我们正在扩展 Daybreak,以帮助普及以机器速度修补易受攻击软件的能力。例如,我们已应用模型发现并生成了针对主流浏览器、网络基础设施以及 FreeBSD 和 Linux 内核等操作系统中的关键漏洞的补丁。为了扩大这些能力的影响范围:
- Codex Security: 我们正在发布 Codex Security 插件的更新,该插件将我们从内部和客户使用模型中学到的经验转化为解决方案,以加速发现和修补现有系统中的漏洞,并自动防止新漏洞进入生产环境。
- GPT‑5.5‑Cyber: 在仅限许可的初步预览之后,我们通过持续有限发布向受信任的防御者推出 GPT‑5.5‑Cyber 的完整版本。该模型在 CyberGym 上达到了新的最先进性能,达到 85.6%,而 GPT‑5.5 为 81.8%。
- Daybreak 网络安全合作伙伴计划:使安全合作伙伴能够通过我们最强大的模型,在其产品和服务中提供受信任的访问,从而将收益扩展到更多组织。
- Patch the Planet:这是一项与 Trail of Bits 合作,联合 HackerOne、Calif、研究人员和维护者共同发起的倡议,旨在帮助广泛使用的开源项目从发现漏洞转向修复漏洞。
- 已有超过 30 个开源项目承诺参与,初始参与者包括 cURL、Go、Python、Sigstore 和 pyca/cryptography。
- 通过 Patch the Planet,我们与研究人员、维护者、企业和合作伙伴合作,使防御者能够在适当的访问权限、治理和人工监督下获得强大的网络能力。点击此处(在新窗口中打开)聆听 Clint 和 Dan 的分享。
网络安全防御处于转折点
人工智能改变了网络安全的格局。前沿 AI 模型正日益加速漏洞发现。历史上,瓶颈在于 发现 漏洞,但现在防御者被发现的漏洞数量所淹没。相反,瓶颈现在变成了 修补 漏洞。
多年来,发现严重漏洞需要罕见的专业知识、时间以及对复杂系统的深入了解。现在,模型可以导航大型代码库、推理攻击路径、验证假设,并揭示可能隐藏的安全问题。防御者绝对需要这些能力,也需要工具来修复我们现在能发现的漏洞,抢在攻击者之前。
漏洞报告本身并不能保护任何人。价值在于验证问题、理解其影响、开发和测试补丁、协调披露,并帮助团队部署修复。我们正与合作伙伴一起投资改进这些后续步骤,以增强防御者能力,并将模型能力转化为实际的风险降低。
前沿防御能力不应集中在少数人手中。软件触及生活的方方面面,从关键基础设施到商业应用和政府网络。随着 AI 改变漏洞发现的节奏,各地的防御者都需要普及这些模型的访问权限,以便在攻击者识别和滥用这些缺陷之前,发现、修复并保护其基础设施。
Daybreak 整合了 OpenAI 模型的前沿网络能力、网络安全受信任访问、Codex Security 工作流以及生态系统合作伙伴,帮助经批准的防御者验证漏洞、优先处理风险、生成和测试修复,并在现有安全和开发工作流中生成证据。我们的目标是为组织提供保持安全所需的工具,即使网络威胁形势持续加速。
从发现到修复:Codex Security
自 3 月以研究预览形式推出 Codex Security 云以来,它已扫描了超过 30,000 个代码库中的 3000 万次提交;人工审查员已手动标记超过 70,000 个发现为已修复,超过 500,000 个发现已自动确定为已修复。
这就是修补现在必须达到的规模。

我们围绕一个简单的理念构建了 Codex Security:通过直接集成到 Codex 中,为每位软件开发人员配备一名安全工程师。Codex Security 不仅仅是生成警报,它会理解你团队的代码及其威胁模型(如果不存在则生成一个),识别可能的漏洞,确定受影响的代码是否可达,收集证据以提供验证步骤,开发有针对性的补丁,并验证结果。人类仍然控制着要调查哪些发现、应用哪些更改以及共享哪些信息。
今天,我们发布了 Codex Security 插件的更新,该更新支持开箱即用的防御性安全工作流。开发人员可以运行深度扫描或审查最近的更改,生成包含严重性、受影响的代码位置、验证证据和修复指导的报告,追踪攻击路径,构建威胁模型,验证发现,并生成针对特定代码库的补丁以供审查。

设置扫描以覆盖整个代码库、代码库的子集或特定的更改或提交。
