Tuesday Jun 23

OpenAI Launches Patch The Planet

23JUN
PATCH THE PLANET85.6%30 PROJECTS

OpenAI's AI finds bugs faster than humans can fix. So it built Patch the Planet: experts plus AI fixing open-source like Python, cURL, and Go. Anthropic's rival cyber model sits export-banned.

The bottleneck flipped. The models now surface flaws faster than security teams can ship repairs.

OpenAI teamed with Trail of Bits and HackerOne to fund researchers helping under-staffed projects. It cites a study: 94% of critical software leans on teams under ten people. A human checks every finding first.

Its defensive model, GPT-5.5-Cyber, is fully live and scored 85.6% on one benchmark. Launch partners include CrowdStrike, Cisco, IBM, and Wiz. The move presses a sidelined rival.

full brief & sources

Why this matters

  • First time a lab frames patching, not finding, as the security bottleneck.
  • Open source runs on tiny teams; 94% of key projects have under 10 maintainers.
  • OpenAI fills the gap left by Anthropic's export-banned cyber model.

🔍 What happened

  • OpenAI expanded its Daybreak program on June 22 with Patch the Planet.
  • Built with Trail of Bits; HackerOne collaborating. 30+ projects committed.
  • An early sprint surfaced hundreds of issues and merged dozens of patches.
  • It found a 23-year-old use-after-free flaw in OpenBSD's kernel.
  • GPT-5.5-Cyber is now fully live, scoring 85.6% on CyberGym, up from 81.8%.
  • Partner program: Accenture, Cisco, CrowdStrike, IBM, Okta, Palo Alto, Wiz.

💬 Smart takes

  • OpenAI: models now find flaws faster than defenders can fix, so patching is the new bottleneck.
  • Skeptic: flooding 10-person open-source teams with AI bug reports can grow the backlog, not shrink it.

🧭 Where this goes

  1. LikelyAnthropic and Google ship rival open-source patching programs within 90 days.
  2. Likely'AI-found, human-reviewed' becomes the standard disclosure workflow.
  3. Possiblea major CVE gets credited to an AI agent as lead finder this year.
  4. Wild Carda Patch the Planet fix ships a high-profile regression and dents trust.

🥄 The Spoon Take

The cyber race just moved from finding bugs to fixing them. OpenAI is funding the unglamorous part, patching, while Anthropic sits benched by an export ban. Whoever owns the patch pipeline owns the trust story with governments and the open-source world.

🤔 Pushback

Pouring AI bug reports onto skeleton-crew open-source teams could bury maintainers, and one bad auto-patch could undo the goodwill fast.