OpenAI has unveiled GPT-5.6-Cyber, a specialized AI model built to help authorized defenders detect advanced cybersecurity threats, expanding its Daybreak defender program into two access tiers: Daybreak Blue for general defensive work like malware analysis and incident response, and the more restricted Daybreak Red for advanced vulnerability research and exploit validation.
Researchers used GPT-5.6-Cyber to investigate V8, the JavaScript engine behind Google Chrome, uncovering two previously unknown vulnerabilities that could be chained together to corrupt memory and escape Chrome's protective sandbox. The findings were disclosed to Google through coordinated vulnerability disclosure and patched as CVE-2026-15903, a high-severity flaw where the V8 optimizing compiler skipped a safety check during integer conversion, potentially allowing attackers to execute arbitrary code inside Chrome's sandbox.
The model's track record extends well beyond Chrome. OpenAI says GPT-5.6-Cyber has also contributed to finding at least five vulnerabilities in a popular mobile operating system, three critical vulnerabilities in a widely used database, and more than 400 privilege-escalation vulnerabilities in a popular operating system kernel.
On performance, GPT-5.6-Cyber completes 95% of advanced cybersecurity requests that OpenAI's general-purpose model refuses, compared to just 1.5% for the standard model, reflecting OpenAI's attempt to close what it describes as a widening gap between attacker and defender AI capabilities. Access requires identity verification, monitoring, approved-use limits, and legal attestations, with partners including Accenture, IBM, CrowdStrike, and Cisco now able to build the model into their own security products.
The launch arrives alongside a parallel industry shift: Google says it now uses large language models throughout its own vulnerability management process — discovering flaws, reproducing reports, determining severity, and generating candidate patches — crediting AI with helping fix over 1,000 Chrome security bugs across two recent releases. Together, these developments underscore how AI-driven vulnerability discovery is rapidly becoming standard practice on both the offensive research and defensive patching sides of major software platforms.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




