OpenAI launches Daybreak cyber tools and Patch the Planet: GPT-5.5-Cyber scores 85.6% on CyberGym, Codex Security hits 500K+ fixed findings

OpenAI on June 22 expanded its Daybreak cybersecurity initiative with two major announcements. The company released an updated Codex Security plugin that integrates vulnerability scanning, patch generation, and remediation directly into developer workflows; since its March research preview, the tool has scanned over 30 million commits across more than 30,000 codebases, with over 500,000 findings automatically resolved. Alongside it, OpenAI launched the full version of GPT-5.5-Cyber — previously available only as a permissive-only preview — through a continued limited release to verified defenders. The model scores 85.6% on CyberGym, outperforming GPT-5.5’s 81.8%, and also leads on ExploitGym (39.5% vs. 25.95%) and SEC-bench Pro (69.8% vs. 63.1%). A new Daybreak Cyber Partner Program brings in 28 security firms including CrowdStrike, Palo Alto Networks, Cloudflare, Cisco, and Wiz to deliver these capabilities to enterprise customers.

The second announcement, Patch the Planet, is a joint initiative with Trail of Bits, HackerOne, and Calif to move open-source projects from vulnerability discovery to actual patching. An initial five-day sprint across 19 projects — including cURL, Python, Go, Sigstore, and pyca/cryptography — surfaced hundreds of issues, merged dozens of patches, and built reusable fuzzing, variant-analysis, and differential-testing workflows. Highlighted findings include 8 Linux kernel pointer information-leak proof-of-concepts and 24 local privilege escalation exploits generated by GPT-5.5-Cyber; a 23-year-old use-after-free in OpenBSD confirmed exploitable for privilege escalation to root; multiple FreeBSD local privilege escalations with PoCs; and an HTTP/2 Bomb denial-of-service affecting over 880,000 internet-facing servers running NGINX, Apache, IIS, and Pingora. On the browser side, five exploitable Chrome V8 vulnerabilities and over 10 Safari WebKit flaws were reported, plus a Firefox WebAssembly vulnerability patched two days before Pwn2Own Berlin, prompting five of six registered Firefox teams to withdraw. All findings went through manual Trail of Bits review before reaching maintainers. Open-source maintainers can apply to join at Patch the Planet · Trail of Bits.

OpenAI | OpenAI