OpenAI and Microsoft unveil AI models that automatically generate security patches
OpenAI expanded its Daybreak initiative with a new model, GPT‑5.5‑Cyber, designed to detect software vulnerabilities and automatically create patches. The model, integrated with a Codex Security Plugin, scanned more than 30 million code commits across 30 000 projects, automatically fixing over 500 000 issues and confirming 70 000 with human researchers. In benchmark testing on CyberGym the model achieved an 85.6 % success rate, outperforming the standard GPT‑5.5 and rival models. OpenAI has partnered with Trail of Bits, HackerOne, Cisco, CrowdStrike, Palo Alto Networks, IBM and governments in Germany, Japan and the United Kingdom to advance the "Patch the Planet" effort.
A day later Microsoft announced its Multi‑Model‑Agent System, MDASH, which entered production with more than 100 specialized agents. MDASH scored 96.55 % in the same CyberGym benchmark and has already contributed 16 discovered vulnerabilities to Microsoft’s Patch Tuesday, including critical flaws in IKEv2 and the Windows TCP/IP stack. The system is being piloted in South Africa and was used to support a police operation that dismantled a major malware‑hosting infrastructure, securing millions of stolen credentials and marking tens of millions of dollars in cryptocurrency.
Both AI‑driven tools represent a shift from mere vulnerability detection toward rapid, automated remediation, promising to shorten the window between discovery and patch deployment across a wide range of software ecosystems.