OpenAI published an official post on Aug. 10 titled “Expanding Daybreak as the Cyber Defense Window Narrows,” introducing GPT-5.6-Cyber, a model built for cybersecurity work, and splitting its Daybreak cyber defense program into two access levels. Citing OpenAI’s announcement and Axios reporting, ABMedia said this is the first OpenAI model described as “offensive-grade.”
OpenAI puts completion at roughly 95% on high-risk dual-use tasks
According to OpenAI, GPT-5.6-Cyber was trained for advanced cybersecurity work and can complete about 95% of assigned high-risk dual-use exploitation tasks. The company said those tasks include assembling attack chains, bypassing authentication, and escalating privileges.
OpenAI compared that result with GPT-5.5-Cyber, which it said reached 57.3%.
Real-world testing cited Chrome V8 findings
OpenAI also said the model had found previously unknown vulnerabilities in real software. One example involved Chrome’s V8 engine. The company said GPT-5.6-Cyber identified two chainable V8 flaws that could corrupt memory and escape the Chrome V8 sandbox.
The 95% figure comes with an important qualifier. As stated in the report, the metric measures whether the model is willing to provide an answer, not whether every answer is correct. That distinction has become a subject of outside discussion.
Daybreak now has Blue and Red tiers
Because of the model’s capabilities, OpenAI is placing tight controls on access. Daybreak has been divided into two layers.
- Daybreak Blue is aimed at broader defensive work and gives approved defenders access to frontier models including GPT-5.6 Sol.
- Daybreak Red is the tier that includes GPT-5.6-Cyber and supports advanced vulnerability research, vulnerability validation, and security testing.
To gain access to Red, users must pass identity verification, meet account security requirements, accept behavior monitoring, comply with approved-use restrictions, and sign legal commitments.
ABMedia links the release to wider warnings on AI security capability
ABMedia said the model’s dual defensive and offensive utility lines up with a string of recent warnings around AI and cybersecurity. The report pointed to earlier coverage that OpenAI’s Astra had temporarily paused some internal work because its security capabilities were considered too strong. It also referred to cases in which white-hat researchers used AI to scan for large numbers of vulnerabilities. In the report’s framing, the ability to help AI find vulnerabilities and the ability to help it exploit them rest on the same underlying skill set.

