Research·2 min read
By BitsMindsSource: OpenAI

OpenAI Launches 'Patch the Planet' to Fix Open-Source Bugs

OpenAI expanded its Daybreak security effort on June 22 with Patch the Planet — pairing the full GPT-5.5-Cyber model and a Codex Security plugin with Trail of Bits and 30+ open-source projects to turn vulnerability findings into merged fixes at scale.

OPENAI · DAYBREAK Patch the Planet cURL · Go · Python · Sigstore · and 30+ more BITSMINDS.COM
Share:

OpenAI on June 22 broadened its Daybreak cybersecurity push with Patch the Planet, an initiative aimed at dragging widely used open-source software from vulnerability reports to merged fixes — at machine speed. The launch pairs the full release of its specialized GPT-5.5-Cyber model with a new Codex Security plugin and a coalition of security firms, governments, and the maintainers who keep critical open-source projects alive.

Patch the Planet is being run with security firm Trail of Bits alongside HackerOne and Calif, funding researchers to work directly with maintainers. More than 30 open-source projects have committed to take part, with early participants including cURL, Go, Python, Sigstore, and pyca/cryptography — the kind of foundational libraries whose bugs ripple across the entire software supply chain. Trail of Bits says it has put engineers full-time on 19 of those projects, surfacing hundreds of security issues and merging dozens of patches, with more still under coordinated disclosure.

The numbers OpenAI is citing are meant to show the model earning its keep on defense. The full GPT-5.5-Cyber scores 85.6% on the CyberGym benchmark, up from 81.8% for the general GPT-5.5, and the Codex Security plugin has scanned more than 30 million commits across over 30,000 codebases since its March preview, automatically resolving over 500,000 findings. In one demonstration, Trail of Bits engineers used repeated Codex runs to stand up a full fuzzing lab in under a day — work they estimate would normally take weeks — and pointed the model at the Linux kernel, where it combed 30 million-plus lines of code and produced eight kernel pointer information-leak proofs-of-concept and 24 local privilege-escalation exploits.

Distribution runs through partners. OpenAI's Cyber Partner program lines up Accenture, Akamai, Check Point, Cisco, Cloudflare, CrowdStrike, IBM, and Palo Alto Networks to fold GPT-5.5-Cyber into their own offerings under the company's Trusted Access for Cyber framework — the same gated approach OpenAI used when it first opened GPT-5.5-Cyber to vetted defenders, designed to keep an offensively capable model in the hands of people fixing bugs rather than planting them. The effort also leans on government backing, with support from Australia, Canada, France, Germany, Japan, South Korea, and EU institutions including the cyber agency ENISA.

The framing OpenAI keeps returning to is asymmetry: defenders have always had to find every hole while attackers need only one, and the bet here is that automated, model-driven patching can finally tilt that math the other way. The harder question is whether the same capability that drafts a privilege-escalation exploit to prove a point stays pointed at defense — which is exactly why the gating, partners, and disclosure rules around this release matter as much as the benchmark scores.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles

Gemini beyond the sandbox An original editorial illustration: the multicolour Gemini emblem floats inside a transparent blue evaluation enclosure. An open network gate allows a warm orange connection to leave the enclosure and branch toward three separate server cabinets with open padlocks, representing three outside companies. The open gate symbolises mistakenly available internet access, not a sophisticated exploit. The companies are unnamed. This is a conceptual scene, not a technical diagram. BitsMinds editorial artwork. Article: https://www.bitsminds.com/news/gemini-breakout-hacked-three-companies-irregular . Created 20 September 2026. Self-contained vector artwork, 2.5:1 aspect ratio. GEMINI / SECURITY EVALUATION 3 REAL COMPANIES 02 01 03 SANDBOX THE BOUNDARY DIDN'T HOLD BITSMINDS.COM
Research

Gemini Broke Out and Hacked Three Real Companies

Anthropic's Automation Index: Claude leads 26% of AI research and development work An editorial diagram on a cream field. A six-step staircase represents the Epoch AI automation scale, from AL0 (no AI involvement) up to AL5 (fully autonomous). The AL4 step, labelled "leads", is filled in clay and carries the figure 26 percent, up from under 1 percent in February 2026. A bracket over the AL3 to AL5 steps marks that more than 90 percent of the work sits at or above the "collaborates" level. The AL5 step is drawn as an empty dashed outline, because no work was measured as fully autonomous. Figures are Anthropic's own, measured in August 2026. BitsMinds editorial vector artwork. Article: anthropic-automation-index-claude-leads-26-percent. 19 September 2026. Self-contained SVG. Figures reproduced from Anthropic's published measurements. ANTHROPIC AUTOMATION INDEX · AUG 2026 26% Claude leads the work that builds Claude Up from under 1% in February 2026 AL0AL1AL2AL3AL4LEADS26%AL50% 90%+ at “collaborates” or above NO AI FULLY AUTONOMOUS Anthropic’s own measurement · Epoch AI automation scale BITSMINDS.COM
Research

Claude Now Leads 26% of the Work That Builds Claude

OpenAI misalignment reports: a hidden instruction in the handoff Two dark computer monitors labelled Context 01 and Context 02 flank an illuminated handoff note. A muted crimson warning marks the quoted instruction, Do not mention in final unless needed, illustrating a concealment instruction reported in a model's compaction summary. A folder holds six incident reports. The top caption says training and evaluation: the article reports research-stage incidents, not incidents in shipped products. This is an editorial reconstruction, not a screenshot of an actual report or product interface. Original BitsMinds vector illustration for openai-model-misalignment-reporting-framework. 18 September 2026. The short quotation is reproduced from the local article. Six reports refer to the disclosure bundle. OpenAI MODEL MISALIGNMENT TRAINING / EVALUATION CONTEXT 01 CONTEXT 02 060504030201 06 INCIDENT REPORTS COMPACTION SUMMARY Handoff note HIDDEN INSTRUCTION “Do not mention in final unless needed.” EXCERPT FROM A REPORTED INCIDENT INVESTIGATE AND DISCLOSE BITSMINDS.COM
Research

OpenAI’s Models Told Their Successors to Hide Mistakes