Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
ai-platform-securityai-enabled-threat-activityoffensive-tooling-releaseadversary-emulation-tradecraft

OpenAI Daybreak and Anthropic Glasswing debut amid rapid gains in AI cyber capability

Updated 2d agoFirst seen May 13, 20266 sources

OpenAI launched Daybreak, a cybersecurity initiative built around GPT-5.5, a tiered Trusted Access for Cyber framework, and Codex Security as its agent harness, positioning it alongside Anthropic’s earlier Project Glasswing. Both programs advertise similar defender-focused uses, including vulnerability discovery, exploit validation in authorized environments, patch validation, and detection engineering, while differing mainly in governance and access controls. Major security vendors including Cisco, CrowdStrike, and Palo Alto Networks joined both efforts, signaling that large defenders are pursuing model-agnostic strategies rather than committing to a single AI provider.

The launches come as the UK AI Security Institute reported that autonomous AI cyber capability is advancing quickly, with the 80%-reliability cyber task time horizon previously doubling every 4.7 months and new results from Claude Mythos Preview and GPT-5.5 exceeding that trend. A newer Claude Mythos Preview checkpoint became the first model to complete both AISI cyber ranges, including the previously unsolved Cooling Tower, while GPT-5.5 also posted strong results on The Last Ones; AISI said benchmark differences between the leading models are now narrow enough that practical differentiation is shifting toward agent harnesses, access restrictions, auditability, and partner ecosystems. The institute warned that current tests likely understate real-world capability and urged organizations to strengthen security baselines as both the defensive value and the cyber risk of frontier models increase.

Share:
OpenAI Daybreak and Anthropic Glasswing debut amid rapid gains in AI cyber capability
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
May 13, 20262mo ago

Daybreak and Glasswing disclosed overlapping security partners

Reporting on Daybreak noted that Cisco, CrowdStrike, and Palo Alto Networks were partners in both OpenAI's Daybreak and Anthropic's Glasswing programs. The overlap suggested major security vendors were pursuing model-agnostic strategies rather than aligning exclusively with one AI provider.

OpenAI launched the Daybreak cybersecurity initiative

OpenAI launched Daybreak as a cybersecurity program built around GPT-5.5, a tiered Trusted Access for Cyber framework, and Codex Security as its agent harness. The initiative positioned OpenAI alongside Anthropic's earlier Glasswing offering for defender-focused AI security workflows.

Palo Alto says frontier AI research produced 26 CVEs across 130+ products

Palo Alto Networks reported that recent frontier AI models were highly effective at finding vulnerabilities and chaining them into critical exploit paths. The company said this work led to 26 CVEs covering 75 issues across more than 130 products, adding independent evidence of rapidly advancing autonomous cyber capability.

Researchers say AI just broke every benchmark for autonomous cyber capability | CyberScoop

GPT-5.5 posted strong results on AISI's 'The Last Ones' benchmark

AISI reported that GPT-5.5 showed strong performance on The Last Ones and that new results for GPT-5.5 and Claude Mythos Preview substantially exceeded its prior trend estimate. The institute said it was still unclear whether this represented a temporary jump or a faster new rate of progress.

Claude Mythos Preview first completed both AISI cyber ranges

A newer Claude Mythos Preview checkpoint became the first model to complete both AISI cyber ranges, including the previously unsolved Cooling Tower challenge. AISI cited this as evidence that frontier autonomous cyber capability had advanced beyond its earlier trendline.

Feb 1, 20265mo ago

AISI published a February 2026 estimate of rapid cyber capability growth

In February 2026, AISI estimated that autonomous cyber capability was improving quickly, with the reliable cyber task time horizon doubling every 4.7 months. The estimate served as the prior benchmark before newer Claude Mythos Preview and GPT-5.5 results were evaluated.

Nov 1, 20242y ago

Autonomous AI cyber task horizon began doubling from late 2024

According to the UK AI Security Institute, frontier AI models' 80%-reliability cyber task time horizon had been doubling every 4.7 months since late 2024 under a 2.5 million token limit. This established the baseline trend used to assess later model advances.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Affected products
2 linked
FirefoxCursor
Organizations
18 linked
AnthropicOpenaiAkamai TechnologiesCisco SystemsNvidiaAmazon Web ServicesPalo Alto NetworksCloudflareCrowdStrikeAppleMicrosoft CorporationOracleJPMorgan ChaseGoogleMozillaReplitNational Cyber Security CentreCursor
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.