HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

OpenAI's GPT‑5.6‑Cyber Model Accepts 95% of Exploit‑Development Requests, Raising Zero‑Day Abuse Risk

OpenAI’s GPT‑5.6‑Cyber model now complies with 95 % of exploit‑development prompts, a stark contrast to the guarded GPT‑5.6 baseline. This capability accelerates zero‑day discovery and forces SOC 2 programs to extend access‑control and awareness controls to AI tooling.

LiveThreat™ Intelligence · 📅 August 11, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
helpnetsecurity.com

GPT‑5.6‑Cyber Model Accepts 95% of Exploit‑Development Requests, Raising Zero‑Day Abuse Risk

What Happened — OpenAI’s newly released GPT‑5.6‑Cyber model, offered through the Daybreak Red access program, was benchmarked to comply with 95 % of researcher requests that involve exploit chains, authentication bypass, and privilege‑escalation work. By contrast, the standard guard‑rail‑enabled GPT‑5.6 model refused 98.5 % of the same requests. The model has already been used internally to discover zero‑day flaws in Chrome’s V8 engine (CVE‑2026‑15903) and other high‑severity bugs in a mobile OS, a database, and a kernel.

Why It Matters for Compliance & Audit Readiness

  • The model’s permissive stance creates a new attack‑surface that can be leveraged by malicious actors to generate exploit code, a scenario SOC 2 controls are designed to anticipate and document.
  • Continuous‑compliance programs must now consider AI‑driven tooling in their access‑control policies, evidence‑collection processes, and security‑awareness training to demonstrate due diligence.
  • Verisq’s Security Awareness capability helps embed policy controls and training around high‑risk AI usage, providing audit‑ready evidence that your organization mitigates misuse of generative models.

Who Is Affected – Cloud‑based AI service providers, enterprises that integrate LLM APIs into security tooling, and any organization that permits developer access to generative AI for code or vulnerability research.

Recommended Actions

  • Update your SOC 2 CC6.1 – Logical Access Controls to require explicit justification and approval for any AI model that can generate exploit code.
  • Capture and retain evidence of request‑review workflows (e.g., request tickets, approval logs) as part of continuous control monitoring.
  • Incorporate targeted security‑awareness modules that cover the risks of permissive AI models and safe‑use guidelines.

Source: Help Net Security

Technical Notes – The model was evaluated on OpenAI’s internal “ExploitGym” benchmark, achieving 95 % success on exploit‑generation prompts. Zero‑day discoveries include two V8 engine bugs (CVE‑2026‑15903) and undisclosed high‑severity flaws in a mobile OS, a database, and a kernel.

📰 Original Source
https://www.helpnetsecurity.com/2026/08/11/openai-gpt-5-6-cyber-model/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →