GPT‑5.6‑Cyber completes 95.0% of advanced exploit-chain and privilege‑escalation requests in OpenAI’s internal tests, far outpacing the 1.5% completion rate for GPT‑5.6 Sol under the company’s guarded access, the firm reported.
What GPT‑5.6‑Cyber is and how it is positioned
OpenAI unveiled GPT‑5.6‑Cyber as a purpose‑trained model "focused on vulnerability research, penetration testing, and incident response." Built on GPT‑5.6 Sol and described as a more permissive successor to GPT‑5.5‑Cyber (released in June 2026), the model is intended to improve capabilities on specialized cybersecurity tasks such as finding zero‑day vulnerabilities and developing exploit chains. OpenAI said it is making GPT‑5.6‑Cyber available through Daybreak Red, a new access tier for authorized vulnerability research, exploit validation, and security testing.
How OpenAI measures reduced safeguards and the results
To quantify the degree to which GPT‑5.6‑Cyber responds to high‑risk, dual‑use cyber prompts, OpenAI built an internal evaluation called Advanced Cybersecurity Completion Rate. Under that metric the company reported the model completed 95.0% of requests related to exploit‑chain development, authentication bypass, privilege escalation and similar advanced scenarios. By contrast, GPT‑5.6 Sol finished 1.5% of those requests and GPT‑5.6 Sol with Daybreak Blue access finished 2.0%. GPT‑5.5‑Cyber, the prior cyber‑permissive model, completed 57.3% of such requests.
OpenAI also cited performance on an ExploitGym benchmark where GPT‑5.6‑Cyber outperformed both GPT‑5.6 Sol and GPT‑5.5‑Cyber, reflecting the company’s claims that the model has been trained to improve exploit development and advanced security research workflows.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildVulnerabilities the model helped find — and where it falls short
OpenAI reported concrete results from the model’s use. One flagged high‑severity finding was CVE‑2026‑15903 (CVSS 8.8), an out‑of‑bounds read/write bug in the V8 JavaScript engine that could allow remote code execution in a sandbox via a crafted HTML page. OpenAI said that CVE‑2026‑15903 could be chained with another previously unknown vulnerability the model found to escape the V8 heap sandbox; Google patched CVE‑2026‑15903 in mid‑July 2026.
The company added that the model has been used to flag at least five vulnerabilities in a popular mobile operating system — including a chain from an untrusted app to local privilege escalation — three critical vulnerabilities in a popular database that include a remote path to code execution, and more than 400 vulnerabilities capable of leading to privilege escalation in a popular operating system kernel.
OpenAI also warned that GPT‑5.6‑Cyber performs worse than GPT‑5.6 Sol on open‑ended tasks such as uncovering vulnerabilities in a repository, producing a working proof‑of‑concept exploit, and submitting a high‑quality vulnerability report. The company attributed this gap to "the model sometimes producing shorter, less detailed vulnerability reports."
Daybreak Red and Daybreak Blue: access tiers and trusted partners
Daybreak Red is one of two access tiers in the Daybreak initiative OpenAI introduced in May 2026. The other tier, Daybreak Blue, provides access to frontier general‑purpose models, including GPT‑5.6 Sol, "with built‑in guardrails tailored to authorized defensive security work," the company said. In the same briefing OpenAI also stated, apparently describing a different configuration, that "Daybreak Blue access removes those guardrails, helping defenders get more out of the model in real‑world security tasks, including incident detection and response, investigations, vulnerability management, and security assessments."
OpenAI said GPT‑5.6‑Cyber has been made available to a group of trusted customer partners to help identify and patch vulnerabilities before attackers can exploit them. Named partners include Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC, and Sophos.
What this means for technologists, enterprises, and adversaries
- Technologists and security teams: OpenAI is pitching these models as a way to flag vulnerabilities and validate exploits so defenders can close the "defense gap." The company argued the models help with incident detection, response, and vulnerability management, but also acknowledged shorter, less detailed reports in some workflows.
- Affected enterprises and procurement leaders: Vendors are being invited to use Daybreak Red access to identify and patch flaws; organizations will need to weigh faster discovery against the model’s uneven performance producing complete proofs‑of‑concept and high‑quality vulnerability writeups.
- Adversaries and threat actors: OpenAI itself noted that attackers have "significantly ramped up their use of the technology" and that AI has shortened the path from disclosure to exploitation. Independent findings cited by OpenAI underline that AI can lower the barrier to exploit development and accelerate vulnerability research — even while substantial human expertise remains necessary.
OpenAI acknowledged the tradeoffs openly, writing that "models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment." The company added that despite those risks, "we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense." The record left on the table by OpenAI’s published metrics and the concrete vulnerabilities the model surfaced frames a central tension: the same capability that helps defenders find and patch critical flaws can also shorten attackers’ path to weaponizing newly disclosed bugs.