该插件还能对扫描器、安全公告、漏洞赏金报告或工单系统中的现有发现进行分类和验证,然后自动大规模生成补丁,以快速清理积压的漏洞。当 Codex Security 完成扫描后,它还可以导出到现有的漏洞管理系统,或通过 SARIF 文件、CodeQL 查询等方式集成到工具中。该插件使这些功能更易于访问,以支持 Codex CLI 的自动化流水线,或集成到 Codex 应用程序中的开发者工作流中。
更新 GPT‑5.5‑Cyber:能力与许可性的结合
我们正在发布 GPT‑5.5‑Cyber 的更新版本,该模型在高级授权网络安全工作中既更宽松又更强大。
我们最初预览的 GPT‑5.5‑Cyber 主要旨在减少专业工作流中不必要的拒绝。此次更新更进一步。它成为我们目前最强的模型,用于发现和帮助修补软件漏洞,同时保留 GPT‑5.5 的通用智能以及处理长周期复杂任务的能力。
该模型能在大型代码库中进行更深入的分析:识别安全相关组件,追踪易受攻击代码是否可达,在受控环境中验证潜在问题,开发和测试补丁,并为人工审查准备证据。目标是帮助防御者完成完整的修复循环——而不仅仅是产生更多发现。
在 CyberGym(衡量代理是否能在软件环境中复现已知漏洞)上,更新后的 GPT‑5.5‑Cyber 在单模型评估中达到 85.6%,而 GPT‑5.5 为 81.8%。这是我们测量到的单模型最高 CyberGym 分数。
GPT‑5.5‑Cyber 在两个要求严苛的真实世界安全基准测试中也优于 GPT‑5.5:在 ExploitGym(测试代理能否将已知漏洞转化为实现未授权代码执行的有效利用)上,得分分别为 39.5% 和 25.95%。在 SEC-bench Pro(评估跨复杂软件目标的长期漏洞发现和概念验证生成)上,GPT‑5.5‑Cyber 达到 69.8%,而 GPT‑5.5 为 63.1%。
基准测试只是故事的一部分。实践中重要的是模型能否发现真实漏洞,将可操作问题与噪音区分开,并帮助防御者安全地落地修复。随着协调披露的完成,我们正在继续评估模型在复杂代码库和真实修复工作流上的表现。
我们与美国政府就我们的网络安全方法进行了持续对话,包括今天的公告以及我们为即将发布的模型所做的准备。这包括与人工智能标准与创新中心(CAISI)就 GPT‑5.5 和 5.5-Cyber 的部署前测试持续合作,并与国家网络总监办公室(ONCD)及科技政策办公室(OSTP)合作,落实最近的行政命令(在新窗口中打开)及相关行业标准。
对于大多数防御者而言,带有网络安全可信访问权限的 GPT‑5.5 和 Codex Security 仍然是正确的起点。GPT‑5.5‑Cyber 适用于经过验证的防御者,其授权工作需要我们最先进的网络安全能力和更宽松的行为,同时配合更强的验证、监控、范围控制和审查。在 Daybreak 的早期工作中,GPT‑5.5 和 Codex Security 已帮助防御者识别并验证了广泛使用系统中的漏洞,包括 Firefox、V8、Safari、OpenBSD、FreeBSD 和 HTTP/2 实现。
与安全生态系统合作
作为此次扩展的一部分,我们还与领先的安全软件和服务提供商共同推出了 OpenAI Daybreak 网络安全合作伙伴计划。通过该计划,参与合作伙伴可以在其提供给客户的安全产品和服务中使用带有网络安全可信访问权限的 GPT‑5.5——这是我们用于大多数防御性网络安全工作流的主要模型。这使他们的客户能够受益于该模型的防御能力,并使他们的软件更具弹性,但直接模型访问权限仍掌握在参与合作伙伴手中。

我们还将与计划合作伙伴合作,继续加强安全防护、监控和滥用预防标准,以便在整个安全生态系统中负责任地部署这些能力。我们正在与首批合作伙伴一起推出该计划,并计划在未来几个月内继续扩展到更多组织。
Patch the Planet:在开源中落地修复
Patch the Planet 是一项旨在帮助维护者从发现走向修复的倡议。该倡议与 Trail of Bits 共同创立,并与 HackerOne 和 Calif 合作,我们资助专家安全研究人员,并为他们配备 Codex Security 和我们的先进模型,以便直接与开源维护者合作。
开源软件为跨行业的产品、公共服务、开发者工具和关键基础设施提供动力。广泛使用的网络库中的漏洞可能影响数千个下游系统。然而,许多此类项目由非常小的团队维持,时间和资金有限。Linux 基金会和哈佛的研究(在新窗口中打开)发现,其研究的广泛使用的项目中,94% 的项目中负责一年内添加的代码超过 90% 的开发者不到十人。
