OpenAI Launches GPT-5.6-Cyber for Advanced Defensive Security Testing

OpenAI launches GPT-5.6-Cyber through Daybreak Red for advanced vulnerability research and exploit testing under restricted access.

Written By
KJ
Kezia Jungco
Aug 12, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

OpenAI has released GPT-5.6-Cyber, a cybersecurity-specific model designed to handle advanced defensive work that general-purpose models often refuse, including exploit validation, vulnerability research, and exploit-chain development.

The model is available through Daybreak Red, a restricted access tier for vetted defenders conducting authorized security testing. In OpenAI’s internal testing, GPT-5.6-Cyber completed 95% of advanced cyber requests, far above standard GPT-5.6 Sol, while still rating High rather than Critical under the company’s Preparedness Framework. OpenAI is pairing the reduced refusal rate with identity checks, monitoring, and additional account controls.

GPT-5.6-Cyber is built to answer harder cyber requests

OpenAI said GPT-5.6-Cyber is built on GPT-5.6 Sol and trained for specialized tasks including finding zero-day vulnerabilities and developing exploit chains. Its Advanced Cybersecurity Completion Rate evaluation covered requests involving exploit-chain development, authentication bypass, privilege escalation, and similar scenarios.

GPT-5.6-Cyber completed 95% of those requests. GPT-5.6 Sol with Daybreak Blue access completed 2%, while the earlier GPT-5.5-Cyber completed 57.3%. OpenAI said the model was specifically trained to reduce refusals on higher-risk, dual-use cyber tasks that its general-purpose model may still block.

OpenAI still places GPT-5.6-Cyber below its highest cyber capability threshold.

Axios reported that the launch came days after OpenAI delayed its forthcoming Astra model after it reached Critical hacking capabilities during safety testing. GPT-5.6-Cyber, by comparison, reached the High threshold but not the Critical threshold.

How GPT-5.6-Cyber differs from Daybreak

GPT-5.6-Cyber is the model itself, while Daybreak is OpenAI’s controlled-access program for cybersecurity professionals.

Daybreak Blue grants approved defenders access to GPT-5.6 Sol, with system-level cyber guardrails removed, for authorized work such as vulnerability discovery, malware analysis, incident response, and patch validation. GPT-5.6 Sol can still refuse some highly dual-use requests even through Blue.

Daybreak Red is intended for more advanced research and gives vetted users access to purpose-trained cybersecurity models, including GPT-5.6-Cyber, for authorized vulnerability research, exploit validation, exploit development, and security testing.

Advertisement

Reduced safeguards bring added risk

OpenAI said GPT-5.6-Cyber helped uncover two previously unknown V8 vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox. Google fixed one as CVE-2026-15903. According to The Hacker News, the flaw carried a CVSS score of 8.8.

The model does not outperform GPT-5.6 Sol on every security task. OpenAI found that GPT-5.6-Cyber performed worse on an open-ended vulnerability discovery and report-writing evaluation, which it attributed to the model sometimes producing shorter, less detailed reports.

“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment,” OpenAI said.

Daybreak access is controlled through identity verification, account security, monitoring, approved-use restrictions, and legal attestations. OpenAI will also require individual Daybreak accounts to use hardware security keys beginning September 1, 2026.

What security teams should consider

For security teams approved to use the program, OpenAI recommends keeping cyber workflows sandboxed and isolated from sensitive production systems, monitoring agent actions, and defining which systems and actions are authorized.

GPT-5.6-Cyber is designed to complete requests that standard frontier models may refuse, including exploit development and other highly dual-use work. The more freedom teams give the model, the more carefully they need to control where it can operate, what it can access, and which actions require human approval.

Organizations considering Daybreak Red will need to decide where the model can operate, what systems it can access, and which actions still require human approval. OpenAI recommends additional monitoring and human oversight for higher-risk workflows.

GPT-5.6-Cyber may be most useful in environments where advanced testing is already tightly scoped and supervised. Its higher completion rate could reduce friction for legitimate research while requiring security teams to put stronger operational boundaries around how the model is used.

Advertisement

Also read: Black Hat 2026 researchers found critical flaws in tools from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks.

KJ

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.