OpenAI on Monday unveiled a brand new cybersecurity-focused mannequin referred to as GPT‑5.6‑Cyber that it stated is targeted on vulnerability analysis, penetration testing, and incident response.
“Constructed on GPT‑5.6 Sol, it’s educated to enhance capabilities on a number of specialised cybersecurity duties (e.g., discovering zero-day vulnerabilities and growing exploit chains) and to cut back refusals for sure higher-risk, dual-use cyber duties,” OpenAI stated.
The factitious intelligence (AI) firm stated it is making GPT 5.6 Cyber out there by way of Dawn Pink, a brand new tier that gives entry to its purpose-trained cybersecurity fashions to different corporations for licensed vulnerability analysis, exploit validation, and safety testing.
GPT-5.6-Cyber, a extra cyber-permissive model of GPT-5.6 Sol, builds upon GPT‑5.5‑Cyber, which OpenAI launched in June 2026.
To measure the decreased charge of refusals offered by GPT‑5.6‑Cyber by way of Dawn Pink entry, OpenAI stated it created an inside analysis referred to as Superior Cybersecurity Completion Charge that measures how typically fashions reply to prompts associated to exploit-chain growth, authentication bypass, privilege escalation, and different superior cybersecurity situations.
The assessments present that GPT‑5.6‑Cyber completes 95.0% of those requests, in contrast with simply 1.5% for GPT‑5.6 Sol and a pair of.0% when used with Dawn Blue entry. It has additionally been discovered to efficiently full extra requests than GPT‑5.5‑Cyber, which completed solely 57.3% of requests.
GPT‑5.6‑Cyber is educated to enhance efficiency on sure cybersecurity workflows involving exploit growth and superior safety analysis. An ExploitGym benchmark analysis has revealed the mannequin to outperform each GPT‑5.6 Sol and GPT‑5.5 Cyber.
OpenAI stated the mannequin additionally demonstrates enhancements in relation to discovering and precisely calibrating the severity of novel zero-day vulnerabilities resulting from specialised coaching, though it performs worse than GPT‑5.6 Sol in relation to open-ended quests related to uncovering vulnerabilities in a repository, growing a working proof-of-concept, and submitting a high-quality vulnerability report.
This, the corporate famous, is because of “the mannequin generally producing shorter, much less detailed vulnerability reviews.”
One of many high-severity vulnerabilities found by the mannequin is CVE-2026-15903 (CVSS rating: 8.8), an out-of-bounds learn and write vulnerability within the V8 JavaScript engine that might permit a distant attacker to doubtlessly execute arbitrary code inside a sandbox through a crafted HTML web page.
It could possibly be chained with one other beforehand unknown vulnerability, additionally discovered by the mannequin, to flee the V8 heap sandbox. CVE-2026-15903 was patched by Google in mid-July 2026. OpenAI stated the mannequin has additionally been used to flag a number of different flaws –
- At the least 5 vulnerabilities in a well-liked cell working system, together with a series from an untrusted app to native privilege escalation
- Three crucial vulnerabilities in a well-liked database, together with a distant path to code execution
- Over 400 vulnerabilities that may result in privilege escalation in a well-liked working system kernel
Dawn Pink is certainly one of two entry tiers arrange by OpenAI as a part of the Dawn initiative it launched again in Might 2026, the opposite being Dawn Blue, which gives entry to frontier general-purpose fashions, together with GPT‑5.6 Sol, with built-in guardrails tailor-made to licensed defensive safety work.
“Dawn Blue entry removes these guardrails, serving to defenders get extra out of the mannequin in real-world safety duties, together with incident detection and response, investigations, vulnerability administration, and safety assessments,” the corporate stated.
GPT‑5.6‑Cyber has been made out there to a bunch of trusted buyer companions like Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC, and Sophos to assist establish and patch vulnerabilities earlier than attackers can exploit them and shut the “protection hole.”
These fashions are being pitched to firms as a method to flag safety vulnerabilities in software program, as dangerous actors have considerably ramped up their use of the know-how to boost campaigns and perform cyber assaults at pace and scale by no means seen earlier than, even when it hasn’t led to the invention of novel or subtle assault strategies.
What’s evident is that AI brokers are enabling cybercriminals and nation-state hackers to outsource the grunt work wanted to plan and perform cyber assaults, providing them a means to enhance the effectivity and productiveness of their operations, leading to assaults which might be higher, larger, and quicker.
To make issues worse, AI has additionally shortened the trail from vulnerability disclosure to exploitation, with attackers leaning on such instruments to jot down vibe exploits for newly disclosed flaws. With AI already reducing the barrier to use growth and accelerating vulnerability analysis, attackers are more likely to forged a wider internet throughout disclosed vulnerabilities going ahead to discover a means into enterprise networks.
Whereas AI techniques have vastly improved at discovering and exploiting vulnerabilities in software program, they nonetheless require substantial human experience, whilst analysis has discovered that cyber-capable reasoning fashions like ChatGPT 5.5 and Anthropic Claude Opus 4.8 can battle to totally patch a found vulnerability or keep away from introducing new points with their fixes.
“The typical success charge for producing a patch that absolutely resolved the vulnerability (with out materially altering software conduct) was simply 26.0%,” 1Password stated. “Patches that efficiently resolved the vulnerability, however altered the applying’s conduct within the course of, occurred 20.1% of the time. Conversely, LLM-generated patches didn’t resolve the vulnerability, added a brand new vulnerability, or each, a median of 53.9% of the time.”
The findings underscore that fashions presently excelling at discovering a variety of vulnerabilities are solely good at successfully patching a “slim subset” of them and assist steer builders away from situations the place the fashions both introduce new bugs no matter whether or not an present challenge was patched or not, successfully increasing an assault floor for malicious actors to use.
“Fashions operating with decreased safeguards carry dangers past customary mannequin utilization, whether or not from misuse or misalignment,” OpenAI stated. “Regardless of these dangers, we imagine that democratizing entry to frontier intelligence for defenders is essential to accelerating and automating cyber protection.”






