OpenAI Launches GPT-5.5-Cyber, Patches Hundreds of Open-Source Vulnerabilities in Five Days
OpenAI's new cybersecurity-focused AI model partnered with security researchers to autonomously find and fix critical flaws in foundational software like Linux and Python. The "Patch the Planet" initiative marks a major shift toward using frontier AI for automated, large-scale digital defense.
By Mateo Ramos
- Defensive Security Innovators
- Believe AI is the only way to scale digital defense to match the speed of modern threats.
- National Security Hawks
- Focus on the geopolitical risks of AI and the need to tightly control frontier models.
- Enterprise Implementers
- View AI agents as practical tools to automate business operations and reduce friction.
Perspectives this story doesn't cover
- Independent Security Researchers who rely on bug bounties for income and may face competition from automated AI.
- Malicious Actors and Advanced Persistent Threats (APTs) who are simultaneously developing offensive AI capabilities.
Key terms
- Fuzzing
- An automated software testing technique that involves inputting massive amounts of random or invalid data into a system to find coding errors and security loopholes.
- Zero-day vulnerability
- A software flaw that is unknown to the vendor or developers, meaning they have "zero days" to fix it before it can be exploited by hackers.
- Open-source software
- Code that is designed to be publicly accessible, allowing anyone to see, modify, and distribute it. It forms the foundational building blocks of most modern technology.
- Agentic AI
- Artificial intelligence systems that can autonomously plan, make decisions, and execute complex, multi-step workflows using various software tools, rather than just answering text prompts.
Key points
- OpenAI launched GPT-5.5-Cyber, a specialized model that scored a record 85.6% on the CyberGym benchmark.
- The 'Patch the Planet' initiative used the AI to find and fix hundreds of bugs in 30+ open-source projects in just five days.
- Critical infrastructure software, including Linux, Python, and cURL, received automated security patches.
- The model is not public; it is restricted to vetted cybersecurity firms and allied government agencies.
- The breakthrough provides a powerful defensive countermeasure against the rising threat of AI-assisted cyberattacks.
The cybersecurity community has spent the past year bracing for an onslaught of AI-powered attacks. But the most significant artificial intelligence development of June 2026 has flipped the script, demonstrating that frontier models can secure the internet's foundational infrastructure faster than humans ever could.
On June 22, OpenAI unveiled GPT-5.5-Cyber, a specialized model engineered specifically for defensive cybersecurity operations. Rather than simply announcing benchmark scores, the company immediately deployed the model into the wild through a massive initiative dubbed "Patch the Planet," partnering with security research firm Trail of Bits and the bug-bounty platform HackerOne.[1]
The results of the initiative's initial five-day sprint were unprecedented. GPT-5.5-Cyber successfully navigated massive codebases, traced complex attack paths, and automatically generated targeted patches for more than 30 critical open-source projects.
The patched software includes foundational pillars of the modern internet: the Linux operating system kernel, the Python programming language, the data-transfer tool cURL, and the cryptographic signing framework Sigstore. These are systems that underpin everything from global banking infrastructure to consumer smartphones.
"The practical demonstration of what GPT-5.5-Cyber can do in production is striking," noted industry analysts tracking the release. In one instance, engineers at Trail of Bits used the model to build an entire fuzzing lab—a complex automated testing environment covering dozens of entry points and variant builds—in less than a single day. Manually, that same task would have taken a team of human engineers several weeks.
The model's technical capabilities represent a significant leap over previous generations. GPT-5.5-Cyber achieved an 85.6% success rate on the rigorous CyberGym benchmark, the highest score ever recorded by a single model and a notable jump from the 81.8% achieved by the standard GPT-5.5 model.[1]
It also demonstrated advanced proficiency in specialized security tasks, scoring 69.8% on the SEC-bench Pro evaluation and 39.5% on ExploitGym, proving its ability to not just find theoretical bugs, but validate their exploitability and produce concrete remediation evidence in a single, automated workflow.[1]
The defensive breakthrough arrives at a critical moment for global digital security. Just days prior to the launch, the "Five Eyes" intelligence alliance—comprising agencies from the US, UK, Australia, Canada, and New Zealand—issued a stark warning that frontier AI models were months away from fundamentally transforming offensive cyber capabilities.[2]
The defensive breakthrough arrives at a critical moment for global digital security.
"In this environment, cyber resilience is integral to advancing business continuity, market confidence, and long-term value," the intelligence agencies warned, noting that AI would inevitably lower the barrier to entry for bad actors and increase the speed of attacks.[2]
Governments worldwide have been scrambling to address this dual-use nature of advanced AI. In the United States, the White House recently issued executive actions aimed at securing the nation against advanced cryptographic attacks and promoting AI innovation that enhances national security.
Similarly, the Council of Europe recently passed a resolution highlighting that while AI presents serious risks of exploitation by malevolent actors, it also offers major opportunities to innovate and protect democratic systems if governed appropriately.[3]
To prevent GPT-5.5-Cyber from falling into the wrong hands, OpenAI is not releasing it as a public API. Instead, the model is strictly gated through a "Trusted Access for Cyber" program.[1]
The initial roster of vetted organizations granted access reads like a who's who of global cybersecurity infrastructure, including Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, Oracle, Palo Alto Networks, and Zscaler.[1]
The rollout was highly coordinated with international governments. Pre-deployment testing was conducted alongside the Center for AI Standards and Innovation and the US Office of the National Cyber Director. Government partnerships for the model's defensive use already cover Australia, Canada, France, Germany, Japan, South Korea, the UK, and key European Union institutions.[1]
The broader AI industry is currently undergoing a massive shift from experimental chatbots to functional, autonomous agents that execute complex workflows. GPT-5.5-Cyber exemplifies this trend, moving beyond simply answering security questions to actively hunting down vulnerabilities and writing the code to fix them.
For the open-source community, which relies heavily on volunteer maintainers who are often overwhelmed by the sheer volume of code they must secure, the arrival of automated, highly capable AI assistants is a game-changer. By clearing out backlogs of vulnerabilities, AI is freeing up human developers to focus on architecture and innovation rather than endless patching.
Why this matters
For years, experts have warned that AI could supercharge cyberattacks by making it easier for hackers to find vulnerabilities. This breakthrough proves the opposite is also true: AI can be deployed defensively at scale to patch the internet's foundational code before bad actors can exploit it, making the digital world safer for everyone.
Sources
[1]Build Fast with AIDefensive Security InnovatorsAI News Today June 24 2026: 15 Biggest Stories
Read on Build Fast with AI →
[2]The GuardianNational Security HawksAI models that can take down governments and business months away, rare Five Eyes statement warns
Read on The Guardian →
[3]Council of EuropeEnterprise ImplementersAI brings both major opportunities and serious risks for democratic systems
Read on Council of Europe →
Comments
More in Artificial Intelligence
See all →AI Infrastructure
How FlashAttention Bypasses the GPU Memory Bottleneck to Enable Long-Context AI
5 sources
Open Source Standards
How the Open Source Initiative's 1.0 Definition Excludes the Most Downloaded Open-Weight AI Models
7 sources
Generative Adversarial Networks
How a Generator and a Discriminator Compete to Create Realistic AI Output
8 sources
Machine Learning
How Generative AI Maps the Joint Probability Distribution of Data
5 sources
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.




