Wednesday Jun 24

OpenAI Ships A Cyber-Defense Model

23JUN
BUGS PATCHEDFIND BUGSPATCH

OpenAI just entered the AI security race. Its new GPT-5.5-Cyber model, built with firm Trail of Bits, hunts and patches software bugs. The target is Anthropic's lead in the field.

Two giants now compete to defend code with AI. Anthropic moved first with Glasswing and Mythos. This is the reply.

The system scans codebases, flags weak spots, and proposes repairs. It scored 85.6% on a vulnerability test. The pitch is protection, not breaking in.

Timing is political. A June White House order created a clearinghouse to hunt and remediate flaws at scale. Both labs want that contract.

full brief & sources

Why this matters

  • Turns AI cyber defense into a two-lab race, not an Anthropic solo lead.
  • Vulnerability-finding at machine scale could reset enterprise security economics.
  • Ties directly to new US policy pushing AI-driven vulnerability remediation.

🔍 What happened

  • Launched June 23, 2026. GPT-5.5-Cyber scored 85.6% on CyberGym, a vulnerability benchmark.
  • 'Patch the Planet' was built with security firm Trail of Bits.
  • Positioned as a direct counter to Anthropic's Glasswing and Mythos.
  • Framed as finding and fixing bugs, not exploiting them.
  • Follows a June 2 White House order creating an AI cybersecurity clearinghouse.

💬 Smart takes

  • OpenAI: GPT-5.5-Cyber finds and helps patch real software vulnerabilities.
  • Trail of Bits: co-developed the tooling behind Patch the Planet.
  • Skeptic: a model that finds bugs to patch can find them to exploit. Benchmarks do not prove the defense edge holds.

🧭 Where this goes

  1. Likelyenterprises pilot AI vuln-scanning inside existing security stacks this year.
  2. LikelyAnthropic answers with fresh Glasswing numbers within weeks.
  3. PossibleAI vuln-finding becomes a standard line in security budgets.
  4. Wild Carda model-found exploit leaks before its patch and causes real damage.

🥄 The Spoon Take

Security is becoming a model benchmark, not just a service. Whoever finds bugs fastest sets the price of safety. The risk is obvious. The same skill that patches the planet can break it. This race is useful and dangerous at once, and both labs know it.

🤔 Pushback

Benchmark scores like 85.6% rarely survive contact with messy production code, and a tool this capable cuts both ways the moment it leaks.