OpenAI Unveils Security-Focused 'Codex Security' and Launches 'GPT-5.5 Cyber'

Photo Image
An AI-generated image depicting OpenAI's GPT-5.5 model.

OpenAI has unveiled Codex Security, a plugin equipped with dedicated cybersecurity capabilities. The company is also releasing GPT-5.5 Cyber, a cybersecurity-specialized AI model, to a select group of qualified experts.

The move is intended to strengthen OpenAI's cybersecurity initiative, Daybreak. Beyond simply identifying software vulnerabilities, the company aims to automate and accelerate the entire process--from validation and risk assessment to patch development, testing, and deployment.

The Codex Security plugin analyzes source code and threat models to identify vulnerabilities, verify whether they are exploitable in real-world attacks, develop patches, and support validation of the results.

Developers and security teams can review Codex Security's recommendations and decide whether further investigation or patch deployment is necessary. OpenAI expects the tool to significantly reduce the time required to move from vulnerability discovery to remediation.

OpenAI is also making the full version of GPT-5.5 Cyber available to a vetted group of defensive cybersecurity professionals. The model retains general intelligence and the ability to perform complex, long-horizon tasks while being specifically optimized for software vulnerability discovery and patch development.

GPT-5.5 Cyber is designed to analyze security-related components and attack paths across large codebases, validate vulnerabilities in controlled environments, and develop and test patches. In CyberGym, a benchmark that evaluates the ability to reproduce known vulnerabilities, the model achieved a score of 85.6%, outperforming the standard GPT-5.5 model's 81.8%.

OpenAI is also launching the Patch the Planet program to strengthen open-source software security. In collaboration with cybersecurity research firm Trail of Bits, professional researchers will use advanced AI models and Codex Security to validate and patch vulnerabilities in open-source projects. Vulnerability classification and coordinated disclosure efforts will be supported by HackerOne and Calypso.

The company is further expanding cooperation with governments and public-sector organizations worldwide. OpenAI has established the Trusted Access for Cyber partnership with the governments of the United States, the United Kingdom, South Korea, Japan, Canada, Australia, Germany, and France, as well as the European Union Agency for Cybersecurity.

“Rather than stopping at vulnerability detection, our goal is to use AI models to help build a safer software ecosystem and stronger cyber resilience,” OpenAI said. “Organizations across both the public and private sectors will be able to work with Daybreak to discover, validate, and remediate software vulnerabilities.”

· This article was translated using AI and was published after final review by the reporter.