We have a new ChatGPT! However, it is focused exclusively on cybersecurity

OpenAI has announced GPT-5.4-Cyber, a specialized variant of its GPT-5.4 artificial intelligence model, designed specifically for advanced workflows in cybersecurity. This new model provides cybersecurity professionals with expanded access to tools that facilitate the analysis of compiled software, the identification of vulnerabilities, and malware analysis, without requiring access to the source code of applications. The launch of GPT-5.4-Cyber comes in the context of the expansion of OpenAI’s Trusted Access for Cyber (TAC) program, which will now allow thousands of verified defenders to access this model

OpenAI has announced GPT-5.4-Cyber, a specialized variant of its GPT-5.4 artificial intelligence model, specifically designed for advanced workflows in cybersecurity. This new model provides cybersecurity professionals with expanded access to tools that facilitate the analysis of compiled software, the identification of vulnerabilities, and malware analysis, without requiring access to the source code of applications.

Cyber SeGPT

The launch of GPT-5.4-Cyber occurs in the context of the expansion of OpenAI’s Trusted Access for Cyber (TAC) program, which will now allow thousands of verified defenders to access this model. The company has emphasized that this new model variant has fewer restrictions than the standard versions, allowing for more permissive use within secure and verified environments.

A significant part of OpenAI’s cybersecurity strategy is its Codex Security tool, which automatically monitors codebases and has helped fix over 3,000 critical vulnerabilities since its launch. With the advancement of technology, OpenAI has also highlighted improvements in the performance of its models in cybersecurity-related tasks, including a notable increase in capture the flag (CTF) performance since its previous version.

The new model allows professionals to defend against cyber threats more effectively by enabling capabilities such as vulnerability research and exploit analysis. However, initial access to GPT-5.4-Cyber is restricted to verified security providers, reflecting a risk mitigation strategy in an environment where the misuse of artificial intelligence remains a concern.

The introduction of GPT-5.4-Cyber aligns with the industry’s growing focus on specific artificial intelligence models for cybersecurity, especially following the launch of Claude Mythos by Anthropic, signaling an arms race in this technological sphere.

New cyberattack reveals vulnerability in AI security analysis

A recent cyber attack has highlighted a structural disconnection between the HTML text and what users actually see in their browsers, allowing attackers to send malicious instructions that go unnoticed by artificial intelligence assistants. This finding was presented by LayerX, a cybersecurity company, which demonstrated its technique through a fake fanfiction site for Bioshock. By using a custom font, the attackers were able to hide a malicious message in seemingly harmless content. Hidden threats in HTML The attack revealed that, although AI assistants like ChatGPT and Claude were examining the […]

A recent cyber attack has highlighted a structural disconnection between the HTML text and what users actually see in their browsers, allowing attackers to send malicious instructions that go unnoticed by artificial intelligence assistants. This finding was presented by LayerX, a cybersecurity company, which demonstrated its technique using a fake Bioshock fanfiction site. By using a custom font, the attackers were able to hide a malicious message in seemingly harmless content.

Hidden Threats in HTML

The attack revealed that, although AI assistants like ChatGPT and Claude were examining the underlying HTML for threats, they lacked the ability to identify hidden content that appeared safe at first glance. In this case, the malicious text urged users to execute a reverse shell on their machines, while the visible text was a set of unreadable characters.

LayerX has pointed out that this vulnerability does not require the use of JavaScript or exploit kits, revealing a flaw in how AI tools analyze the security of web pages. While browsers present information in a designed manner, AIs treat the text of the DOM as the complete representation of what is shown to the user, leaving a gap that attackers can exploit.

In response to this threat, LayerX recommends that AI providers implement dual rendering analysis and treat custom fonts as potential threat surfaces. Additionally, it is vital that these tools avoid making security judgments without having verified the full context of the page. So far, Microsoft has stood out as the only provider that has fully addressed the issue following LayerX’s responsible disclosure in December 2025.

OpenAI launches Codex Security: An AI agent to combat vulnerabilities

OpenAI has launched Codex Security, an AI-powered security agent designed to identify, validate, and propose solutions to vulnerabilities in systems. This new service, which is available in preview mode for ChatGPT Pro, Enterprise, Business, and Edu users, will offer free access for one month to its innovative features. Reduction of false positives Codex Security is the evolution of Aardvark, presented in private beta in October 2025, with the aim of helping developers and security teams detect and fix vulnerabilities at scale. During its beta phase, Codex Security has scanned […]

OpenAI has launched Codex Security, an AI-powered security agent designed to identify, validate, and propose solutions to vulnerabilities in systems. This new service, which is available in preview mode for ChatGPT Pro, Enterprise, Business, and Edu users, will offer free access for one month to its innovative features.