随着人工智能使得更快地发现和修补更多漏洞成为可能,它也为维护者创造了更多工作,他们需要筛选数千份报告,其中许多是低质量的误报。维护者不应面临更多报告却没有额外能力来修复它们。这就是为什么 Patch the Planet 围绕专家人工安全审查而构建。
每次合作都始于我们的安全研究人员与所协助的维护者之间的协商。维护者定义其优先级、偏好及既定的披露流程。Patch the Planet 安全研究人员随后端到端管理整个工作——在漏洞和补丁到达维护者之前进行验证和去重,显著减轻维护者负担并加速修复进程。
参与项目将获得 ChatGPT Pro、Codex Security 有条件访问权限,以及用于核心开发、维护者自动化和发布工作流的 API 额度。
在跨多个项目的首个五天冲刺中,我们审查了数百个问题,合并了数十个补丁(更多补丁正在进行中),并构建了可复用的模糊测试、变体分析、差异测试和基于规范的测试工作流。您可在 Trail of Bits 博客此处(在新窗口中打开)阅读更多内容。
发现漏洞固然重要,但真正保护世界的是落实修复,而这需要协作和社区支持。
保护关键基础设施和敏感系统
我们还在与全球各国政府和机构紧密合作,提升其防御性网络安全能力并保护关键基础设施。我们一直与美国政府及相关联邦机构密切合作,为日益具备网络能力的 AI 模型做准备。过去一个月,我们已与澳大利亚、加拿大、法国、德国、日本、韩国以及欧盟机构(如 ENISA)建立了可信网络访问合作伙伴关系。我们与英国政府在网络安全、测试评估及其他共同感兴趣的领域也建立了不断深化的可信伙伴关系。
我们计划直接与符合条件的政府网络等关键基础设施运营商合作,为其运营的系统量身定制安全防护措施。这项工作的重点是让先进 AI 对防御者更有用,同时让恶意行为者更难造成现实世界伤害。
我们还将与企业客户和可信合作伙伴合作,纳入其运营或保护的特定系统的更广泛背景和标识符,强化我们的网络安全防护能力,以及预防涉及关键服务的有害网络活动的能力。
下一步计划
Daybreak 整合了模型、Codex Security、Patch the Planet、专家研究人员、维护者、安全合作伙伴、关键基础设施运营商和可信访问控制,帮助人类防御者迎接挑战。
公共和私营部门的组织可与 OpenAI Daybreak 合作,在其构建和依赖的软件中识别、验证和修复漏洞。开发者和维护者可在其拥有的代码上运行 Codex Security,审查结果并协助落实修复。安全合作伙伴和从业者可使用我们的前沿模型强化其防御工具,并快速将这些能力推广至更多组织。
目标是超越使用模型发现更多漏洞的层面,迈向更安全的软件和网络韧性的世界。
We’re expanding Daybreak to help democratize patching vulnerable software at machine speed. For example, we’ve applied our models to discover and generate patches for critical vulnerabilities in major browsers, network infrastructure, and operating systems such as FreeBSD and the Linux kernel. To scale the impact of these capabilities:
- **Codex Security:**We’re launching an update to the Codex Security plugin, which implements what we’ve learned from internal and customer usage of our models into a solution to accelerate the process of discovering and patching vulnerabilities in existing systems as well as automatically preventing new vulnerabilities from ever reaching production.
