
AWS and OpenAI have made Daybreak Red and Daybreak Blue—specialized AI models for cybersecurity—available on Amazon Bedrock, AWS's managed AI service.
The models help security teams discover vulnerabilities, analyze code, and develop fixes while keeping sensitive data encrypted and isolated within AWS infrastructure.
This matters because defenders face shrinking windows to patch vulnerabilities before attackers exploit them, and the new models can reason across entire codebases and propose solutions in minutes—under the same security controls and governance that customers already rely on for other AWS workloads.
What happened
OpenAI's Daybreak Red (GPT-5.6 Cyber) and Daybreak Blue (GPT-5.6 Sol) are now available to eligible customers on Amazon Bedrock in US East (N. Virginia). Both models are purpose-built for cybersecurity work—Daybreak Red for advanced tasks like vulnerability research and exploit reproduction, Daybreak Blue for vulnerability discovery and incident response.
Why it matters
Security teams can now analyze source code, identify vulnerabilities, and conduct red-team research while keeping sensitive code and vulnerability data encrypted and isolated within AWS infrastructure they control. The models can reason across entire codebases and propose fixes in minutes, helping defenders close the shrinking window between vulnerability disclosure and exploitation. According to OpenAI, security researchers using GPT-5.6 Cyber identified two previously unknown vulnerabilities in V8 (Chrome's JavaScript engine) that, when chained, could enable memory corruption and a heap sandbox escape—one of only four successful zero-day entries to V8 CTF in 2026.
What to watch
Access requires enrollment in Trusted Access for Cyber from OpenAI; eligible customers must contact OpenAI or their AWS account team for approval. Zero-operator access is enforced at the chip level, inference data is encrypted in transit and at rest using customer-managed AWS KMS keys, and data is not used for model training unless customers opt in. Customers may request zero data retention through their AWS account team.
AWS and OpenAI announced that Daybreak Red and Daybreak Blue—specialized AI models for cybersecurity—are now available on Amazon Bedrock, AWS's managed service for running AI workloads. Daybreak Red provides access to GPT-5.6 Cyber, a model purpose-trained for cybersecurity. Daybreak Blue provides access to GPT-5.6 Sol, trained with safeguards calibrated for defensive cybersecurity work. Both are part of OpenAI's Daybreak initiative, which gives defenders governed access to frontier AI, including agentic tooling, application red teaming, and services that help move from findings to tested fixes.
The availability addresses a critical challenge: the window between when a vulnerability is disclosed and when it is exploited keeps shrinking. Frontier models can now reason across entire codebases, trace a vulnerability to its root cause, and propose a fix in minutes. However, cybersecurity is inherently dual-use—a request to reproduce a vulnerability or reverse-engineer an exploit chain looks identical regardless of intent. General-purpose models resolve that ambiguity by declining the request. Daybreak Red and Daybreak Blue resolve it through context: who is using the model, where the work occurs, and what safeguards govern access. Daybreak Blue is the right starting point for most security teams, supporting vulnerability discovery, detection engineering, and incident response. Daybreak Red is designed for advanced tasks like vulnerability research, exploit reproduction, and mitigation development, with a lower refusal threshold matched by stronger identity verification, monitoring, and access controls.
The models run on Amazon Bedrock's next-generation inference engine. Zero-operator access is enforced at the chip, so even AWS operators cannot access prompts and completions during inference. Everything is encrypted in transit and at rest with customer-managed AWS KMS keys. Access is governed by AWS Identity and Access Management policies, logged in AWS CloudTrail, and routed through VPC endpoints. Customers can set data perimeter policies at the organization level to prevent exfiltration. Inference data is not used for model training, and neither model requires opt-in to share data with OpenAI; classifier-flagged traffic for automated abuse detection is retained by AWS for up to 30 days and processed programmatically, though customers may request zero data retention through their AWS account team.
According to OpenAI, security researchers used GPT-5.6 Cyber through Daybreak Red to identify two previously unknown vulnerabilities in V8, the JavaScript engine used by Chrome. When chained together, they could enable memory corruption and a heap sandbox escape. The initial vulnerability was fixed and released as CVE-2026-15903, one of only four successful zero-day entries to V8 CTF in 2026. Both models are now available to eligible customers on Amazon Bedrock in US East (N. Virginia). Access requires enrollment in Trusted Access for Cyber from OpenAI; eligible customers must contact OpenAI or their AWS account team for approval. AWS Security Vice President John Sheehan noted that AWS security teams are already using both models to analyze source code, discover vulnerabilities, and conduct red-team research under the same infrastructure controls applied to other critical workloads.
The cybersecurity landscape has shifted in recent years. Frontier AI models can now reason across entire codebases, trace vulnerabilities to their root cause, and propose fixes within minutes—capabilities that belong in defenders' hands but also in adversaries'. The body emphasizes that the window between vulnerability disclosure and exploitation is shrinking, placing immense pressure on security teams to validate findings and ship patches quickly across sprawling, unfamiliar code bases. The challenge is no longer surfacing potential issues but confirming which findings are real and acting before the window closes.
AWS and OpenAI are addressing this by bringing Daybreak Red and Daybreak Blue to Amazon Bedrock, where they operate under the same infrastructure, controls, and governance customers already trust for other AWS workloads. The dual-use nature of cybersecurity work—where the same request to reproduce a vulnerability or reverse-engineer an exploit chain could come from either defender or attacker—demands context-aware safeguards. Daybreak Blue starts with a higher refusal threshold and is designed for broader defensive tasks; Daybreak Red lowers that threshold for advanced researchers but enforces stronger identity verification, monitoring, and access controls. The body demonstrates this approach works: researchers using GPT-5.6 Cyber identified two previously unknown V8 vulnerabilities that became one of only four successful zero-day entries to V8 CTF in 2026.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Silicon Motion announced a private placement of US$1 billion in aggregate principal amount of 0% convertible s…

Sundar Pichai, CEO of Alphabet and Google, announced on August 11 that the Gemini app's monthly active users (…

A new platform called frontier.fast has launched an open competition where anyone can submit code patches to m…

Anthropic announced it has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generat…

An AI system generated a research draft that strengthened a mathematical bound related to the Riemann hypothes…

Researchers published findings showing AMIE (Video), a Gemini-based AI system, performed at or above the level…

The AI news that matters, in one minute each morning.
Sign up free