OpenAI가 '데이브레이크(DayBreak)' 이벤트를 통해 소프트웨어 취약점 패치 자동화를 가속화하는 신규 보안 도구와 'GPT-5.5-Cyber'의 전체 버전을 공개했습니다. AI가 취약점 '발견'을 넘어 '수정 및 패치' 단계까지 기계적인 속도로 자동화함으로써, 보안 담당자들이 공격자보다 먼저 시스템을 방어할 수 있도록 돕는 것이 핵심입니다. 또한 주요 오픈소스 프로젝트들이 참여하는 'Patch the Planet' 이니셔티브 등 파트너십을 통해 전 세계 조직의 보안 수준을 전반적으로 높이고자 합니다.
번역된 본문
2026년 6월 22일
보안 회사 Daybreak: 전 세계 모든 조직을 보호하기 위한 도구
단순한 취약점 발견을 넘어 엔드투엔드(End-to-End) 패치 자동화의 가속화를 위해 새로운 도구, 파트너십 및 GPT-5.5-Cyber의 전체 버전을 출시합니다. 로딩 중... 공유 우리는 기계의 속도(Machine speed)로 취약한 소프트웨어 패치를 대중화(Democratize)하기 위해 Daybreak의 기능을 확장하고 있습니다. 예를 들어, 우리는 모델을 적용하여 주요 브라우저, 네트워크 인프라, FreeBSD 및 리눅스 커널(Linux kernel)과 같은 운영 체제의 치명적인 취약점을 발견하고 패치를 생성했습니다.
이러한 역량의 영향력을 확장하기 위한 주요 소식은 다음과 같습니다:
Codex Security: 기존 시스템의 취약점 발견 및 패치 속도를 높이고, 새로운 취약점이 프로덕션(Production) 환경에 유입되는 것을 자동으로 방지하는 솔루션에 내부 및 고객 모델 사용 경험을 반영하여 Codex Security 플러그인의 업데이트를 출시합니다.
GPT-5.5-Cyber: 초기 허용적(Permissive-only) 미리보기에 이어, 신뢰할 수 있는 방어자(Defender)들을 대상으로 한 지속적인 제한 릴리스를 통해 GPT-5.5-Cyber의 전체 버전을 출시합니다. 이 모델은 CyberGym에서 새로운 최고 수준(State-of-the-art)의 성능을 기록하며, GPT-5.5가 달성한 81.8%와 비교하여 85.6%에 도달했습니다.
Daybreak Cyber 파트너 프로그램: 보안 파트너들이 자사 제품 및 서비스에 대한 신뢰할 수 있는 액세스 권한을 통해 가장 강력한 모델의 혜택을 더 많은 조직으로 확장할 수 있도록 지원합니다.
Patch the Planet: HackerOne, Calif, 연구원 및 유지보수자와의 협업으로 Trail of Bits와 함께 설립한 이니셔티브로, 널리 사용되는 오픈소스 프로젝트가 취약점 발견에서 수정으로 넘어갈 수 있도록 돕습니다. cURL, Go, Python, Sigstore, pyca/cryptography를 포함한 30개 이상의 오픈소스 프로젝트가 참여를 약속했습니다. Patch the Planet을 통해 우리는 적절한 액세스, 거버넌스(Governance) 및 인간의 감독 하에 강력한 사이버 역량을 방어자들에게 제공하기 위해 연구원, 유지보수자, 기업 및 파트너와 협력하고 있습니다. 이에 대해 Clint와 Dan의 이야기를 여기(새 창에서 열림)에서 들어보세요.
전환점에 선 사이버 방어
AI는 사이버 보안의 물리적 법칙(Physics)을 바꾸어 놓았습니다. 최첨단(Frontier) AI 모델은 취약점 발견을 지속적으로 가속화하고 있습니다. 역사적으로 병목 현상은 취약점을 찾는 것이었지만, 이제는 방어자들이 너무 많은 취약점에 압도되어 오히려 취약점을 '수정(Patching)'하는 것이 새로운 병목 현상이 되었습니다.