- **GPT‑5.5‑Cyber:**Following an initial permissive-only preview, we’re launching the full version of GPT‑5.5‑Cyber through our continued limited release to trusted defenders. This model sets new state-of-the-art performance on CyberGym, reaching 85.6% compared with 81.8% for GPT‑5.5.
- Daybreak Cyber Partner Program: Enabling security partners to scale the benefits to more organizations through our most capable models with trusted access in their products and services.
- Patch the Planet: an initiative founded with Trail of Bits in collaboration with HackerOne, Calif, researchers, and maintainers to help widely used open-source projects move from findings to fixes.
- More than 30 open-source projects have committed to participate, with initial participants including cURL, Go, Python, Sigstore, and pyca/cryptography.
- With Patch the Planet, we are working with researchers, maintainers, enterprises, and partners to make powerful cyber capability available to defenders with appropriate access, governance, and human oversight. Hear from Clint and Dan about this here(opens in a new window).
Cyber defense at an inflection point
AI has changed the physics of cybersecurity. Frontier AI models have been increasingly accelerating vulnerability discovery. The bottleneck historically has been finding vulnerabilities, but now defenders are overwhelmed with the number of vulnerabilities found. Instead, the bottleneck is now patching vulnerabilities.
For years, finding serious vulnerabilities required rare expertise, time, and deep familiarity with complex systems. Now, models can navigate large codebases, reason through attack paths, validate hypotheses, and surface security issues that might otherwise stay hidden. Defenders absolutely need access to these capabilities, and also need tools to fix what we can now find, before attackers do.
Vulnerability reports, on their own, do not protect anyone. The value comes from validating the issue, understanding its impact, developing and testing a patch, coordinating disclosure, and helping teams deploy the fix. We are investing alongside our partners to improve these latter steps, in order to turbocharge defenders and convert model capability into real-world risk reduction.
Frontier defensive capabilities should not be concentrated in the hands of a few. Software touches all aspects of life, from critical infrastructure to business applications and government networks. As AI changes the pace of vulnerability discovery, defenders everywhere need democratized access to these models to find, fix, and protect their infrastructure before attackers can identify and abuse these flaws.
Daybreak brings together the frontier cyber capabilities OpenAI’s models, Trusted Access for Cyber, Codex Security workflows, and ecosystem partners to help approved defenders validate vulnerabilities, prioritize risk, generate and test fixes, and produce evidence inside existing security and development workflows.Our goal is to provide organizations the tools they need to stay secure even as the cyberthreat landscape continues to accelerate.
From findings to fixes with Codex Security
Since launching Codex Security cloud in research preview in March, it has scanned over 30 million commits across more than 30,000 codebases; human reviewers have manually marked more than 70,000 findings as fixed, and over 500,000 findings have automatically been determined to be fixed.
This is the scale at which patching must now happen.

We built Codex Security around a simple premise: put the equivalent of a security engineer next to every software developer by integrating directly into Codex. Rather than just generating alerts, Codex Security will understand your team’s code and its threat model (or generate one if it doesn’t exist), identify plausible vulnerabilities, determine whether affected code is reachable, gather evidence to provide validation steps, develop a targeted patch, and verify the result. Humans remain in control of which findings to investigate, which changes to apply, and what information to share.
