OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, was unveiled on September 3, 2026, and aims to equip organizations protecting essential services in the United States and internationally with advanced cyber models, training, and technical support.
The $1 billion commitment is not a cash grant but rather product credits and subsidized access to Daybreak cyber models and products, intended for use over the next six months. Priority access will be given to water and wastewater utilities, electric grid operators, state and local governments, community and regional banks, nonprofits, and open-source maintainers. These entities often operate with limited staff and budgets while defending complex and aging systems against sophisticated threats.
Daybreak has been operational since June 2026, with an expansion in August following the release of GPT-5.6-Cyber. The program features two tiers: Daybreak Blue, which supports common defensive tasks with standard models, and Daybreak Red, offering approved organizations access to specialized cyber models for more sensitive and advanced work. Approximately 2,000 organizations, including cybersecurity firms, defense groups, and law enforcement agencies, are already utilizing Daybreak. The new commitment seeks to extend these capabilities to defenders who cannot afford commercial pricing.
OpenAI emphasized the urgency of this initiative, stating that AI-enabled cyberattacks are expected to become more widespread and sophisticated in the coming months. The company believes there is a "defender’s window"—a narrowing opportunity to leverage AI to close security gaps before attackers exploit them. This announcement coincided with OpenAI's internal classification of a new model as meeting the "Critical" threshold for cyber capability, meaning it could potentially aid in creating cyberweapons, highlighting the dual-use nature of AI tools.
A pilot program is underway with MS-ISAC, a federally supported organization that provides threat intelligence and incident response support to thousands of public-sector entities, including utilities, hospitals, schools, and law enforcement. This pilot will grant an initial group of public-sector and water-system defenders access to Daybreak, along with training and hands-on support. OpenAI previously tested this approach by offering up to $1 million in free API credits and Daybreak access to states and utilities affected by recent attacks on U.S. water infrastructure. During these incidents, teams used the tools for code and configuration review, security finding verification, patch development, and fix testing while maintaining system operations.
Also announced on September 3, the Daybreak Defense Network integrates over 35 enterprise products and partner-operated services into the Daybreak ecosystem, with HackerOne listed as an early partner. The goal is to make Daybreak capabilities accessible through existing defender tools, minimizing workflow disruption. OpenAI has also published its Defense Factory architecture, a continuous automated system designed to identify vulnerabilities, test them, and prepare fixes for human review, encouraging other defenders to adapt it.
The initiative has garnered support from more than 150 organizations across cybersecurity, technology, critical infrastructure, finance, and AI, presented by OpenAI as a collaborative effort. However, specific details regarding the costs and eligibility criteria for the broader program have not been extensively disclosed, which could be a significant factor for smaller, under-resourced entities like rural water utilities or county governments.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.