OpenAI · 2026-05-11 · major
OpenAI Daybreak — Cyber Defense Suite Pairs GPT-5.5, Codex Security, and GPT-5.5-Cyber Across Cloudflare, Cisco, CrowdStrike, and Palo Alto Networks
OpenAI's response to Anthropic's Project Glasswing bundles GPT-5.5, a Codex Security agent, and the restricted GPT-5.5-Cyber model behind partnerships with 20+ cyber vendors for code review, threat modeling, and patch validation.

OpenAI's cyber-defense initiative wraps GPT-5.5 plus a security-tuned Codex agent into a vendor ecosystem aimed at automating code review and patch validation.
What is it?
Daybreak is OpenAI's first product-shaped cybersecurity push, announced May 11 by Greg Brockman. It bundles three model tiers — standard GPT-5.5 for everyday workflows, GPT-5.5 with Trusted Access for Cyber for authorized defensive work, and the heavily gated GPT-5.5-Cyber for red-team and penetration testing — behind a Codex Security agent that drives the loop.
How does it work?
Codex Security ingests a repository, builds threat models, identifies exploitable flaws in isolated sandboxes, proposes patches, and revalidates them. The system also handles dependency risk analysis, detection signals, and remediation guidance. Access is tightly gated: organizations must request a scan or contact OpenAI sales, and GPT-5.5-Cyber stays under Trusted Access controls.
Why does it matter?
Anthropic's Project Glasswing has already shown what frontier models can do for vulnerability hunting — Mozilla used Claude Mythos to surface 271 Firefox bugs. Daybreak is the second top-lab to formalize that workflow into a partner ecosystem, with Cloudflare, Cisco, CrowdStrike, Palo Alto Networks, Akamai, Fortinet, Oracle, Zscaler, Snyk, Tenable, Rapid7, SentinelOne, Trail of Bits, Socket, Semgrep, and others lined up.
Who is it for?
enterprise security teams and SOC tooling vendors