ZeroHour
AI model

GPT-5.6-Cyber

0 mentions in 7 days · 1 in 30 days · 3 total · first seen · last

Timeline

OpenAI Announced $1B in Defensive Tools for Water Utilities

OpenAI pledges $1 billion in subsidized Daybreak cyber models and training for water utilities, grid operators, and other critical-infrastructure defenders.

OpenAI announced Daybreak for Frontline Defenders on September 3, 2026, committing $1 billion in product credits and subsidized access to its Daybreak cyber models, training, and technical support for under-resourced defenders. Priority access goes to water and wastewater utilities, electric grid operators, state and local governments, community banks, nonprofits, and open-source maintainers; around 2,000 organizations already use Daybreak, which includes Daybreak Blue and Daybreak Red tiers. The program includes an MS-ISAC pilot, the Daybreak Defense Network with 35+ partner products (including HackerOne), and publication of OpenAI's Defense Factory automated vulnerability discovery architecture; it launched the same day OpenAI shipped a model it internally classifies as Critical for cyber capability.

Security Affairs · 10d agoAI industry

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

A Security researchers disclosed three Zoom annotation flaws enabling zero-click client hijacking; Zoom shipped fixes in June and July with no exploitation reported.

Researchers at A Security found three flaws in Zoom's annotation feature: CVE-2026-53413 (CVSS 8.3, buffer over-write), CVE-2026-53414 (CVSS 6.5, buffer over-read), and CVE-2026-53415 (CVSS 8.3, use-after-free). A crafted drawing object sent over the wrong message channel can overwrite adjacent memory and hijack another attendee's client with no user interaction. Fixes shipped in Zoom Workplace 7.1.5/7.0.6, VDI Client 7.0.11/6.6.16, and Zoom Rooms/Meeting SDK 7.1.0+ during June and July. No exploitation has been reported and the flaws are absent from CISA's Known Exploited Vulnerabilities catalog.

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI released GPT-5.6-Cyber for vulnerability research and pentesting via Daybreak Red, completing 95% of advanced cyber task evaluations.

GPT-5.6-Cyber, built on GPT-5.6 Sol, targets zero-day discovery, exploit chain development and incident response with reduced refusals, scoring 95.0% on OpenAI's Advanced Cybersecurity Completion Rate versus 1.5% for GPT-5.6 Sol and 57.3% for GPT-5.5-Cyber. The model found CVE-2026-15903 (CVSS 8.8), an out-of-bounds read/write in Chrome's V8 JavaScript engine that Google patched in mid-July 2026. It is available to trusted partners including CrowdStrike, Palo Alto Networks and Cloudflare through the Daybreak Red access tier.

The Hacker News · Aug 11, 2026Model releaseCVE-2026-15903

Related CVEs

  • Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H
    Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
    · google chrome
  • Out-of-Bounds Write in Zoom Clients Enables Participant-to-Participant RCE
    Zoom has fixed an out-of-bounds write (CWE-787) in the annotator function of its client applications, tracked as CVE-2026-53413. A meeting participant can trigger the missing bounds check remotely through the annotation feature, causing a buffer over-write in another attendee's client; per the CVSS vector, user interaction and high attack complexity are required. Successful exploitation may allow the attacker to execute code on the victim's machine with that user's privileges, effectively hijacking another participant's client from within the same meeting. Anyone running a vulnerable Zoom Client (the platform's desktop and mobile apps, used by an extremely large user base) is potentially affected until patched. There is no public proof-of-concept, the flaw is not yet in CISA's KEV catalog, and no exploitation in the wild is known, though an EPSS of 5.6% (92nd percentile) indicates meaningful exploitation potential.
    · Zoom Clients (client applications)mass
  • Use-After-Free in Zoom Client Annotator Enables Participant-to-Participant RCE
    CVE-2026-53415 is a use-after-free vulnerability (CWE-416) in the annotator function of Zoom Clients, scored 8.3 (High) with a network attack vector and changed scope. It is triggered when one meeting participant sends crafted annotation input that another participant's Zoom client processes, allowing an attacker in the meeting to corrupt memory in a fellow attendee's client; the CVSS vector marks user interaction as required and attack complexity as high, while press coverage describes the flaw as zero-click for the victim. A successful attack yields remote code execution on the other participant's client, with high impact to confidentiality, integrity, and availability. Anyone using Zoom Clients who joins meetings with untrusted participants where annotation is available is potentially affected. Exploitation status: not in CISA KEV, no public PoC, EPSS estimates only a 0.5% probability of exploitation in the next 30 days (44th percentile), and Zoom has already patched the flaw.
    · Zoom Clients (annotator function)mass
  • Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on
    Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.