OpenAI on Monday unveiled a brand new cybersecurity-focused mannequin referred to as GPT‑5.6‑Cyber that it mentioned is concentrated on vulnerability analysis, penetration testing, and incident response.
“Constructed on GPT‑5.6 Sol, it’s educated to enhance capabilities on a number of specialised cybersecurity duties (e.g., discovering zero-day vulnerabilities and creating exploit chains) and to scale back refusals for sure higher-risk, dual-use cyber duties,” OpenAI said.
The unreal intelligence (AI) firm mentioned it is making GPT 5.6 Cyber out there via Dawn Purple, a brand new tier that gives entry to its purpose-trained cybersecurity fashions to different companies for approved vulnerability analysis, exploit validation, and safety testing.
GPT-5.6-Cyber, a extra cyber-permissive model of GPT-5.6 Sol, builds upon GPT‑5.5‑Cyber, which OpenAI launched in June 2026.
To measure the lowered price of refusals offered by GPT‑5.6‑Cyber via Dawn Purple entry, OpenAI mentioned it created an inside analysis referred to as Superior Cybersecurity Completion Price that measures how typically fashions reply to prompts associated to exploit-chain improvement, authentication bypass, privilege escalation, and different superior cybersecurity situations.
The checks present that GPT‑5.6‑Cyber completes 95.0% of those requests, in contrast with simply 1.5% for GPT‑5.6 Sol and a couple of.0% when used with Dawn Blue entry. It has additionally been discovered to efficiently full extra requests than GPT‑5.5‑Cyber, which completed solely 57.3% of requests.
GPT‑5.6‑Cyber is educated to enhance efficiency on sure cybersecurity workflows involving exploit improvement and superior safety analysis. An ExploitGym benchmark analysis has revealed the mannequin to outperform each GPT‑5.6 Sol and GPT‑5.5 Cyber.
OpenAI mentioned the mannequin additionally demonstrates enhancements in the case of discovering and precisely calibrating the severity of novel zero-day vulnerabilities because of specialised coaching, though it performs worse than GPT‑5.6 Sol in the case of open-ended quests related to uncovering vulnerabilities in a repository, creating a working proof-of-concept, and submitting a high-quality vulnerability report.
This, the corporate famous, is because of “the mannequin generally producing shorter, much less detailed vulnerability experiences.”
One of many high-severity vulnerabilities found by the mannequin is CVE-2026-15903 (CVSS rating: 8.8), an out-of-bounds learn and write vulnerability within the V8 JavaScript engine that would permit a distant attacker to probably execute arbitrary code inside a sandbox through a crafted HTML web page.
It may very well be chained with one other beforehand unknown vulnerability, additionally discovered by the mannequin, to flee the V8 heap sandbox. CVE-2026-15903 was patched by Google in mid-July 2026. OpenAI mentioned the mannequin has additionally been used to flag a number of different flaws –
- At the very least 5 vulnerabilities in a preferred cellular working system, together with a series from an untrusted app to native privilege escalation
- Three important vulnerabilities in a preferred database, together with a distant path to code execution
- Over 400 vulnerabilities that may result in privilege escalation in a preferred working system kernel
Dawn Purple is one in all two entry tiers arrange by OpenAI as a part of the Dawn initiative it launched again in Could 2026, the opposite being Dawn Blue, which offers entry to frontier general-purpose fashions, together with GPT‑5.6 Sol, with built-in guardrails tailor-made to approved defensive safety work.
“Dawn Blue entry removes these guardrails, serving to defenders get extra out of the mannequin in real-world safety duties, together with incident detection and response, investigations, vulnerability administration, and safety assessments,” the corporate mentioned.
GPT‑5.6‑Cyber has been made available to a bunch of trusted buyer companions like Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC, and Sophos to assist determine and patch vulnerabilities earlier than attackers can exploit them and shut the “protection hole.”
These fashions are being pitched to firms as a technique to flag safety vulnerabilities in software program, as unhealthy actors have considerably ramped up their use of the know-how to boost campaigns and perform cyber assaults at pace and scale by no means seen earlier than, even when it hasn’t led to the invention of novel or subtle assault methods.
What’s evident is that AI brokers are enabling cybercriminals and nation-state hackers to outsource the grunt work wanted to plan and perform cyber assaults, providing them a approach to enhance the effectivity and productiveness of their operations, leading to assaults which can be higher, greater, and sooner.
To make issues worse, AI has additionally shortened the trail from vulnerability disclosure to exploitation, with attackers leaning on such instruments to jot down vibe exploits for newly disclosed flaws. With AI already reducing the barrier to take advantage of improvement and accelerating vulnerability analysis, attackers are more likely to solid a wider internet throughout disclosed vulnerabilities going ahead to discover a approach into enterprise networks.
Whereas AI techniques have vastly improved at discovering and exploiting vulnerabilities in software program, they nonetheless require substantial human experience, whilst analysis has discovered that cyber-capable reasoning fashions like ChatGPT 5.5 and Anthropic Claude Opus 4.8 can battle to totally patch a found vulnerability or keep away from introducing new points with their fixes.
“The common success price for producing a patch that totally resolved the vulnerability (with out materially altering software conduct) was simply 26.0%,” 1Password said. “Patches that efficiently resolved the vulnerability, however altered the applying’s conduct within the course of, occurred 20.1% of the time. Conversely, LLM-generated patches didn’t resolve the vulnerability, added a brand new vulnerability, or each, a mean of 53.9% of the time.”
The findings underscore that fashions at present excelling at discovering a variety of vulnerabilities are solely good at successfully patching a “slender subset” of them and assist steer builders away from situations the place the fashions both introduce new bugs no matter whether or not an present challenge was patched or not, successfully increasing an assault floor for malicious actors to take advantage of.
“Fashions working with lowered safeguards carry dangers past commonplace mannequin utilization, whether or not from misuse or misalignment,” OpenAI mentioned. “Regardless of these dangers, we consider that democratizing entry to frontier intelligence for defenders is essential to accelerating and automating cyber protection.”


