OpenAI expanded Daybreak today, widening the scope of its cybersecurity program. Until now, Daybreak was mostly about finding vulnerabilities. Now the company wants to push harder on getting patches shipped before attackers can use newly discovered flaws. OpenAI’s view is pretty simple: for years, the industry got much better at spotting bugs than it did at fixing them.
The update adds new tools, new partnerships, and Patch the Planet, a program meant for open-source projects that are doing important work without much support behind them. OpenAI says the aim is to move the entire patching process faster, from writing the fix and checking it to getting it deployed.
The numbers explain why this matters. OpenAI says 48,185 CVEs were published in 2025. Average time to remediation climbed to 252 days. Even critical vulnerabilities still took about 74 days to fix. And 94% of widely used open-source projects have fewer than 10 core maintainers.
Attackers don’t wait around for any of that. OpenAI says they can move within days, sometimes before a patch is available at all. That leaves a gap where you’re exposed and waiting for vendors, cloud providers, or open-source maintainers to catch up.
And when that gap stays open, the fallout is familiar: outages, fraud, and data leaks. OpenAI says the average cost of a breach now stands at $4.44 million worldwide and $10.22 million in the US.
If you follow security policy, this update is one to watch. OpenAI isn’t the only group heading this way. Anthropic is making a similar push with Project Glasswing, and the US Cybersecurity and Infrastructure Security Agency, or CISA, wants to cut critical patch deadlines from weeks down to three days.
Automation can help sort reports, verify findings, and even put together a draft patch. But people still have to make the harder calls: how exploitable the flaw really is, whether the fix is safe, what regressions it could trigger, and when it should actually go live in production.
You can follow Daybreak through OpenAI’s security updates.