Daybreak: Tools for securing every organization in the world

Daybreak: Tools for securing every organization in the world

OpenAI announced an expansion of Daybreak to help democratize patching vulnerable software at machine speed.

Codex Security update accelerates vulnerability patching

The Codex Security plugin update provides out‑of‑the‑box defensive workflows that integrate scanning, validation, and patch generation directly into developer environments. Developers can run deep scans or review recent changes, generate reports with severity, affected code locations, validation evidence, and remediation guidance, trace attack paths, build threat models, validate findings, and generate codebase‑specific patches for review. The plugin can also triage and validate existing findings from scanners, advisories, bug‑bounty reports, or ticketing systems, then automate patch generation at scale to close a backlog of vulnerabilities. When a scan completes, Codex Security can export to existing vulnerability management systems or integrate via SARIF files, CodeQL queries, and more. Since its research preview in March, the tool has scanned over 30 million commits across more than 30 000 codebases; human reviewers have manually marked more than 70 000 findings as fixed, and over 500 000 findings have been automatically determined to be fixed.

GPT‑5.5‑Cyber release enhances defensive AI capabilities

The full release of GPT‑5.5‑Cyber delivers higher performance on cybersecurity benchmarks while retaining permissive behavior for authorized defenders. On CyberGym, which measures whether an agent can reproduce known vulnerabilities in software environments, the updated model reached 85.6 % compared with 81.8 % for GPT‑5.5. On ExploitGym, which tests turning known vulnerabilities into working exploits that achieve unauthorized code execution, GPT‑5.5‑Cyber scored 39.5 % versus 25.95 % for GPT‑5.5. On SEC‑bench Pro, which evaluates long‑horizon vulnerability discovery and proof‑of‑concept generation across complex software targets, the model reached 69.8 % compared with 63.1 % for GPT‑5.5. The model sustains deeper analysis across large codebases, identifying security‑relevant components, tracing reachability of vulnerable code, validating likely issues in controlled environments, developing and testing patches, and preparing evidence for human review. For most defenders, GPT‑5.5 with Trusted Access for Cyber and Codex Security remains the right starting point; GPT‑5.5‑Cyber is intended for verified defenders whose authorized work requires the most advanced cyber capabilities and more permissive behavior, paired with stronger verification, monitoring, scoped controls, and review.

Daybreak Cyber Partner Program scales access through trusted partners

The program lets security vendors embed GPT‑5.5 with Trusted Access for Cyber into their products, extending defensive AI to more organizations. Participating partners can use the model in the security products and services they provide to customers, allowing those customers to benefit from the model’s defensive capabilities while keeping direct model access in the hands of the partners. OpenAI will collaborate with program partners to strengthen safeguards, monitoring, and abuse‑prevention standards needed to deploy these capabilities responsibly across the security ecosystem. An initial set of partners includes Accenture, Akamai, NCC Group, Capgemini, Cato Networks, Check Point, Cisco, Cloudflare, Cognizant, CrowdStrike, Darktrace, Elastic, EY, Fortinet, GuidePoint Security, IBM, KPMG, Okta, Palo Alto Networks, Proofpoint, PwC, SentinelOne, SpecterOps, Sophos, Tenable, Trend AI, Wiz, and Zscaler, with plans to expand to more organizations in the coming months.

Patch the Planet helps open-source maintainers move from findings to fixes

Patch the Planet pairs expert security researchers with open-source maintainers to validate, deduplicate, and patch vulnerabilities, reducing maintainer burden. The initiative, founded with Trail of Bits and in collaboration with HackerOne and Calif, funds expert researchers and equips them with Codex Security and advanced models to work directly with maintainers. Each engagement begins with consultation; maintainers define priorities, preferences, and disclosure processes. Researchers then manage the work end‑to‑end—validating and deduplicating both vulnerabilities and patches before they reach maintainers. Participating projects receive ChatGPT Pro, conditional access to Codex Security, and API credits for core development, maintainer automation, and release workflows. The initial five‑day sprint across multiple projects surfaced hundreds of issues for review, merged dozens of patches with more underway, and built reusable fuzzing, variant‑analysis, differential‑testing, and specification‑based testing workflows. More than 30 open‑source projects have committed to participate, with initial participants including cURL, Go, Python, Sigstore, and pyca/cryptography.

Collaboration with governments and critical infrastructure operators

OpenAI is working with governments and critical infrastructure operators to tailor safeguards and extend trusted access for defending essential systems. In the past month, Trusted Access for Cyber partnerships have been established with Australia, Canada, France, Germany, Japan, Republic of Korea, and EU institutions such as ENISA, alongside a growing partnership with the UK government around cyber, testing and evaluation, and other areas of mutual interest. The focus of this work is to make advanced AI more useful to defenders while making it harder for malicious actors to cause real‑world harm. OpenAI also plans to work directly with eligible operators of critical infrastructure, including government networks, to develop safeguards tailored to the systems they operate, and to incorporate broader context and identifiers about specific systems into its cybersecurity safeguards.

Outlook: shifting from vulnerability discovery to remediation

Daybreak aims to close the loop from finding to fixing vulnerabilities, promoting cyber resilience. By bringing together frontier cyber capabilities, Trusted Access for Cyber, Codex Security workflows, ecosystem partners, and expert researchers, the initiative provides organizations the tools they need to stay secure even as the cyberthreat landscape continues to accelerate. The goal is to move beyond using models to find more vulnerabilities toward a world of safer software and cyber resilience.

Sources