OpenAI has expanded its Daybreak security effort with new tools and partnerships to speed up software patching. The initiative aims to address the shifting landscape of cybersecurity where AI has accelerated vulnerability discovery, creating a bottleneck in patching rather than finding flaws. The company stated that defenders are now overwhelmed by the number of vulnerabilities found, necessitating a move toward "democratize patching vulnerable software at machine speed."
The expansion includes the full launch of GPT-5.5-Cyber for vetted defenders and the release of a Codex Security plugin. OpenAI reported that its models have already been used to generate patches for critical vulnerabilities in major browsers, network infrastructure, and operating systems such as Free BSD and the Linus Kernel. The company noted that frontier AI models have increasingly accelerated vulnerability discovery, shifting the primary challenge from detection to remediation.
Daybreak Cyber Partner Program
The Daybreak Cyber Partner Program allows security vendors to incorporate GPT-5.5 with Trusted Access for Cyber into their products and services. This structure maintains direct model access with participating partners. OpenAI is also expanding its cybersecurity partnerships with governments and critical infrastructure operators. Collaborators include agencies in the U.S., Australia, Canada, France, Germany, Japan, South Korea, and EU institutions such as ENISA.
Patch the Planet Initiative
OpenAI revealed the "Patch the Planet" initiative, a collaboration with HackerOne, Calif, researchers, and maintainers. The goal is to help widely used open-source projects move from findings to fixes. More than 30 open-source projects have signed on, including cURL, Go, Python, Sigstore, and pyca/cryptography. The company emphasized that the initiative focuses on making powerful cyber capability available to defenders with appropriate access, governance, and human oversight.
Tool Capabilities and Performance
The updated Codex Security plugin assists developers in running scans, assessing severity, collecting validation evidence, mapping potential attack paths, and generating patches tailored to a specific codebase for human review. It can ingest findings from various sources, such as scanners, advisories, bug bounties, or ticketing systems, to automate patch creation at scale and export results into existing workflows.
OpenAI is rolling out the full version of GPT-5.5-Cyber to trusted defenders following an earlier preview. The company stated that the model outperformed GPT-5.5 on benchmarks including CyberGym, ExploitGym, and SEC-bench Pro.