수년간 심각한 취약점을 찾기 위해서는 희귀한 전문성, 시간, 복잡한 시스템에 대한 깊은 이해가 필요했습니다. 이제 모델이 대규모 코드베이스(Codebase)를 탐색하고, 공격 경로(Attack path)를 추론하며, 가설을 검증하고, 그렇지 않으면 숨겨져 있을 보안 문제를 표면화할 수 있습니다. 방어자들은 이러한 기능에 대한 액세스가 절대적으로 필요하며, 동시에 공격자가 악용하기 전에 우리가 발견한 취약점을 수정할 수 있는 도구가 필요합니다.
취약점 보고서 그 자체는 누구도 보호하지 않습니다. 진정한 가치는 문제를 검증하고, 영향도를 파악하고, 패치를 개발 및 테스트하고, 공개를 조정하고, 팀이 수정본을 배포하도록 돕는 데서 나옵니다. 우리는 방어자들을 전폭적으로 지원하고 모델의 역량을 실제 위험 감소로 전환하기 위해 파트너들과 함께 이후의 작업 과정들을 개선하는 데 투자하고 있습니다.
최첨단 방어 역량은 소수의 손에 집중되어서는 안 됩니다. 소프트웨어는 핵심 인프라부터 비즈니스 애플리케이션, 정부 네트워크에 이르기까지 삶의 모든 측면에 영향을 미칩니다. AI가 취약점 발견의 속도를 변화시킴에 따라, 전 세계의 방어자들은 공격자가 결함을 식별하고 악용하기 전에 인프라를 찾고, 수정하고, 보호하기 위해 이러한 모델에 대한 대중적인 접근성이 필요합니다.
Daybreak는 OpenAI 모델의 최첨단 사이버 역량, 사이버를 위한 신뢰할 수 있는 액세스(Trusted Access for Cyber), Codex Security 워크플로우, 그리고 생태계 파트너를 한자리에 모아 승인된 방어자가 기존 보안 및 개발 워크플로우 내에서 취약점을 검증하고, 위험의 우선순위를 정하고, 수정 사항을 생성 및 테스트하고, 증거를 확보할 수 있도록 돕습니다. 우리의 목표는 조직이 안전을 유지하는 데 필요한 도구를 제공하는 것입니다.
June 22, 2026 Security Company Daybreak: Tools for securing every organization in the world New tools, partnerships, and the full version of GPT‑5.5‑Cyber to move past vulnerability discovery and onto the acceleration of end-to-end patch automation. Loading… Share We’re expanding Daybreak to help democratize patching vulnerable software at machine speed. For example, we’ve applied our models to discover and generate patches for critical vulnerabilities in major browsers, network infrastructure, and operating systems such as FreeBSD and the Linux kernel. To scale the impact of these capabilities: Codex Security: We’re launching an update to the Codex Security plugin , which implements what we’ve learned from internal and customer usage of our models into a solution to accelerate the process of discovering and patching vulnerabilities in existing systems as well as automatically preventing new vulnerabilities from ever reaching production. GPT‑5.5‑Cyber: Following an initial permissive-only preview, we’re launching the full version of GPT‑5.5‑Cyber through our continued limited release to trusted defenders. This model sets new state-of-the-art performance on CyberGym, reaching 85.6% compared with 81.8% for GPT‑5.5. Daybreak Cyber Partner Program : Enabling security partners to scale the benefits to more organizations through our most capable models with trusted access in their products and services. Patch the Planet : an initiative founded with Trail of Bits in collaboration with HackerOne, Calif, researchers, and maintainers to help widely used open-source projects move from findings to fixes. More than 30 open-source projects have committed to participate, with initial participants including cURL, Go, Python, Sigstore, and pyca/cryptography. With Patch the Planet, we are working with researchers, maintainers, enterprises, and partners to make powerful cyber capability available to defenders with appropriate access, governance, and human oversight. Hear from Clint and Dan about this here (opens in a new window) . Cyber defense at an inflection point AI has changed the physics of cybersecurity. Frontier AI models have been increasingly accelerating vulnerability discovery. The bottleneck historically has been finding vulnerabilities, but now defenders are overwhelmed with the number of vulnerabilities found. Instead, the bottleneck is now patching vulnerabilities. For years, finding serious vulnerabilities required rare expertise, time, and deep familiarity with complex systems. Now, models can navigate large codebases, reason through attack paths, validate hypotheses, and surface security issues that might otherwise stay hidden. Defenders absolutely need access to these capabilities, and also need tools to fix what we can now find, before attackers do. Vulnerability reports, on their own, do not protect anyone. The value comes from validating the issue, understanding its impact, developing and testing a patch, coordinating disclosure, and helping teams deploy the fix. We are investing alongside our partners to improve these latter steps, in order to turbocharge defenders and convert model capability into real-world risk reduction. Frontier defensive capabilities should not be concentrated in the hands of a few. Software touches all aspects of life, from critical infrastructure to business applications and government networks. As AI changes the pace of vulnerability discovery, defenders everywhere need democratized access to these models to find, fix, and protect their infrastructure before attackers can identify and abuse these flaws. Daybreak brings together the frontier cyber capabilities OpenAI’s models, Trusted Access for Cyber, Codex Security workflows, and ecosystem partners to help approved defenders validate vulnerabilities, prioritize risk, generate and test fixes, and produce evidence inside existing security and development workflows. Our goal is to provide organizations the tools they need to stay secure even as the cyberthreat landscape continues to accelerate. From findings to fixes with Codex Security Since launching Codex Security cloud in research preview in March, it has scanned over 30 million commits across more than 30,000 codebases; human reviewers have manually marked more than 70,000 findings as fixed, and over 500,000 findings have automatically been determined to be fixed. This is the scale at which patching must now happen. We built Codex Security around a simple premise: put the equivalent of a security engineer next to every software developer by integrating directly into Codex. Rather than just generating alerts, Codex Security will understand your team’s code and its threat model (or generate one if it doesn’t exist), identify plausible vulnerabilities, determine whether affected code is reachable, gather evidence to provide validation steps, develop a targeted patch, and verify the result. Humans remain in control of which findings to investigate, which changes to apply, and what information to share. Today, we’re releasing an update to the Codex Security plugin that enables out-of-the-box defensive security workflows. Developers can run deep scans or review recent changes, generate reports with severity, affected code locations, validation evidence, and remediation guidance, trace attack paths, build threat models, validate findings, and generate codebase-specific patches for review. Set up a scan to cover an entire codebase, a subset of the codebase, or a specific change or commit. The plugin can also triage and validate existing findings from scanners, advisories, bug-bounty reports, or ticketing systems, then automate patch generation at scale to quickly close a backlog of vulnerabilities. When Codex Security completes a scan, it can also export to an existing vulnerability management system or integrate into tools with SARIF files, CodeQL queries, and more. The plugin makes these capabilities much more accessible to support automated pipelines with Codex CLI or integrate into developer workflows in the Codex app. Updating GPT‑5.5‑Cyber: pairing capability with permissiveness We are releasing an update to GPT‑5.5‑Cyber, our model that is both more permissive and more capable for advanced, authorized cybersecurity work. Our initial preview of GPT‑5.5‑Cyber was designed primarily to reduce unnecessary refusals in specialized workflows. This update goes further. It is our strongest model yet for finding and helping patch software vulnerabilities, while retaining GPT‑5.5’s general-purpose intelligence and ability to work across long, complex tasks. The model can sustain deeper analysis across large codebases: identifying security-relevant components, tracing whether vulnerable code is reachable, validating likely issues in controlled environments, developing and testing patches, and preparing evidence for human review. The goal is to help defenders move through the full remediation loop—not simply produce more findings. On CyberGym, which measures whether an agent can reproduce known vulnerabilities in software environments, the updated GPT‑5.5‑Cyber reached 85.6% in single-model evaluations, compared with 81.8% for GPT‑5.5. This is the highest CyberGym score we have measured from a single model. GPT‑5.5‑Cyber also outperformed GPT‑5.5 on two demanding real-world security benchmarks: 39.5% versus 25.95% on ExploitGym, which tests whether agents can turn known vulnerabilities into working exploits that achieve unauthorized code execution. On SEC-bench Pro, which evaluates long-horizon vulnerability discovery and proof-of-concept generation across complex software targets, GPT‑5.5‑Cyber reached 69.8%, compared with 63.1% for GPT‑5.5. Benchmarks are only one part of the story. What matters in practice is whether a model can find real vulnerabilities, distinguish actionable issues from noise, and help defenders land fixes safely. We are continuing to evaluate the model’s performance on complex repositories