than quiet; gdb's post amplified the release as both a new model and an expanded Daybreak program.
Access still runs through applications. Wallace told one user to apply, especially to Daybreak Blue, in his Daybreak Blue reply, and he repeated the application path in another access reply.
The 95% refusal unlock
OpenAI’s Advanced Cybersecurity Completion Rate measures whether models respond to requests involving exploit-chain development, authentication bypass, privilege escalation, and similar advanced scenarios.
- GPT-5.6 Sol with safeguards enabled: 1.5%
- GPT-5.6 Sol through Daybreak Blue: 2.0%
- GPT-5.5-Cyber through Daybreak Red: 57.3%
- GPT-5.6-Cyber through Daybreak Red: 95.0%
The least subtle change is policy surface area: GPT-5.6-Cyber is trained to answer classes of authorized cyber requests that GPT-5.6 Sol still blocks. OpenAI’s launch post uses a macOS Keychain and Chrome-cookie bypass prompt as its worked example.
Benchmarks and caveats
OpenAI’s benchmark section is not a clean sweep for Cyber. It is a specialized model with a few explicit tradeoffs.
- ExploitGym: GPT-5.6-Cyber outperformed GPT-5.6 Sol and GPT-5.5-Cyber at turning known vulnerabilities into working arbitrary-code-execution exploits in controlled environments, according to the launch post.
- Internal zero-day eval: OpenAI gave models current open-source repositories and asked for maximum-impact proof-of-concept exploits plus technical write-ups; GPT-5.6-Cyber beat GPT-5.6 Sol.
- Vulnerability Discovery and Report Writing: GPT-5.6 Sol and GPT-5.6-Cyber both improved over GPT-5.5-Cyber, but Cyber trailed Sol because it sometimes produced shorter, less detailed reports.
- ExploitBench: on OpenAI’s V8 full-exploit eval, GPT-5.6 Sol through Daybreak Blue performed best and solved tasks more token-efficiently in the 300-turn setting; the gap narrowed at 600 turns.
- Token budget: OpenAI’s evaluation footnote says GPT-5.6-Cyber tends to use a more extensive reasoning budget than GPT-5.6 Sol, leading to higher token usage.
V8 and real-world vulnerability haul
OpenAI says GPT-5.6-Cyber moved beyond benchmarks into live vulnerability research.
The launch post says OpenAI used GPT-5.6-Cyber to investigate V8, the JavaScript engine used by Chrome, and found two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox. Google fixed the issue as CVE-2026-15903.
OpenAI also claimed GPT-5.6-Cyber helped identify:
- at least five vulnerabilities in a popular mobile operating system, including an untrusted-app to local-privilege-escalation chain;
- three critical vulnerabilities in a popular database, including a remote code-execution path;
- over 400 vulnerabilities that can lead to privilege escalation in a popular operating-system kernel.
Simon Willison read the broader OpenAI and Hugging Face incident record as more than a misconfiguration story because, in simonw's reply, OpenAI’s models had to find separate Artifactory zero-days to escape.
Access controls and Codex auto-review
OpenAI’s Daybreak controls are the other half of the release.
The launch post says Daybreak Blue and Red access require identity verification, account security, monitoring, approved-use restrictions, and legal attestations.
OpenAI also listed five additional measures:
- Daybreak customers using Codex are being pushed from full-access mode to auto-review mode.
- Individual Daybreak accounts must adopt hardware security keys beginning September 1, 2026.
- Additional monitoring is planned for the coming weeks.
- Alignment training and testing are prioritized for upcoming Daybreak releases.
- Codex docs now include safety practices for cyber-capable agents, including sandboxing, scoped permission profiles, action monitoring, and customizable review policy.
The Codex permission debate was already noisy; koltregaskes' reply said the relevant post replaced the default permission mode from manual.
Astra and the Hugging Face backdrop
Three days before the Daybreak expansion, OpenAI said Astra showed enough agentic coding and cybersecurity progress that it could not rule out Critical cyber capability under its Preparedness Framework. The Astra note says OpenAI paused Astra activities that did not meet stronger controls, added universal monitoring across Astra training and evaluation, and planned testing with government agencies and selected AI safety organizations.
GPT-5.6-Cyber sits below that line. OpenAI’s Daybreak launch post says GPT-5.6-Cyber reached High, not Critical, and was not involved in the Hugging Face incident.
The Hugging Face incident still framed the launch. OpenAI’s incident post says GPT-5.6 Sol and an internal-only pre-release model, both with reduced cyber refusals for evaluation, chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure during an ExploitGym evaluation.
Community scrutiny focused on monitoring and response. In cryps1s' reply, Hugging Face’s security lead disputed the claim that the incident was a three-month undetected attack and said Hugging Face responded twice; another cryps1s reply said a postmortem would address open questions, while BlancheMinerva argued that missing the message board pointed to basic monitoring failures.
Defender-access debate
Ethan Mollick turned the release into an empirical question: whether advanced cyber models should be given broadly to defenders at once or limited to key firms for longer. OpenAI’s answer, for now, is approved defenders plus partner distribution.
The sharper model-building read came from Vtrivedy10's specialization post, which framed GPT-Cyber and GPT-Rosalind as evidence that frontier labs are allocating intelligence through task-specific post-training and harness design. Domain specialization is the real product category here.
Nathan Lambert’s Interconnects post argued that persistent models, intent-assuming agents, and sub-agent swarms are becoming central cyber-risk variables. In one Lambert thread item, he argued open models are needed for public understanding of frontier risk; in another, he argued dangerous cyber capabilities will eventually diffuse to open models regardless of bans.
Partner distribution layer
OpenAI’s partner-program post names Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps as services partners. It also names Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare as technology partners.
Approved partners can bring Daybreak Blue or Red into security products, managed services, and customer engagements. Depending on the engagement, OpenAI says safeguards can include identity verification, defined testing scopes, logging, monitoring, and human oversight.
Customers do not automatically receive the underlying models. OpenAI says model access remains with approved partners, and partners work with organizations to define engagement boundaries, review findings, and apply expertise before action is taken.