Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models

OpenAI has introduced a new large language model (LLM) specifically trained for cybersecurity tasks, GPT-5.6-Cyber, alongside a revised two-tier access program called Daybreak. The announcement, made in a company blog post on August 10, details how the new model and access tiers aim to balance advanced cybersecurity capabilities with safety measures.
The Daybreak program now consists of two tiers: Daybreak Blue and Daybreak Red. Daybreak Blue provides access to frontier general-purpose models, including the latest GPT-5.6 Sol, for authorized defensive security work. This tier removes some "system-level safeguards" that are present for general users of GPT-5.6 Sol, which OpenAI noted could otherwise impede legitimate defensive tasks. Permitted activities for Daybreak Blue members include vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
For more advanced cybersecurity operations, Daybreak Red members gain access to purpose-trained cybersecurity models like GPT-5.5-Cyber and the newly launched GPT-5.6-Cyber. This tier is intended for tasks such as vulnerability research, exploit validation, and security testing. OpenAI stated that even without the general guardrails, GPT-5.6 Sol with Daybreak Blue access would still refuse highly dual-use prompts, such as those related to pentesting production systems. GPT-5.6-Cyber, exclusively available through Daybreak Red, is designed to further reduce these refusals and enhance performance on sensitive security tasks.
OpenAI claims that GPT-5.6-Cyber significantly outperforms its other models in cybersecurity scenarios. In a set of sensitive requests involving exploit-chain development, authentication bypass, and privilege escalation, GPT-5.6-Cyber completed 95% of the tasks. In contrast, general-access GPT-5.6 Sol completed only 1.5% of these tasks, and with Daybreak Blue access, it completed 2.0%. The previous cyber-focused model, GPT-5.5-Cyber, completed 57.3% of the same requests.
The company also reported that GPT-5.6-Cyber demonstrated superior performance across various cybersecurity-specific AI benchmarks, including ExploitGym and ExploitBench, and in tasks like zero-day vulnerability discovery evaluation and vulnerability reporting. As an example of its capabilities, OpenAI stated that its researchers used GPT-5.6-Cyber to identify CVE-2026-15903, a high-severity vulnerability in V8, Chrome’s JavaScript engine. This finding was validated and reported to Google through coordinated vulnerability disclosure, and Google subsequently fixed the issue.
The introduction of the two-tier system is seen as an initial step by OpenAI to address concerns regarding the potential misuse of powerful AI models while enabling their application in cybersecurity defense. The Daybreak Red tier specifically restricts access to models capable of more advanced and potentially harmful actions, while Daybreak Blue aims to bridge gaps where previous models with stringent guardrails proved insufficient for defensive operations. However, it is noted that AI model guardrails alone are not a complete control plane for defense, emphasizing the need for visibility, segmentation, and adherence to zero-trust principles within an organization's own infrastructure to manage AI agent actions and contain potential risks.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets