
OpenAI ships GPT-5.6-Cyber, which completes 95% of exploit requests other models refuse
OpenAI released GPT-5.6-Cyber, a GPT-5.6 Sol variant trained for zero-day discovery and exploit-chain construction, which completes 95% of offensive security requests on OpenAI's internal benchmark against 57.3% for GPT-5.5-Cyber and 2% for the defensive Daybreak Blue tier. The capability is demonstrated rather than promised: the model found two chainable flaws in Chrome's V8 engine, disclosed as CVE-2026-15903, plus at least five in a popular mobile operating system. Access runs only through the new Daybreak Red tier, requiring identity verification and hardware security keys, which moves the safety boundary from model refusal to enrollment control.
Source: the-decoder.com ↗
The model rarely refuses security-related queries that other models block by default.
Why this matters
- → Shifts offensive security capabilities from model refusal to access control
- → Demonstrates AI finding real zero-days (Chrome V8, mobile OS flaws)
- → Narrows the window for defenders as threat actors adopt autonomous AI attacks