OpenAI Shifts Cybersecurity Focus from Discovery to Patching as Five Eyes Warns of AI Threats
OpenAI expanded its Daybreak initiative with tools to patch vulnerabilities automatically, while the Five Eyes alliance warned that AI models specialized for cyber attacks are only months away from being operational.
OpenAI on June 23 expanded its Daybreak cybersecurity initiative with a suite of tools that emphasize patching over vulnerability discovery, just as the Five Eyes intelligence alliance issued a rare public warning that AI models specialized for offensive cyber operations could be operational within months. The simultaneous developments underscore a growing divide in how AI is reshaping security: defenders scrambling to fix more flaws than ever, and attackers gaining capabilities to exploit them faster.
Since a research preview launched in March, OpenAI’s Codex Security plugin has processed more than 30 million commits across over 30,000 repositories. Human reviewers confirmed more than 70,000 fixes, and an additional 500,000 findings were resolved automatically, according to the company.
From Discovery to Remediation
The updated Codex Security plugin scans entire codebases, traces attack paths, constructs threat models, validates findings, generates patches, and exports results into existing vulnerability management pipelines via SARIF files and CodeQL queries. OpenAI argues that AI models have accelerated vulnerability discovery to the point where defenders are overwhelmed by the volume of findings, making automated remediation the critical bottleneck.
OpenAI also launched the full version of GPT-5.5-Cyber, described as its most capable model for authorized security work. On the CyberGym benchmark, which tests whether an agent can reproduce known vulnerabilities, the model scored 85.6%, compared to 81.8% for standard GPT-5.5 and outperforming Anthropic’s Mythos model according to OpenAI.
- Patch the Planet: A new initiative with Trail of Bits, HackerOne, and the nonprofit Calif. Expert researchers use Codex Security and OpenAI models to validate and patch vulnerabilities in widely used open source projects before they reach maintainers. More than 30 projects have signed on, including cURL, Go, Python, Sigstore, and pyca/cryptography.
- Daybreak Cyber Partner Program: Security vendors can integrate GPT-5.5 with Trusted Access for Cyber into their products. Launch partners include multiple major cybersecurity firms, with plans to expand to additional vendors and governments.
Five Eyes Sounds Alarm on AI Threats
The Five Eyes alliance, comprising intelligence agencies from the United States, United Kingdom, Canada, Australia, and New Zealand, published a rare call to action warning that AI models specialized for cyber attacks could be developed within months. The group urged a “whole-of-organisation and whole-of-society response” to prepare for AI-enabled threats that could automate reconnaissance, exploit generation, and lateral movement.
OpenAI said it is working directly with governments to help boost cyber defenses and protect critical infrastructure. The company’s Daybreak initiative remains restricted to verified defenders, with access controls designed to prevent misuse. The coming months will see the partner program expand and additional open source projects join Patch the Planet, as the industry confronts a future where both offense and defense are increasingly driven by AI.
Fact check
-
Codex Security processed more than 30 million commits across over 30,000 repositories since March 2026.
verified · source
-
GPT-5.5-Cyber scored 85.6% on the CyberGym benchmark, compared to 81.8% for standard GPT-5.5.
verified · source
-
OpenAI claims GPT-5.5-Cyber outperformed Anthropic's Mythos model on the CyberGym benchmark.
reported · source
-
The Five Eyes alliance warned that AI models specialized for cyber attacks could be operational within months.
verified · source
-
Patch the Planet includes Trail of Bits, HackerOne, and Calif as founding partners, with more than 30 open source projects signed on including cURL, Go, and Python.
verified · source
Source reporting (5)
- SecurityWeek · OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery
- TechRadar Pro · 'Act now': Five Eyes warns that AI models specialized for cyber attacks are only months away
- The Decoder · OpenAI says new GPT-5.5-Cyber outperforms Anthropic's Mythos on cybersecurity benchmark
- Help Net Security · OpenAI wants AI to fix vulnerabilities, not just find them
- Infosecurity Magazine · Five Eyes Group Issues Urgent Call to Tackle Frontier AI Threats
Join the conversation
You need to be registered and logged in to comment on blog articles.
Related Articles
Attackers Exploit macOS Weaknesses, CI/CD Flaws, and Ransomware in Latest Wave of Cyber Incidents
Jun 24, 2026
LastPass, BeyondTrust, and Others Confirm Data Theft in Klue-Salesforce Supply Chain Attack
Jun 24, 2026
New tools emerge to govern AI-generated code and detect bot traffic as enterprise adoption accelerates
Jun 24, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.