Unit 42 Puts OpenAI Cyber Models to Work for Defenders
Unit 42 is putting OpenAI's frontier cyber models to work across customer environments as OpenAI expands its Daybreak program, supporting vulnerability discovery, validation, and remediation of attack paths. Help Net Security reports that Unit 42 is one of seven technology partners in Daybreak, where approved partners retain model access instead of transferring it directly to customers.
Unit 42 is putting OpenAI's frontier cyber models to work across customer environments to identify, validate, and help remediate attack paths, according to a Palo Alto Networks blog post. Unit 42 is Palo Alto Networks' threat intelligence and consulting organization.
Help Net Security reports that Unit 42 is among seven technology partners approved for OpenAI's Daybreak program, alongside CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare. The publication also names nine security and professional-services partners, including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps.
Partner-operated access
According to Help Net Security, OpenAI expanded Daybreak on August 10 and structured it around two access tiers: Daybreak Blue for a broad set of defensive security workflows, and Daybreak Red for more closely governed work such as red teaming and penetration testing. Access to the underlying models remains with approved partners rather than being transferred directly to their customers.
The arrangement enables partner-led work spanning vulnerability discovery, exploit validation, incident response, remediation, and security testing, Help Net Security reports. The same report describes engagement-specific safeguards including defined testing scopes, logging, monitoring, and human oversight, with partners and customers setting boundaries for each engagement.
That distinction separates provider-operated security assessments from self-service access to a high-capability cyber model. In comparable managed-security engagements, model access controls, scoped authorization, and validation by experienced operators are central safeguards because the same capabilities used to establish exploitability can be misused outside an approved test environment.
Daybreak model tiers
The Lec reports that OpenAI introduced GPT-5.6-Cyber for advanced vulnerability research, exploit validation, and security testing as part of the Daybreak expansion. According to the publication, Daybreak Blue is built on GPT-5.6 Sol, while Daybreak Red includes access to GPT-5.6-Cyber for organizations conducting advanced vulnerability research, exploit development, and red-team exercises.
The Lec reports that OpenAI evaluated GPT-5.6-Cyber on ExploitGym, a benchmark measuring whether a model can turn known software vulnerabilities into working exploit code. In OpenAI's reported evaluation, the model achieved the highest success rate among evaluated models and completed 95% of advanced cybersecurity tasks. Those figures are reported by OpenAI.
The Lec also reports that eligible Amazon Bedrock customers that complete Daybreak enrollment can use the models within AWS environments, subject to identity verification, account-security requirements, monitoring, approved-use restrictions, and compliance checks. For security engineering teams, the development puts frontier-model capability into a service-delivery channel where findings can be tied to authorized scope, remediation workflows, and existing customer infrastructure.
Key Points
- 1Unit 42 is using OpenAI cyber models in customer engagements, extending frontier-model access through managed security services rather than customer self-service.
- 2Daybreak separates broad defensive work from higher-governance red-team activity, reflecting the different operational risks associated with exploit validation and development.
- 3Vendor-reported ExploitGym results indicate stronger cyber capability, while practitioners should distinguish OpenAI's evaluation claims from independently reproduced benchmark results.
Scoring Rationale
The story concerns controlled access to a frontier cybersecurity model through major security providers, with direct relevance to vulnerability management, red teaming, and incident response teams. Its impact is material but bounded by enrollment, authorized-use controls, and partner-operated delivery rather than broad public model availability.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
