OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model intended to help defenders find vulnerabilities and validate exploits before attackers can use AI at scale, The Decoder reports. The move adds two access tiers, Daybreak Blue and Daybreak Red, and places the most permissive cyber model behind the Red tier. According to The Decoder, Daybreak Blue gives users access to GPT-5.6 Sol with safeguards tuned for authorized defensive work such as vulnerability detection, malware analysis, and incident response. Daybreak Red is aimed at security researchers working on vulnerability research, exploit validation, and penetration testing. GPT-5.6-Cyber is available through that Red tier. OpenAI is also putting operational controls around the program. The Decoder reports that access requires identity verification, account security measures, monitoring, and legal declarations. Hardware security keys are set to become mandatory for all Daybreak accounts on September 1, 2026, and OpenAI recommends running security workflows inside isolated sandboxes and using Auto-Review mode in Codex for actions requiring elevated privileges. The core product claim is that GPT-5.6-Cyber refuses fewer authorized security tasks than general-purpose models or more restricted tiers. The Decoder says the model is based on GPT-5.6 Sol and was trained for tasks including zero-day discovery and exploit-chain construction. In OpenAI’s internal “Advanced Cybersecurity Completion Rate” benchmark, GPT-5.6-Cyber answered 95% of queries across scenarios such as exploit-chain development, authentication bypass, and privilege escalation. The comparison figures are stark but should be treated as OpenAI’s own benchmark until independently validated. The Decoder reports that GPT-5.6 Sol with safety measures enabled completed 1.5% of the benchmark, Daybreak Blue reached 2%, and GPT-5.5-Cyber reached 57.3%. In one test involving a WebSocket authentication bypass for an internal admin panel, only GPT-5.6-Cyber on Daybreak Red produced working exploit code, while other variants refused. OpenAI also says the model has already been used in real vulnerability research. Per The Decoder, GPT-5.6-Cyber analyzed V8, Chrome’s JavaScript engine, and found two previously unknown flaws that could be chained to corrupt memory and bypass the V8 heap sandbox. Google fixed the issues after coordinated disclosure, and the flaws were assigned CVE-2026-15903. The Decoder further reports that GPT-5.6-Cyber found at least five vulnerabilities in a “popular mobile operating system.” One reported chain would let an app escalate from restricted access to administrator privileges. The excerpt provided does not name the operating system or give a disclosure timeline, so that claim remains less complete than the Chrome/V8 example. The strategic tension is explicit: the same model capability that can help authorized defenders can also enable offensive workflows if access controls fail. OpenAI’s approach, as described by The Decoder, is to make more capable exploit-generation and vulnerability-research behavior available to vetted users under a monitored program, rather than block that behavior entirely across all products. Who benefits: Authorized security researchers, red teams, incident responders, and vulnerability-discovery programs could benefit if Daybreak Red gives them reliable model help on tasks general models refuse. OpenAI also gains a structured way to serve high-sensitivity cyber users without opening the same capabilities broadly. Who's exposed: Organizations with weak vulnerability-management practices are more exposed if AI-assisted exploit development becomes more capable across the industry. OpenAI is also exposed to reputational and safety risk if vetting, monitoring, or sandboxing controls fail.