LIVE · cybersecurity feed
Live wire
ai

OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber

Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models

zeroday.news ·

OpenAI has introduced a new large language model (LLM) specifically trained for cybersecurity tasks, GPT-5.6-Cyber, alongside a revised two-tier access program called Daybreak. The announcement, made in a company blog post on August 10, details how the new model and access tiers aim to balance advanced cybersecurity capabilities with safety measures.

The Daybreak program now consists of two tiers: Daybreak Blue and Daybreak Red. Daybreak Blue provides access to frontier general-purpose models, including the latest GPT-5.6 Sol, for authorized defensive security work. This tier removes some "system-level safeguards" that are present for general users of GPT-5.6 Sol, which OpenAI noted could otherwise impede legitimate defensive tasks. Permitted activities for Daybreak Blue members include vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.

For more advanced cybersecurity operations, Daybreak Red members gain access to purpose-trained cybersecurity models like GPT-5.5-Cyber and the newly launched GPT-5.6-Cyber. This tier is intended for tasks such as vulnerability research, exploit validation, and security testing. OpenAI stated that even without the general guardrails, GPT-5.6 Sol with Daybreak Blue access would still refuse highly dual-use prompts, such as those related to pentesting production systems. GPT-5.6-Cyber, exclusively available through Daybreak Red, is designed to further reduce these refusals and enhance performance on sensitive security tasks.

OpenAI claims that GPT-5.6-Cyber significantly outperforms its other models in cybersecurity scenarios. In a set of sensitive requests involving exploit-chain development, authentication bypass, and privilege escalation, GPT-5.6-Cyber completed 95% of the tasks. In contrast, general-access GPT-5.6 Sol completed only 1.5% of these tasks, and with Daybreak Blue access, it completed 2.0%. The previous cyber-focused model, GPT-5.5-Cyber, completed 57.3% of the same requests.

The company also reported that GPT-5.6-Cyber demonstrated superior performance across various cybersecurity-specific AI benchmarks, including ExploitGym and ExploitBench, and in tasks like zero-day vulnerability discovery evaluation and vulnerability reporting. As an example of its capabilities, OpenAI stated that its researchers used GPT-5.6-Cyber to identify CVE-2026-15903, a high-severity vulnerability in V8, Chrome’s JavaScript engine. This finding was validated and reported to Google through coordinated vulnerability disclosure, and Google subsequently fixed the issue.

The introduction of the two-tier system is seen as an initial step by OpenAI to address concerns regarding the potential misuse of powerful AI models while enabling their application in cybersecurity defense. The Daybreak Red tier specifically restricts access to models capable of more advanced and potentially harmful actions, while Daybreak Blue aims to bridge gaps where previous models with stringent guardrails proved insufficient for defensive operations. However, it is noted that AI model guardrails alone are not a complete control plane for defense, emphasizing the need for visibility, segmentation, and adherence to zero-trust principles within an organization's own infrastructure to manage AI agent actions and contain potential risks.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.