OpenAI Releases GPT-5.5-Cyber: Defender-Restricted AI for Automated Vulnerability Detection, Exploitability Validation, and Patching (Daybreak / Patch the Planet)

OpenAI Releases GPT-5.5-Cyber (TL-2026-0909), also tracked as GPT-5.5-Cyber, is a info-severity tracked intrusion set, first published 2026-06-23. It has no confirmed attribution, affects OpenAI GPT-5.5-Cyber (Daybreak / Trusted Access for Cyber), maps to 16 MITRE ATT&CK techniques (T1190, T1195.001, T1203), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-0909

Threat ID
TL-2026-0909
Also known as
GPT-5.5-Cyber, Daybreak, Patch the Planet, Codex Security
Severity
INFO
Status
MONITORING
Category
THREAT_INTEL
First published
2026-06-23
Last reviewed
2026-06-23
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, open-source software, government, critical infrastructure
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
15

Malware and tooling in OpenAI Releases GPT-5.5-Cyber

Malware and tooling: Codex Security, Daybreak, GPT-5.5-Cyber

OpenAI released GPT-5.5-Cyber, a cyber-specialized model distributed only to verified, trusted defenders through its Trusted Access for Cyber program, alongside the Codex Security plugin and the Patch the Planet initiative co-built with Trail of Bits and HackerOne. The model can navigate large codebases, trace attack paths, validate exploitability, and generate targeted patches in a single automated workflow. This is a defensive/dual-use AI capability announcement — not an active exploit, malware campaign, or vulnerability.

How OpenAI Releases GPT-5.5-Cyber works

On June 22-23, 2026, OpenAI expanded its Daybreak cybersecurity platform with the full release of GPT-5.5-Cyber, the Codex Security plugin, and the Patch the Planet initiative. GPT-5.5-Cyber is a cyber-specialized variant that, per OpenAI and reporting by Cyber Security News and Axios, can navigate large codebases, trace attack paths, validate exploitability, generate targeted patches, and produce remediation evidence within a single automated workflow. It reports the highest single-model score recorded on CyberGym at 85.6% (versus 81.8% for GPT-5.5), 39.5% on ExploitGym (versus 25.95% for GPT-5.5), and 69.8% on SEC-bench Pro (versus 63.1% for GPT-5.5).

The full model is not available for general use. It is limited to verified, trusted defenders through OpenAI's Trusted Access for Cyber program, which reduces automated safety refusals for approved defensive tasks such as secure code review, vulnerability triage, malware analysis, red teaming, and penetration testing. GPT-5.5 with Trusted Access is recommended as the entry point. OpenAI states it conducted pre-deployment testing with the Center for AI Standards and Innovation (CAISI), coordinated with the Office of the National Cyber Director (ONCD), and references the June 2026 Executive Order on AI security. Trusted Access for Cyber partnerships named include Australia, Canada, France, Germany, Japan, South Korea, EU institutions, and ENISA. Daybreak partner roster includes Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, Oracle, Palo Alto Networks, and Zscaler.

The Codex Security plugin, launched in research preview in March 2026, can review recent commits and produce reports with severity, affected code locations, validation evidence, and remediation guidance; trace attack paths; build threat models; validate findings; generate patches; and export results into vulnerability management systems. Reported aggregate Codex Security statistics include scanning over 30 million commits, processing more than 30,000 codebases, handling over 70,000 manually verified fixes, and automatically resolving over 500,000 findings. The Patch the Planet initiative, co-founded with Trail of Bits and partnered with HackerOne, pairs AI-assisted vulnerability research with human expert review; an initial five-day sprint surfaced hundreds of issues, merged dozens of patches, and produced reusable testing workflows including fuzzing, variant analysis, and differential testing. More than 30 open-source projects have committed to participate, with initial participants including cURL, Go, Python, Sigstore, and pyca/cryptography.

From a threat-intelligence standpoint this is tracked as an INFORMATIONAL industry/landscape signal documenting a dual-use AI capability. The same capabilities that accelerate defensive vulnerability discovery, exploitability validation, and patch generation also lower the barrier to offensive vulnerability research and exploit development if misused — which is why OpenAI gates the full model behind verified-defender access and reduced-refusal Trusted Access controls. There is no CVE, no active exploitation, no public proof-of-concept against a target, no malware family, no threat actor, and no malicious indicators of compromise associated with this record. The MITRE techniques and indicators below document the dual-use capability surface (primarily Resource Development and Reconnaissance) and the benign reference entities, not an observed attack.

MITRE ATT&CK techniques used in TL-2026-0909

Initial Access

T1190 Exploit Public-Facing Application; T1195.001 Compromise Software Dependencies and Development Tools

Execution

T1203 Exploitation for Client Execution

Resource Development

T1587 Develop Capabilities; T1587.004 Exploits; T1588 Obtain Capabilities; T1588.002 Tool; T1588.005 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1592 Gather Victim Host Information; T1592.002 Software; T1593 Search Open Websites/Domains; T1595 Active Scanning; T1595.002 Vulnerability Scanning; T1596 Search Open Technical Databases; T1596.005 Scan Databases

Affected products and versions in OpenAI Releases GPT-5.5-Cyber

  • OpenAI — GPT-5.5-Cyber (Daybreak / Trusted Access for Cyber)

Remediation for OpenAI Releases GPT-5.5-Cyber

Immediate actions

  • No remediation required: this is a defensive/dual-use AI capability announcement, not a vulnerability or active threat.
  • Defenders eligible for OpenAI Trusted Access for Cyber can evaluate GPT-5.5-Cyber and Codex Security for secure code review and vulnerability triage.

Longer-term hardening

  • Incorporate AI-assisted vulnerability discovery (fuzzing, variant analysis, differential testing) into secure SDLC and patch management workflows.
  • Track dual-use AI capability uplift as a landscape factor in threat models: assume adversaries gain similar AI-accelerated vulnerability research over time and prioritize timely patching of public-facing and open-source dependencies.

Timeline of OpenAI Releases GPT-5.5-Cyber

  • CyberGym benchmark (1,507 instances across 188 open-source projects, derived from OSS-Fuzz vulnerabilities) published (arXiv 2506.02548), later used to evaluate GPT-5.5-Cyber.
  • SEC-bench benchmark for evaluating LLM agents on real-world software security tasks published (arXiv 2506.11791); SEC-bench Pro later used as a GPT-5.5-Cyber evaluation.
  • OpenAI Codex Security plugin launched in research preview.
  • Axios reports OpenAI rolling out a more capable version of its cyber model with reduced safety refusals for approved defenders under Trusted Access for Cyber.
  • Trail of Bits publishes 'Introducing Patch the Planet,' detailing AI-assisted vulnerability research paired with human expert review and an initial five-day sprint surfacing hundreds of issues.
  • OpenAI expands its Daybreak cybersecurity platform; announces Patch the Planet initiative co-built with Trail of Bits and HackerOne, and the Codex Security plugin.
  • Threadlinqs Intelligence ingests the announcement as TL-2026-0909, an INFORMATIONAL industry/landscape signal documenting a dual-use AI capability (no CVE, no IOCs, no active exploitation).
  • GPT-5.5-Cyber full release covered by Cyber Security News: 85.6% CyberGym, 39.5% ExploitGym, 69.8% SEC-bench Pro; limited to verified, trusted defenders.

Sources cited for OpenAI Releases GPT-5.5-Cyber

Threats related to OpenAI Releases GPT-5.5-Cyber

Detection coverage for TL-2026-0909

As of 2026-06-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0909 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats