메뉴
BL
The Decoder 36일 전

오픈AI, GPT-5.5-Cyber 공개...보안 벤치마크 앤스로픽 제쳐

IMP
9/10
핵심 요약

오픈AI가 취약점 발견부터 패치 생성까지 전 과정을 자동화하는 보안 모델 'GPT-5.5-Cyber'와 'Codex Security' 업데이트를 전격 공개했습니다. 이 모델은 주요 사이버 보안 벤치마크에서 앤스로픽의 최신 모델을 뛰어넘는 성능을 기록했습니다. 오픈AI는 25개 이상의 글로벌 보안 기업 및 여러 정부와 협력하여 이 기술의 적용 범위를 확대하고 있습니다.

번역된 본문

오픈AI가 업데이트된 Codex Security 플러그인, 정식 버전의 GPT-5.5-Cyber 모델, 그리고 25개 이상의 보안 업체 및 여러 정부 기관이 참여하는 파트너 네트워크를 통해 'Daybreak(새벽)' 사이버 보안 이니셔티브를 확대합니다.

앤스로픽이 최근 비슷한 지적을 했고 오픈AI도 동의합니다. 사이버 보안의 진짜 병목 현상은 결함을 찾는 것에서 실제로 이를 패치하는 것으로 옮겨졌습니다. 이러한 격차를 해소하기 위해 오픈AI는 결함 발견부터 패치 생성에 이르는 전체 파이프라인을 다루는 업데이트된 Codex Security 플러그인과 보안 벤치마크에서 신기록을 세운 전문 모델인 GPT-5.5-Cyber의 정식 버전을 출시했습니다. 또한 오픈 소스 패칭 이니셔티브와 25개 이상의 보안 업체가 참여하는 파트너 프로그램을 시작했습니다.

Codex Security 업데이트, 발견부터 패치까지의 과정을 완성하다 Codex Security 플러그인은 3월에 연구용 프리뷰로 출시되었습니다. 오픈AI에 따르면, 이후 3만 개 이상의 코드베이스에서 3천만 건 이상의 커밋을 스캔했습니다. 50만 건 이상의 발견 사항이 자동으로 수정된 것으로 표시되었으며, 인간 리뷰어가 수동으로 추가로 7만 건을 확인했습니다. 오픈AI는 업데이트된 플러그인이 모든 개발자 옆에 앉아있는 보안 엔지니어처럼 작동하기를 원합니다. 이 플러그인은 위협 모델과 함께 코드를 분석하고, 결함을 찾아내고, 영향을 받는 코드에 실제로 접근할 수 있는지 확인하며, 목표에 맞는 패치를 구축하고 결과를 검증합니다.

이번 업데이트의 새로운 기능은 전체 코드베이스에 대한 심층 스캔, 공격 경로 분석, SARIF 파일이나 CodeQL 쿼리를 통한 기존 취약점 관리 시스템으로의 내보내기입니다. 또한 다른 스캐너나 버그 바운티 보고서의 결과를 분류하고 일괄 처리 모드에서 패치 생성을 자동화할 수 있습니다. 오픈AI는 모든 변경 사항은 여전히 인간이 최종 승인한다고 밝혔습니다.

GPT-5.5-Cyber, 인증된 수비수만 접근 가능 GPT-5.5-Cyber의 정식 버전은 보안 작업에서 불필요한 요청 거부를 줄이는 데 주안점을 두었던 이전 프리뷰를 대체합니다. 오픈AI는 이 업데이트된 모델을 소프트웨어 결함을 찾고 수정하는 데 있어 가장 성능이 뛰어난 단일 모델이라고 부릅니다. 오픈AI에 따르면 GPT-5.5-Cyber는 모든 주요 사이버 보안 벤치마크에서 1위를 차지했습니다. CyberGym은 에이전트가 소프트웨어 환경에서 알려진 결함을 재현할 수 있는지 측정합니다. ExploitGym은 에이전트가 취약점을 실제로 작동하는 익스플로잇으로 전환할 수 있는지 테스트합니다. SEC-bench Pro는 장기적인 취약점 발견 능력을 평가합니다.

모델 CyberGym ExploitGym SEC-bench Pro
GPT-5.5-Cyber 85.6% 39.5% 69.8%
Mythos 5 83.8%
GPT-5.5 81.8% 25.95% 63.1%
GPT-5.4 79.0%
Claude Opus 4 73.1%

오픈AI는 최신 버전의 GPT-5.5-Cyber가 표준 모델보다 의도적으로 더 관대하고 요청 거부가 적다고 설명합니다. 하지만 검증된 수비수(defender)만이 접근할 수 있으며, 오픈AI는 이러한 접근 권한을 신원 확인, 모니터링 및 안전장치와 연동합니다. 대부분의 사용자는 Cyber 및 Codex Security에 대한 Trusted Access와 결합된 GPT-5.5를 계속 사용해야 한다고 오픈AI는 덧붙였습니다.

25개 이상의 보안 업체와 여러 정부가 프로그램에 참여 Daybreak 사이버 파트너 프로그램을 통해 보안 업체들은 자사 제품에 'Cyber를 위한 Trusted Access'가 적용된 GPT-5.5를 통합할 수 있습니다. 파트너에는 시스코(Cisco), 크라우드스트라이크(CrowdStrike), 클라우드플레어(Cloudflare), 팔로알토네트웍스(Palo Alto Networks), IBM, 포티넷(Fortinet), Wiz, 센티넬원(SentinelOne), 다크트레이스(Darktrace), 팔란티어(Palantir), 액센추어(Accenture), PwC, KPMG 등이 포함됩니다.

오픈AI는 정부 관련 업무도 확장하고 있습니다. 이 회사는 자체적인 Trusted... (원문 끝)

원문 보기
원문 보기 (영어)
OpenAI says new GPT-5.5-Cyber outperforms Anthropic's Mythos on cybersecurity benchmark Matthias Bastian View the LinkedIn Profile of Matthias Bastian Jun 23, 2026 Nano Banana Pro prompted by THE DECODER Key Points OpenAI is expanding its Daybreak cybersecurity initiative with new tools, moving beyond simply identifying vulnerabilities to automatically resolving them. The Codex Security plugin has been updated to handle the entire workflow up to patch generation, and the GPT-5.5-Cyber cybersecurity model is now fully available after leaving its preview phase. As part of a dedicated partner program, OpenAI is collaborating with over 25 security companies and several governments to advance its cybersecurity capabilities. Ask about this article… Search OpenAI is expanding its Daybreak cybersecurity initiative with an updated Codex Security plugin, the full GPT-5.5-Cyber model, and a partner network of more than 25 security firms and several governments. Anthropic recently made a similar point , and OpenAI agrees. The real bottleneck in cybersecurity has moved from finding flaws to actually patching them. To close that gap, OpenAI is shipping an updated Codex Security plugin that covers the full pipeline from discovery to patch generation, along with the full release of GPT-5.5-Cyber, a specialized model that sets new highs on security benchmarks. OpenAI also launched an open-source patching initiative and a partner program with more than 25 security firms. Codex Security update closes the loop from discovery to patch The Codex Security plugin shipped as a research preview back in March . Since then, it's scanned over 30 million commits across more than 30,000 codebases, OpenAI says. Over 500,000 findings were automatically flagged as fixed, and human reviewers manually confirmed another 70,000. Ad OpenAI wants the updated plugin to act like a security engineer sitting next to every developer. It analyzes code alongside a threat model, spots flaws, checks whether affected code is actually reachable, builds a targeted patch, and verifies the result. Ad DEC_D_Incontent-1 New in this update are deep scans of entire codebases, attack path analysis, and export to existing vulnerability management systems through SARIF files or CodeQL queries. The plugin can also triage findings from other scanners or bug bounty reports and automate patch generation in batch mode. Humans still sign off on every change, OpenAI says. GPT-5.5-Cyber stays locked to vetted defenders The full version of GPT-5.5-Cyber replaces an earlier preview that mostly aimed to cut unnecessary refusals in security workflows. OpenAI calls the updated model the most capable single model for finding and patching software flaws. Ad GPT-5.5-Cyber leads on all key cybersecurity benchmarks, according to OpenAI. CyberGym measures whether an agent can reproduce known flaws in software environments. ExploitGym tests whether agents can turn vulnerabilities into working exploits. SEC-bench Pro evaluates long-term vulnerability discovery. Model CyberGym ExploitGym SEC-bench Pro GPT-5.5-Cyber 85.6% 39.5% 69.8% Mythos 5 83.8% – – GPT-5.5 81.8% 25.95% 63.1% GPT-5.4 79.0% – – Claude Opus 4 73.1% – – The latest version of GPT-5.5-Cyber is deliberately more permissive than standard models and refuses fewer requests, OpenAI says. But only verified defenders can access it, and OpenAI ties that access to verification, monitoring, and guardrails. Most users should stick with GPT-5.5 paired with Trusted Access for Cyber and Codex Security, OpenAI says. Ad DEC_D_Incontent-2 Over 25 security firms and several governments join the program Through the Daybreak Cyber Partner Program , security companies can plug GPT-5.5 with Trusted Access for Cyber into their own products. Partners include Cisco, CrowdStrike, Cloudflare, Palo Alto Networks, IBM, Fortinet, Wiz, SentinelOne, Darktrace, Palantir, Accenture, PwC, and KPMG. Ad OpenAI is also expanding its government work. The company says it has Trusted Access partnerships with Australia, Canada, France, Germany, Japan, South Korea, the EU agency ENISA, and the UK. In the US, OpenAI is working to carry out a recently issued executive order on AI security and plans to collaborate directly with critical infrastructure operators. OpenAI also launched Patch the Planet together with Trail of Bits, HackerOne, and Calif to bring the same patching tools to open-source software. More than 30 open-source projects have signed on, including cURL, Go, Python, Sigstore, and pyca/cryptography. Security researchers work with maintainers to validate and deduplicate flaws and patches before anything gets merged. A first five-day sprint turned up hundreds of issues and led to dozens of merged patches, OpenAI says. AI News Without the Hype – Curated by Humans Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section. Subscribe now Source: OpenAI
관련 소식