OpenAI Releases GPT-5.5-Cyber and "Patch the Planet": Opening AI Offense-Defense Capability to Security Firms

2 views

On June 22, under its Daybreak security program, OpenAI released three things at once: the full version of GPT-5.5-Cyber, open only to vetted security institutions; a Codex Security plugin embedded in the dev workflow; and Patch the Planet, dedicated to finding and fixing bugs in open source projects.

Three Things at Once

On June 22, under its own Daybreak security program, OpenAI released three things at once: the full version of GPT-5.5-Cyber, a defense-focused model open only to vetted security institutions; a plugin called Codex Security that embeds vulnerability scanning into the dev workflow; and "Patch the Planet," dedicated to finding and fixing bugs in commonly used open source projects. OpenAI specifically noted that issues the model finds must first be reviewed by humans before being disclosed externally.

Take the Benchmarks With a Grain of Salt

This model can do deeper analysis in large codebases—locating sensitive components, verifying suspected vulnerabilities—and can also write patches and run tests. OpenAI says it scored 85.6% on CyberGym, higher than standard GPT-5.5's 81.8%, claiming "highest for a single model." But CyberGym is OpenAI's own internal evaluation and hasn't been on a third-party leaderboard, so take that number with a grain of salt. There's also an accompanying partner program under which about 30 security firms can integrate this capability into their own products.

The Real Story

What's interesting isn't that the model is stronger, but how it's released—limited to vetted institutions, with human re-review required. For the same offense-defense capability, who gets it and how it's gated matter far more than a few points of benchmark lead.

via: OpenAI Official Announcement