Reduction of false positives

Codex Security is the evolution of Aardvark, presented in private beta in October 2025, with the aim of helping developers and security teams detect and fix vulnerabilities at scale. During its beta phase, Codex Security has scanned over 1.2 million commits in various open-source projects, identifying 792 critical findings and 10,561 high-severity findings. Among the detected vulnerabilities are issues in popular projects such as OpenSSH, GnuTLS, and PHP.

The company emphasizes that Codex Security combines the reasoning capabilities of its advanced models with automated validation, which minimizes the risk of false positives and delivers practical solutions. An analysis over time in specific repositories has shown an improvement in service accuracy and a 50% reduction in false positive rates.

The operation of Codex Security is based on three stages: first, it analyzes the structure of the repository to create an editable threat model that documents the system’s exposures. Then, it identifies vulnerabilities based on a real context and validates them in an isolated environment. Finally, it proposes solutions that best align with the system’s behavior, facilitating their review and deployment.

The launch of Codex Security comes at a time when competition in the software security field is increasing, especially after the recent launch of Claude Code Security by Anthropic, another agent that helps scan for vulnerabilities in software codebases.

Yahoo presents Scout: a free answer engine based on artificial intelligence

Yahoo has launched Scout, a new AI-powered answer engine that is available in beta through its search app. Unlike other systems like OpenAI’s ChatGPT, which is subscription-based, Scout positions itself as a free product supported by ads. Yahoo’s strategy is to use advertising to fund access, thus democratizing the discovery and use of AI. Attention to brands With 250 million monthly users in the United States and the ability to capture 18 trillion intent signals per year, Yahoo seeks to modernize the […]

Yahoo has launched Scout, a new AI-powered answer engine that is available in beta through its search app. Unlike other systems like OpenAI’s ChatGPT, which is subscription-based, Scout positions itself as a free product supported by ads. Yahoo’s strategy is to use advertising to fund access, thereby democratizing the discovery and use of AI.

Attention to brands

With 250 million monthly users in the United States and the ability to capture 18 trillion intent signals per year, Yahoo seeks to modernize the way information is presented on its platform. Jim Lanzone, CEO of Yahoo, emphasized that Scout represents a renewed opportunity to fulfill the company’s mission of being a trusted guide on the internet. It is an opportunity we didn’t think would return, but artificial intelligence has provided it to us and we are taking advantage of it, Lanzone commented.

Scout, which will act as a data aggregation layer, differs in its approach to advertising compared to other giants like Google and ChatGPT. Scout’s ads will be designed based on situational relevance, using the vast dataset that Yahoo has accumulated on user interests and behaviors. This provides brands with a new advertising space that prioritizes structured content and contextual creativity.

Therefore, brands are urged to consider Scout as a testing ground for advertising through AI-generated responses. With a focus on data-driven relevance and a more authoritative structure, Scout could become an essential tool for companies looking to capture consumer attention in a dynamic response format.

ChatGPT will have ads, although they said it was the last resort

OpenAI has announced that it will begin testing targeted ads in ChatGPT for a select group of users in the United States, a decision that represents a significant effort by the company to generate revenue. The introduction of this feature comes at a time when OpenAI is not expected to reach profitability for several years, highlighting the financial difficulties the company is currently facing. Generative (and promoted) AI OpenAI’s CEO, Sam Altman, had previously stated that advertising in ChatGPT would be a “last resort,” suggesting that the situation […]

OpenAI has announced that it will begin testing targeted ads in ChatGPT for a select group of users in the United States, a decision that represents a significant effort by the company to generate revenue. The introduction of this feature comes at a time when OpenAI is not expected to reach profitability for several years, highlighting the financial challenges the company is currently facing.

Generative (and promoted) AI

The CEO of OpenAI, Sam Altman, had previously stated that advertising on ChatGPT would be a “last resort”, suggesting that the company’s financial situation might be more complicated than initially thought. Despite his claims, the arrival of ads on the platform had been the subject of rumors for some time, indicating that the possibility of monetization has been on OpenAI’s horizon.

The decision to introduce ads also seems to be a response to the growing competition in the field of artificial intelligence and technology services, where other players are already advancing in monetization through advertising. As the market becomes increasingly competitive, OpenAI seeks to diversify its revenue and ensure its long-term sustainability.

This move to incorporate advertising could change the user experience in ChatGPT, a service that has been valued for its ability to interact and respond without commercial interruptions. However, the company hopes that the ads will be relevant and ultimately enhance the overall user experience. With this initiative, OpenAI aligns itself with the monetization strategies that other competitors have been implementing on their platforms, which could be an indication of broader changes in the way artificial intelligence services are funded in the future.