Today, we’re releasing an update to the Codex Security plugin that enables out-of-the-box defensive security workflows. Developers can run deep scans or review recent changes, generate reports with severity, affected code locations, validation evidence, and remediation guidance, trace attack paths, build threat models, validate findings, and generate codebase-specific patches for review.

Set up a scan to cover an entire codebase, a subset of the codebase, or a specific change or commit.
The plugin can also triage and validate existing findings from scanners, advisories, bug-bounty reports, or ticketing systems, then automate patch generation at scale to quickly close a backlog of vulnerabilities. When Codex Security completes a scan, it can also export to an existing vulnerability management system or integrate into tools with SARIF files, CodeQL queries, and more. The plugin makes these capabilities much more accessible to support automated pipelines with Codex CLI or integrate into developer workflows in the Codex app.
Updating GPT‑5.5‑Cyber: pairing capability with permissiveness
We are releasing an update to GPT‑5.5‑Cyber, our model that is both more permissive and more capable for advanced, authorized cybersecurity work.
Our initial preview of GPT‑5.5‑Cyber was designed primarily to reduce unnecessary refusals in specialized workflows. This update goes further. It is our strongest model yet for finding and helping patch software vulnerabilities, while retaining GPT‑5.5’s general-purpose intelligence and ability to work across long, complex tasks.
The model can sustain deeper analysis across large codebases: identifying security-relevant components, tracing whether vulnerable code is reachable, validating likely issues in controlled environments, developing and testing patches, and preparing evidence for human review. The goal is to help defenders move through the full remediation loop—not simply produce more findings.
On CyberGym, which measures whether an agent can reproduce known vulnerabilities in software environments, the updated GPT‑5.5‑Cyber reached 85.6% in single-model evaluations, compared with 81.8% for GPT‑5.5. This is the highest CyberGym score we have measured from a single model.
GPT‑5.5‑Cyber also outperformed GPT‑5.5 on two demanding real-world security benchmarks: 39.5% versus 25.95% on ExploitGym, which tests whether agents can turn known vulnerabilities into working exploits that achieve unauthorized code execution. On SEC-bench Pro, which evaluates long-horizon vulnerability discovery and proof-of-concept generation across complex software targets, GPT‑5.5‑Cyber reached 69.8%, compared with 63.1% for GPT‑5.5.
Benchmarks are only one part of the story. What matters in practice is whether a model can find real vulnerabilities, distinguish actionable issues from noise, and help defenders land fixes safely. We are continuing to evaluate the model’s performance on complex repositories and real remediation workflows as coordinated disclosures conclude.
We’ve had ongoing dialogue with the U.S. government about our cyber approach, including today’s announcements and on our preparation for upcoming model releases. That includes continued collaboration with the Center for AI Standards and Innovation (CAISI) on pre-deployment testing for GPT‑5.5 and 5.5-Cyber, and work with the Office of the National Cyber Director (ONCD) and Office of Science and Technology Policy (OSTP) on implementation of the recent Executive Order(opens in a new window) and associated industry standards.
For most defenders, GPT‑5.5 with Trusted Access for Cyber and Codex Security remains the right starting point. GPT‑5.5‑Cyber is intended for verified defenders whose authorized work requires our most advanced cyber capabilities and more permissive behavior, paired with stronger verification, monitoring, scoped controls, and review. Across early Daybreak work, GPT‑5.5 and Codex Security have helped defenders identify and validate vulnerabilities in widely used systems, including Firefox, V8, Safari, OpenBSD, FreeBSD, and HTTP/2 implementations.
