Search

Cookies

We use cookies to improve your experience. By continuing, you accept our use of cookies.

Technology

OpenAI Unveils Less Restricted GPT-5.6-Cyber for Security Researchers

· · 3 min read

OpenAI has introduced GPT-5.6-Cyber, a specialized AI model with fewer restrictions for trusted cybersecurity researchers. This advanced tool aims to help defenders identify zero-day vulnerabilities and develop exploit chains more effectively.

OpenAI has announced the release of GPT-5.6-Cyber, a purpose-built artificial intelligence model designed to empower trusted cybersecurity professionals with enhanced capabilities for vulnerability research and exploit development. This new model, part of OpenAI's expanded Daybreak Program, offers significantly fewer restrictions than its general-purpose counterparts, allowing researchers to tackle complex security challenges more directly.

Daybreak Program: Two Tiers for Cyber Defenders

The Daybreak Program now features two distinct access tiers: Daybreak Blue and Daybreak Red. The Blue tier provides security researchers with access to advanced general-purpose AI models, including GPT-5.6 Sol. These models are intended for tasks such as identifying software vulnerabilities, code review, malware analysis, and incident response.

The Daybreak Red tier, however, offers a more specialized approach, granting access to purpose-built cybersecurity models like the new GPT-5.6-Cyber. This tier is specifically tailored for in-depth vulnerability research, exploit testing, and comprehensive security assessments, giving cyber defenders a critical advantage against evolving threats.

GPT-5.6-Cyber: Enhanced Capabilities and Fewer Restrictions

Built upon the foundation of GPT-5.6 Sol, the GPT-5.6-Cyber model has undergone specific training for cybersecurity-related tasks, including the discovery of zero-day vulnerabilities and the creation of exploit chains. A key differentiator of this model is its reduced refusal rate for sensitive cybersecurity requests, which are often blocked by standard AI models due to potential misuse concerns.

During internal evaluations, GPT-5.6-Cyber successfully completed 95% of advanced cybersecurity requests, a stark contrast to the 1.5% completion rate of the safeguarded GPT-5.6 Sol, and a substantial improvement over its predecessor, GPT-5.5-Cyber, which managed around 57%.

Real-World Impact and Safeguards

The capabilities of GPT-5.6-Cyber have already demonstrated tangible results. Researchers utilizing the model successfully uncovered two previously unknown vulnerabilities within V8, the JavaScript engine powering Google Chrome. These vulnerabilities, when chained, could lead to memory corruption and allow attackers to escape Chrome's security sandbox. Both issues were reported to Google and subsequently patched.

Furthermore, GPT-5.6-Cyber has assisted in identifying vulnerabilities across major mobile operating systems, a popular database system, and an operating-system kernel, including hundreds of privilege-escalation flaws.

While OpenAI is easing some model restrictions to facilitate legitimate security research, it is simultaneously implementing stringent safeguards. These include the mandatory use of hardware security keys, automated review processes within Codex, and plans for expanded monitoring of the model's usage. Access to GPT-5.6-Cyber will remain highly restricted, limited to cybersecurity individuals and organizations who undergo identity verification and sign legal attestations confirming authorized and ethical use.

Related