
Ukraine's Ministry of Digital Transformation gains access to Daybreak, OpenAI's vulnerability hunting tool.
Ukraine's Ministry of Digital Transformation gains access to Daybreak, OpenAI's cybersecurity tool powered by GPT-5.6 Sol, to audit its aging infrastructure in the face of Russian attacks.
AI-generated summary
OpenAI amended its usage policy in January 2024 to authorize certain military and defensive cybersecurity activities.
OpenAI artificial intelligence enlisted on the digital front. The Ukrainian Ministry of Digital Transformation obtains access to Daybreak, the American laboratory's software vulnerability hunting tool. The announcement was also made on the sidelines of the United Nations General Assembly.
Kyiv wants to spot the holes in its aging systems before Russian groups rush in. Then it's a matter of verifying that the patches actually hold up.
Ukraine's Ministry of Digital Transformation can now use Daybreak to audit its aging infrastructure
The tool is based on GPT-5.6 Sol and also validates the effectiveness of patches before their deployment
Polish cyber firefighters had already identified six flaws in router firmware using OpenAI models
On the digital assets side, automated code auditing is gaining ground after a record year in stolen amounts
Daybreak, OpenAI’s AI that sifts Ukrainian code
Concretely, Daybreak runs on GPT-5.6 Sol, a large OpenAI language model from the previous generation (GPT-6 Sol was released on September 22). Trained on huge volumes of text and code, it reads software like a human listener would. The tool sifts through old systems and verifies that a suspected flaw is actually exploitable. But sometimes just one is enough to open an entire network. Finally, he checks that the patch closes the hole properly before putting it into production.
Because the volume of attacks is not weakening. CERT-UA (the Ukrainian IT emergency team) handled nearly 6,000 incidents in 2025. An increase of 37% over one year. In December 2023, the operator Kyivstar lost part of its core network. 24 million subscribers were then left without service. The attack was attributed to Sandworm, an offensive unit of Russian military intelligence. Since then, ESET has documented new waves of erasure software from the same group. They target the country's energy and cereal sectors.
The Consul General of Ukraine in San Francisco, Dmytro Kushneruk, presented the device. At his side, Sasha Baker, head of national security policy at OpenAI, justifies the urgency.
“We are proud to support Ukraine’s cyber defenders, who protect essential services from attacks every day. Ukraine is already on the front line, and its defenders need support now. »
Sasha Baker, Head of National Security Policy at OpenAI
Ukraine is not the first state under pressure to receive this type of support. French, German and Polish cyber agencies already have OpenAI models. CERT Polska has identified six vulnerabilities in commercial router software, which have since been corrected by the publisher. In early September, the company promised $1 billion in subsidized access to Daybreak for under-resourced defenders. She also announced an extension to “partner countries” within a few weeks. Kyiv therefore obtained access three weeks later.
OpenAI and the military, a red line erased in 2024
This defensive zeal, however, has a short history. Until the beginning of 2024, OpenAI's usage policy prohibited any military or warlike activity, without nuance. The line disappeared on January 10. A few days later in Davos, Anna Makanju confirmed that the company was already working with the Pentagon on cybersecurity tools. The vice president of global affairs spoke alongside Sam Altman.
Not everyone sees this as a philanthropic impulse. Jamie MacColl is a senior cybersecurity researcher at the Royal United Services Institute. He told the BBC that Western companies also gain valuable intelligence from an active war zone. “Given this, it is not surprising that OpenAI now also provides defensive cybersecurity services,” he adds.
Kyiv is used to these technology transfers. Microsoft estimates its aid at more than $400 million since the start of the invasion. Google also shelters hundreds of Ukrainian sites behind its Project Shield anti-DDoS shield.
Crypto: the hunt for vulnerabilities also applies to smart contracts
But the same problem arises wherever the war chest fits into a few lines of code. The code is public there. A poorly written smart contract cannot be corrected with a click. Router firmware, on the other hand, quietly waits for its patch. The Bybit hack cost $1.46 billion in February 2025, a record attributed to the North Korean group Lazarus. Chainalysis counted more than $2.17 billion stolen from crypto services in the first half of 2025 alone. This is already more than in all of 2024.
Ukraine knows these rails well. Elliptic had recorded more than $100 million in cryptocurrency donations in the first months of the invasion. They were paid to the government and NGOs via public addresses. And language model-assisted audits are progressing quickly. The proof in August 2025, during the final of the DARPA AI Cyber Challenge. Fully automated systems detected and fixed flaws in real open source projects, without human intervention.
AI outlook — possibilities, not facts
Expanding access to Daybreak to other OpenAI partner countries
Very likely · Within weeks

The Services and Payment Agency confirms a data leak via fraudulent access to a user account on August 27, 2026, detected the next day. More than 143,000 people would be affected according to FrenchBreaches, with 2023-2024 payment notices from the Île-de-France “Coup de Pouce Energie” system containing names, addresses, IBAN/BIC, beneficiary numbers and amounts paid. This is the second such leak at ASP in five months.

China opened an investigation in late September 2026 into DeepSeek and Moonshot AI after Anthropic's accusations of allegedly using fraudulent accounts to train their models on Claude's responses. CAC investigators are seeking to determine whether sensitive Chinese data was transferred to U.S. servers, rather than focusing on alleged technological theft to the detriment of Anthropic.

Cardano joins the x402 protocol, enabling automated payments for AI agents and online services. The official TypeScript kit now supports ADA and native tokens, although usage is currently limited to the staging network.

More than 52 bitcoins from the Coldcard wallet hack were transferred to a legal trust in Wyoming to be returned to their owners, after being sheltered by ethical hackers.

Anthropic unveiled Claude Opus 5.5, sold 40% cheaper, followed immediately by OpenAI and its new GPT-6 Sol and Luna models at knockdown prices. This price war comes as Anthropic's IPO on Nasdaq approaches.

X deploys X Numbers, private codes allowing you to receive messages and calls from untracked accounts without revealing your phone number, thus paving the way for the X Money payment service.