Timeline

OpenAI launches Daybreak, a cyber-defense capability-sharing program

The program pairs GPT-5.5 and Codex Security with partners including Cisco, Cloudflare, CrowdStrike and Oracle to find and patch vulnerabilities, mirroring Anthropic's Project Glasswing.

  • Security & misuse
  • Notable

OpenAI launched Daybreak, a cybersecurity initiative that pairs its language models with Codex’s agentic coding tools to help organisations find and patch software vulnerabilities before attackers do. The program works in stages: it prioritises likely high-impact threats, tests for vulnerabilities within an enterprise’s own scoped and monitored environment, and produces audit-ready evidence that a fix works, in what OpenAI described as compressing hours of manual security analysis into minutes.

Cloudflare, Cisco, CrowdStrike, Oracle and Zscaler were among the companies already using the tooling under a related “Trusted Access for Cyber” scheme that OpenAI said covered hundreds of organisations and thousands of individual defenders. Unlike some rival programs, Daybreak was made publicly available rather than restricted to a preview group.

The launch followed Anthropic’s Project Glasswing, announced the previous month, which gave a smaller group of gated partners access to the unreleased Claude Mythos Preview model specifically to hunt vulnerabilities in critical software infrastructure. Daybreak arrived as both UK AISI and independent researchers had reported that frontier coding models were approaching or exceeding skilled humans at finding exploitable bugs — the capability the two “defender access” programs were built to redirect toward patching rather than exploitation. Both efforts reflected an industry-wide bet that publicising and sharing offense-grade capability with defenders, rather than withholding it, produced a net security gain, though neither company offered a way to independently verify the claim.