2 weeks ago
OpenAI's Daybreak Red hacking model found 400 kernel vulnerabilities
OpenAI is a company that makes very smart computer programs.
It made a special helper program that can find mistakes, called bugs, in other computer software.
Most computer programs are not allowed to do hacking things, but OpenAI loosened the safety rules on this helper so it could do that work.
They call this programme Daybreak, and the special helper is called GPT-5.6-Cyber.
The helper is so good that it finished 95 out of every 100 hard cyber tasks it was given.
It found more than 400 bugs in one operating system, which is the main software a computer runs on.
It also found two secret bugs in Chrome, a web browser many people use, and Google fixed them.
Because this helper could be used for bad things too, only approved people are allowed to use it.
OpenAI hopes the helper will help good guys protect computers before bad guys break in.
OpenAI announced Daybreak, a two-tier cybersecurity programme, on August 10, splitting access into a Blue tier for defenders and a restricted Red tier.
Daybreak Red gates GPT-5.6-Cyber, OpenAI's most permissive cybersecurity model, trained with reduced safeguards so it can develop working exploits.
In testing, GPT-5.6-Cyber completed 95 per cent of advanced cybersecurity task requests.
The model uncovered two previously unknown Chrome V8 vulnerabilities, fixed by Google as CVE-2026-15903, and more than 400 privilege-escalation vulnerabilities in a single popular operating system kernel.
Access is restricted through vetting rather than sale, following Google's limited-access pilot for its Gemini 3.5 Flash Cyber model.
- Who
- OpenAI, which released the Daybreak programme and the GPT-5.6-Cyber model.
- What
- A two-tier cybersecurity programme called Daybreak, whose restricted GPT-5.6-Cyber model found 400+ kernel vulnerabilities and other serious bugs in widely used software.
- Where
- Not stated in the articles; the findings concern software such as Google's Chrome.
- When
- Announced on August 10.
- Why
- To give defenders equivalent capability as AI models increasingly breach real systems, closing what OpenAI calls a narrowing cyber defence window.
Critics Concerned About Offensive AI
Supporters Citing the Defence Window
Building exploit-writing AI models
Critics Concerned About Offensive AI
Loosening safety rails so a model writes working exploits creates a dangerous dual-use tool that could be misused in attacks.
Supporters Citing the Defence Window
Because AI models already breach real systems autonomously, defenders need the same capability to keep pace and close a widening defence gap.
Restricting access by vetting
Critics Concerned About Offensive AI
The capability itself is sensitive, and relying on approvals rather than built-in limits may not be enough to prevent misuse.
Supporters Citing the Defence Window
Vetting-based distribution, rather than selling openly, is the responsible way to share an offensive security tool with approved defenders.
Key facts
- Programme
- Daybreak (Blue and Red access tiers)
- Red tier model
- GPT-5.6-Cyber, OpenAI's most permissive cybersecurity model
- Blue tier models
- Frontier general-purpose models including GPT-5.6 Sol
- Announcement date
- August 10
- Task completion rate
- 95 per cent of advanced cybersecurity task requests
- Kernel vulnerabilities found
- More than 400 privilege-escalation vulnerabilities in one popular operating system kernel
- Chrome V8 findings
- Two previously unknown vulnerabilities, fixed as CVE-2026-15903
- Comparable Google model
- Gemini 3.5 Flash Cyber, limited to governments and trusted partners
Quotes
OpenAI
OpenAI representative explaining access tiers
“"A system that finds vulnerabilities and writes working exploits is not a defensive tool that happens to have offensive applications."”
wionews.com
“"Four hundred privilege‑escalation bugs in one kernel is not a model finding a needle in a haystack."”
wionews.com










