Official GPT-5.5-Cyber Version and Codex Security Released, Vulnerability Verification and Patching Automated
OpenAI is expanding Daybreak, a cybersecurity initiative that uses AI to discover software vulnerabilities and automate verification and patching.
OpenAI announced plans to expand Daybreak on the 23rd.
Daybreak explained that it aims to accelerate the entire fix process, extending beyond vulnerability discovery to verification, risk assessment, and the development, testing, and distribution of patches.
Codex Security, unveiled alongside it, analyzes the team's code and threat models to identify potential vulnerabilities, determines whether actual access to the code is possible, collects verification grounds, and develops and verifies patches.
The developer and security personnel decide whether to conduct further investigation and apply patches.
The official version of GPT-5.5-Cyber was released on a limited basis to verified defense experts.
This model analyzes security components and attack paths of large-scale codebases and verifies vulnerabilities in a controlled environment.
OpenAI announced that it recorded 85.6% on CyberGym, a benchmark evaluating the ability to reproduce known vulnerabilities, surpassing GPT-5.5's 81.8%.all.
OpenAI is also launching the Daybreak Cyber Partner Program to support security software and service partners in utilizing GPT-5.5 and Trusted Access for Cyber in their products.
OpenAI launched the 'Patch the Planet' program to help open source project maintainers move from discovering vulnerabilities to actually fixing them.
It was developed in collaboration with the security research firm Trail of Bits, and HackerOne and Calif support vulnerability classification and coordinated disclosure.
More than 30 open source projects have expressed their intention to participate, and initial participating projects included cURL, Go, Python, Sigstore, and pyca/cryptography.
Participating projects are provided with access to ChatGPT Pro, conditional access to Codex Security, and API credits.
OpenAI has collaborated with governments and agencies around the world to strengthen defensive cybersecurity capabilities and protect critical infrastructure.
Over the past month, trust-based access partnerships have been established with Australia, Canada, France, Germany, South Korea, Japan, and EU agencies including the European Union Cybersecurity Agency (ENISA).
It was also announced that cooperation with the UK government in the fields of cybersecurity, testing, and evaluation is being expanded.