What happened
OpenAI on August 10 announced GPT-5.6-Cyber, a version of its flagship GPT-5.6 Sol model tuned for cybersecurity work such as finding unknown vulnerabilities and building exploit chains. The model is not publicly available. It sits behind Daybreak Red, the most tightly vetted tier of OpenAI's new Daybreak program for security defenders. A broader tier, Daybreak Blue, gives approved security teams access to frontier general-purpose models with the usual screening on security prompts relaxed, for work like vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. OpenAI says that on its internal benchmark for advanced cyber tasks, the specialized model completes 95 percent of requests where the standard model completes 1.5 percent. The company also disclosed that it used the model to find two previously unknown flaws in V8, the JavaScript engine inside Chrome, which Google has since patched.
Why it matters for your business
You will probably never touch this model, but it will touch you. The security vendors, auditors, and managed providers protecting small businesses are gaining AI tools that find flaws faster — and the same week brought reports of attackers using AI agents to automate intrusions. The practical takeaway is that the time between a flaw becoming known and being exploited keeps shrinking, which makes prompt patching and modern defenses more valuable than ever. When evaluating IT and security vendors, it is now fair to ask how they are using AI-assisted tooling, and how they gate it. None of this changes the fundamentals that stop most real-world attacks on small firms: patched systems, multi-factor authentication, tested backups, and trained people. AI raises the tempo; it does not change the playbook.
