OpenAI's Daybreak adds GPT-5.5-Cyber and 'Patch the Planet' for open-source defense
OpenAI has broadened its Daybreak cybersecurity effort with the full release of GPT-5.5-Cyber, a model tuned for defensive security work: locating vulnerabilities in large codebases, confirming them in a sandbox, and drafting and testing fixes. The company frames it as its most capable security model so far, citing gains over the general GPT-5.5 on several benchmarks — 85.6% vs 81.8% on CyberGym, 39.5% vs 25.95% on ExploitGym, and 69.8% vs 63.1% on SEC-bench Pro. The emphasis is notable: the pitch is about shipping patches, not just surfacing bugs.
Alongside the model, OpenAI launched ‘Patch the Planet,’ an initiative aimed at hardening critical open-source projects, an updated Codex Security plugin meant to catch flaws before they reach production and speed remediation in existing systems, and a Cyber Partner Program for security vendors. Together these position Daybreak as an end-to-end discover-validate-patch pipeline rather than a standalone scanner.
OpenAI points to concrete results to back the claims, including Linux kernel findings (kernel-pointer info-leak PoCs and 24 local privilege-escalation exploits), a 23-year-old use-after-free in OpenBSD’s System V semaphore implementation, 34 vulnerabilities and 7 LPE PoCs in FreeBSD, and an HTTP/2 denial-of-service technique dubbed ‘HTTP/2 Bomb’ affecting major implementations. The broader significance is the push toward AI that automates the full vulnerability lifecycle at scale — promising for under-resourced open-source maintainers, but also raising the familiar dual-use question of equally capable offensive tooling.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.