Working with the security ecosystem
As part of this expansion, we’re also launching the OpenAI Daybreak Cyber Partner Program with leading security software and services providers. Through the program, participating partners can use GPT‑5.5 with Trusted Access for Cyber—our primary model for most defensive cybersecurity workflows—in the security products and services they provide to customers. This allows their customers to benefit from the model’s defensive capabilities and make their software more resilient, but keeps direct model access in the hands of participating partners.

We will also collaborate with program partners to continue to strengthen the safeguards, monitoring, and abuse-prevention standards needed to deploy these capabilities responsibly across the security ecosystem. We're rolling this out with an initial set of partners and plan to continue expanding to more organizations in the coming months.
Patch the Planet: landing fixes in open-source
Patch the Planet is an initiative built to help maintainers move from findings to fixes. Founded with Trail of Bits, and in collaboration with HackerOne and Calif, we are funding expert security researchers and equipping them with Codex Security and our advanced models to work directly with open source maintainers.
Open source software powers products, public services, developer tools, and critical infrastructure across sectors. A vulnerability in a widely used networking library can affect thousands of downstream systems. Yet many of these projects are sustained by very small teams with limited time and funding.Research from the Linux Foundation and Harvard(opens in a new window) found that 94 percent of the widely used projects it studied had fewer than ten developers responsible for more than 90 percent of the code added in a year.
As AI makes it possible to find and patch more vulnerabilities faster, it also creates more work for maintainers, who need to sift through thousands of reports, many of which are low-quality false positives. Maintainers should not be left with more reports and no additional capacity to fix them. That’s why Patch the Planet is built around expert human security review.
Each engagement begins with consultation between our security researchers and the maintainers they are helping. Maintainers define their priorities, preferences, and established disclosure processes. Patch the Planet security researchers then manage the work end to end–validating and deduplicating both vulnerabilities and patches before they reach maintainers, significantly reducing the burden on maintainers and speeding up remediation.
Participating projects receive ChatGPT Pro, conditional access to Codex Security, and API credits for core development, maintainer automation, and release workflows.
The initial five-day sprint across multiple projects surfaced hundreds of issues for review, merged dozens of patches with more underway, and built reusable fuzzing, variant-analysis, differential-testing, and specification-based testing workflows. You can read more on the Trail of Bits blog here(opens in a new window).
Finding vulnerabilities is important, but it’s landing the fix that protects the world, and that takes collaboration and community support.
Protecting critical infrastructure and sensitive systems
We are also collaborating closely with governments and institutions around the world to uplift their defensive cybersecurity capabilities and protect critical infrastructure. We have been working closely with the US Government and relevant federal agencies as we prepare for increasingly cyber-capable AI models. In the past month we have already established Trusted Access for Cyber partnerships with Australia, Canada, France, Germany, Japan, Republic of Korea, and EU institutions like ENISA. We also have a growing and trusted partnership with the UK government around cyber, testing and evaluation, and other areas of mutual interest.
We plan to work directly with eligible operators of critical infrastructure, including government networks, to develop safeguards tailored to the systems they operate. The focus of this work is to make advanced AI more useful to defenders, while making it harder for malicious actors to cause real-world harm.
We will also work with enterprise customers and trusted partners to incorporate broader context and identifiers about the specific systems they operate or protect, strengthening our cybersecurity safeguards and ability to prevent harmful cyber activity involving critical services.
What comes next
Daybreak brings together models, Codex Security, Patch the Planet, expert researchers, maintainers, security partners, critical infrastructure operators, and trusted access controls to help human defenders rise to the challenge. Organizations across the public and private sectors can work with OpenAI Daybreak to identify, validate, and remediate vulnerabilities across the software they build and rely on. Developers and maintainers can run
Codex Security on code they own, review the findings, and help land fixes. Security partners and practitioners can use our frontier models to strengthen their defensive tools and bring those capabilities to more organizations quickly.
The goal is to move beyond using models to find more vulnerabilities, towards a world of safer software and cyber resilience.
本文内容采集自官方网站,排版和翻译可能与原页面存在差异。
阅读官方全文