Artificial Intelligence

OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal

GPT‑5.4‑Cyber is a model fine-tuned for defenders, lowering boundaries for legitimate cybersecurity work.

Artificial Intelligence (AI)

Days after Anthropic unveiled its Claude Mythos AI model, OpenAI introduced GPT-5.4-Cyber, a cybersecurity-focused model that will be offered to many defenders.

OpenAI announced that it’s scaling its Trusted Access for Cyber program to thousands of verified defenders and hundreds of security teams. They will be given access to GPT-5.4-Cyber, a fine-tuned variant of GPT-5.4 that relaxes the usual guardrails for legitimate cybersecurity work. 

GPT-5.4-Cyber also provides new capabilities such as binary reverse engineering, which enables users to analyze compiled executable software for vulnerabilities and malicious behavior.

The new AI model is initially being offered on a limited, iterative basis to vetted security vendors, organizations, and researchers.

Individual defenders who want to enroll into the Trusted Access for Cyber program and test GPT‑5.4‑Cyber can apply through chatgpt.com/cyber via an identity verification process, while enterprise teams must go through their OpenAI account representative. 

The AI giant’s announcement centers on three guiding principles: democratized access (making tools widely available through objective verification rather than manual gatekeeping), iterative deployment (learning from real-world use and improving over time), and ecosystem resilience (supporting the broader defender community through grants, open source contributions, and tools like Codex Security).

Advertisement. Scroll to continue reading.

The announcement comes in the wake of Anthropic’s release of Claude Mythos, a new and powerful AI model allegedly capable of autonomously discovering thousands of zero-day vulnerabilities. This led Anthropic to withhold its public release and instead offer it only to a few dozen major organizations through a restricted program called Project Glasswing.

Both Anthropic and OpenAI are prioritizing defensive use while managing dual-use risks, but the latter believes advanced defensive tools should reach as many legitimate defenders as possible.

“We don’t think it’s practical or appropriate to centrally decide who gets to defend themselves. Instead, we aim to enable as many legitimate defenders as possible, with access grounded in verification, trust signals, and accountability,” OpenAI explained.

The company has not shared information about the performance of its GPT-5.4-Cyber model, but said its Codex Security platform, which automatically scans codebases and proposes fixes, has already helped identify over 3,000 critical and high-severity vulnerabilities across the open source ecosystem.

Related: Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments

Related: ‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks

Related: ‘Mythos-Ready’ Security: CSA Urges CISOs to Prepare for Accelerated AI Threats

Related Content

Artificial Intelligence

Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others.

Vulnerabilities

The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations.

Artificial Intelligence

AI infrastructure introduces new security risks that traditional data center designs were never built to handle.

Artificial Intelligence

An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically.

Artificial Intelligence

The new program stems from an AI-focused Executive Order signed by President Trump on June 2.

Artificial Intelligence

A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. 

Artificial Intelligence

Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution.

Artificial Intelligence

Two announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version