HomeSecurityGPT-5.5-Cyber: OpenAI enhances Daybreak for code security

GPT-5.5-Cyber: OpenAI strengthens Daybreak for code security

GPT -5.5-Cyber ​​is OpenAI ’s new, more powerful model for discovering and fixing software vulnerabilities, and the company has just announced the expansion of its Daybreak initiative with the release of its enhanced version. The model is available exclusively to trusted defenders and promises to fundamentally change the way organizations address vulnerabilities in their code. The move marks a strategic shift from simply discovering vulnerabilities to automating their remediation at machine speed .

GPT-5.5-Cyber ​​OpenAI Daybreak software vulnerabilities AI cybersecurity

OpenAI describes GPT-5.5-Cyber ​​as its “most powerful model to date for finding and fixing software vulnerabilities . ” The model is capable of conducting deeper analysis on large code bases, identifying security issues, validating them in a controlled environment, and developing and testing patches. In benchmarks, the model scored 85.6% on CyberGym (versus 81.8% for GPT-5.5), 39.5% on ExploitGym (versus 25.95%), and 69.8% on SEC-bench Pro (versus 63.1%), demonstrating significant progress over its predecessor.

See also: OpenAI announces new, more efficient GPT-5.5 model

In conjunction with the release of GPT-5.5-Cyber, OpenAI is updating the Codex Security plugin to improve the process of discovering and fixing vulnerabilities in existing systems. The plugin allows developers to perform deep scans, review recent changes, generate reports with details on severity, affected code locations, validation evidence, and remediation instructions. It also allows for attack path detection , threat modeling , validation of findings, and codebase-specific patching . To date, Codex Security has scanned over 30 million commits across more than 30,000 codebases , with 70,000+ findings manually marked as fixed and 500,000+ automatically identified as resolved.

GPT-5.5-Cyber ​​- SecNews.gr

GPT-5.5-Cyber ​​and Daybreak: What OpenAI detected in the real code

Through the Daybreak initiative, OpenAI has already identified a significant number of vulnerabilities in operating systems and web browsers. In the Linux Kernel, 8 kernel pointer information leak PoCs and 24 local privilege escalation exploits were discovered . In OpenBSD, a 23-year- old use-after-free vulnerability was found in System V semaphores. In FreeBSD , 34 vulnerabilities and 7 local privilege escalation PoCs were found , while 6 vulnerabilities were found in dnsmasq ( CVE-2026-4890 , CVE-2026-4891 , CVE-2026-4892 and CVE-2026-5172 ). Also notable is the discovery of CVE-2026-47729 (known as Squidbleed ), a 29-year-old vulnerability in the Squid web proxy that can leak cleartext HTTP requests of other users under certain conditions.

See also: OpenAI GPT-5.4-Cyber: New AI model for cybersecurity

OpenAI Patch the Planet

OpenAI announced a new initiative called Patch the Planet, in partnership with Trail of Bits and HackerOne, aimed at securing open-source projects. Initial participating projects include cURL, NATS Server, pyca/cryptography, Sigstore, aiohttp, the Go project, freenginx, Python , and python.org. The initiative aims to relieve maintainers of the burden of patching by allowing security engineers to review and validate findings, collaborate with projects to develop patches, and create reusable vulnerability discovery workflows.

OpenAI Daybreak AI platform for vulnerability detection and cybersecurity

Competition

These developments come at a time when frontier models from Anthropic and OpenAI are accelerating vulnerability discovery, leaving software maintainers inundated with an increasing volume of bugs that need to be verified, triaged, and fixed. The Canadian Centre for Cyber ​​Security has noted that “ threat actors with limited technical expertise can use publicly available AI models for malicious purposes .” Organizations are urged to prepare for AI-based exploits that may bypass proactive checks. GPT-5.5-Cyber ’s high ExploitGym score ( 39.5% ) underscores this concern: the model is a powerful tool, and access to it is therefore subject to strict verification checks through the Trusted Access for Cyber ​​framework.

See also: OpenAI Daybreak: The Answer to the Claude Mythos for Cybersecurity

For organizations looking to leverage Daybreak, OpenAI recommends integrating Codex Security into their software development lifecycle (SDLC) for continuous code scanning and patch automation, as well as requesting access through the Trusted Access for Cyber ​​program. The Patch the Planet represents a significant effort to reduce the time gap between vulnerability discovery and patching — a gap that malicious actors are increasingly exploiting. According to The Hacker News, the initiative marks a paradigm shift in cybersecurity: from reactive vulnerability discovery to proactive, AI-driven patching at machine speed.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS