- OpenAI has added GPT-5.5-Cyber, updated Codex Security workflows, and open-source patching support to its Daybreak program.
- The additions are intended for developers, enterprise security teams, approved cyber defenders, software vendors, open-source maintainers, and critical infrastructure operators.
- OpenAI says the program is shifting its focus from identifying vulnerabilities to validating problems, producing and testing patches, coordinating disclosure, and helping organizations deploy fixes.
- Codex Security now provides security workflows inside Codex, including codebase scans, threat modeling, attack-path analysis, validation evidence, remediation guidance, and code-specific patch generation.
- Human reviewers retain control over which findings are investigated, which changes are applied, and what information is shared.
- OpenAI reports that the model outperformed the standard GPT-5.5 model across three cyber benchmarks, although the supplied announcement does not include independent replication of those results.
- The OpenAI Daybreak Cyber Partner Program will make selected defensive capabilities available through products and services from more than 20 security businesses.
- OpenAI says Codex Security has scanned more than 30 million commits across over 30,000 codebases since the cloud version entered research preview in March.
- Sidharth Sharma, who leads go-to-market activity for OpenAI in Asia-Pacific, stated: 'Cyber is quickly moving up the priority list for every enterprise. The focus now should be practical: securing code as it’s written, patching vulnerabilities faster and protecting the software supply chain.'
- OpenAI describes GPT-5.5-Cyber as its most capable model for advanced, authorized cybersecurity work.
- OpenAI says GPT-5.5-Cyber is intended for verified defenders whose work requires advanced cyber capabilities and more permissive model behavior, supported by stronger verification, monitoring, scoped controls, and review.
- On CyberGym, a benchmark measuring whether an AI agent can reproduce known software vulnerabilities, OpenAI reports that GPT-5.5-Cyber scored 85.6 percent.
- The partner group is expected to expand over the coming months.
- OpenAI founded the initiative with Trail of Bits and is working with HackerOne, Calif, security researchers, and project maintainers.
- More than 30 open-source projects have committed to participate.
- OpenAI states: 'Finding vulnerabilities is important, but it’s landing the fix that protects the world, and that takes collaboration and community support.'
OpenAI has introduced GPT-5.5-Cyber, its most advanced model for cybersecurity, alongside enhanced Codex Security workflows. This initiative aims to shift the focus from merely identifying vulnerabilities to validating issues, producing patches, and coordinating disclosures to better protect software supply chains.
The Codex Security now includes comprehensive security workflows, such as codebase scans, threat modeling, and attack-path analysis. OpenAI reports that since March, it has scanned over 30 million commits across more than 30,000 codebases, demonstrating its commitment to enhancing software security.
Sidharth Sharma, leading OpenAI's go-to-market efforts in Asia-Pacific, emphasized the urgency of cybersecurity, stating, 'Cyber is quickly moving up the priority list for every enterprise.' The initiative also collaborates with Trail of Bits and HackerOne, engaging over 30 open-source projects to foster community support in addressing vulnerabilities.91415
On the CyberGym benchmark, GPT-5.5-Cyber achieved an impressive 85.6 percent score, showcasing its capabilities in reproducing known software vulnerabilities. OpenAI's Daybreak Cyber Partner Program will provide selected defensive capabilities through partnerships with more than 20 security businesses, reinforcing its commitment to collaborative cybersecurity efforts.
OpenAI asserts, 'Finding vulnerabilities is important, but it’s landing the fix that protects the world.'16
“OpenAI has introduced GPT-5.5-Cyber and updated Codex Security workflows to enhance cybersecurity efforts. The initiative focuses on validating problems, producing patches, and collaborating with over 30 open-source projects.”
