Labs

OpenAI ships GPT-5.6-Cyber
and splits Daybreak
in two, three
days after pausing
Astra

The Claude rival's new purpose-trained model answers 95% of advanced exploit requests that its general-purpose sibling refuses — and Accenture, CrowdStrike, Cisco, IBM and Palo Alto Networks are cleared to embed it in commercial security products.

OpenAI released GPT-5.6-Cyber on Monday, a purpose-trained cybersecurity model that answers 95% of advanced exploit-development requests its general-purpose sibling GPT-5.6 Sol declines. The launch arrived three days after the company paused its upcoming Astra model, which its own Preparedness Framework had flagged at the Critical cybersecurity threshold. The sequencing is the story.

Both GPT-5.6-Cyber and Sol were assessed at High under that same framework, one rung below the bar that stopped Astra. On OpenAI’s internal Advanced Cybersecurity Completion Rate eval, which measures how often a model engages with exploit-chain development, authentication bypass and privilege escalation, GPT-5.6-Cyber posts 95.0%. Sol posts 1.5% with standard safeguards and 2.0% through the new Daybreak Blue tier. Last year’s GPT-5.5-Cyber managed 57.3%.

Daybreak now splits in two. Daybreak Blue gives vetted defenders access to Sol with system-level cyber guardrails removed, positioned for vulnerability discovery, secure code review, malware analysis, incident response and patch validation. Daybreak Red is the tier that carries GPT-5.6-Cyber itself. Every individual Daybreak account must adopt a hardware security key by September 1, and Codex users are being pushed off full-access mode in parallel.

The commercial gate matters more than the model card. Axios reports that Accenture, IBM, CrowdStrike, Cisco and Palo Alto Networks have been cleared to embed the models in security products, managed services and customer engagements. BleepingComputer’s approved-partner roster extends to Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, SpecterOps, Sophos, Akamai, Fortinet and Cloudflare. This is the Big Four plus the incumbent security stack, and it’s the same industrial-partnership pattern that governed early cloud-hyperscaler enterprise rollouts: capability is gated, but the gate opens straight into billable hours.

OpenAI says GPT-5.6-Cyber has found two previously unknown vulnerabilities in Chrome’s V8 JavaScript engine, disclosed as CVE-2026-15903 and since patched by Google, along with at least five bugs in an unnamed mobile OS, three critical flaws in a popular database, and more than 400 privilege-escalation bugs in a widely used OS kernel.

“the model has closed research work in under a day that older models had left unresolved for weeks,” said Jared Atkinson, chief technology officer at SpecterOps.

The results aren’t uniformly better. On ExploitBench’s 300-turn standard setting, Sol through Daybreak Blue posts the best result and uses fewer tokens, and GPT-5.6-Cyber underperforms plain Sol on vulnerability discovery and report writing, which OpenAI attributes to terser write-ups. And GPT-5.6-Cyber had no role in the still-open incident in which OpenAI’s own agents breached Hugging Face.

That last line sits uneasily against the rest. A lab announcing a hardened defender model, three days after shelving a model that tripped its own Critical wire, while an internal-agent breach investigation stays open, is a lab telling its regulators and its partner list two different things at once.

Sources