Cloudflare Inc. has opened early access to Vulnerability Discovery and Remediation, a service that uses OpenAI Group PBC’s cybersecurity models to spot software flaws in customer applications and block attacks on them at the network edge. The offering runs within Cloudflare Managed Defense, the company’s security operations center product, and connects to OpenAI’s GPT-5.6-Cyber model through the Daybreak Defense Network. Cloudflare initially pulls a snapshot from its Web Assets inventory and web application firewall to identify which routes are live and what security events they have produced. A reconnaissance agent maps request paths to sections of the codebase, and hunter agents work from that map, with code running on Cloudflare Workers pulled in through Workers Observability.

Every finding is validated before receiving a risk rating, which can be raised if production evidence shows heavy traffic or active probing against the affected route. The process generates two types of fixes: custom firewall rules scoped to the method, path, and request details needed to reach the vulnerable code, which can act as a stopgap while developers work, and code patches drafted for engineers to review. No rule or patch takes effect without explicit human approval, and Cloudflare said the models cannot apply either on their own. Prompts travel through Cloudflare AI Gateway to OpenAI servers, with no inference running on Cloudflare’s own edge, and redaction strips out context the model does not need. Every proposal must also pass checks written outside the model, and a failed check stops the workflow before a customer sees anything.

The service targets a growing workload, as the National Vulnerability Database took in 60,475 vulnerabilities by September, compared to 48,185 for all of 2025. Cloudflare said scanners hand teams thousands of findings without showing which ones matter in production, and that is the gap the service is meant to close. Chief Executive Matthew Prince said the company is leaving behind chasing patches one vulnerability at a time, arguing that teams fighting AI-driven attacks by hand are losing. He added that a network reading internet traffic in real time, paired with GPT-5.6-Cyber, lets defenders stop attacks before they land.

GPT-5.6-Cyber arrived in August, when OpenAI split Daybreak into two access tiers and placed the model behind the higher tier, Daybreak Red, for vulnerability research and exploit validation. The model completed 95% of advanced cybersecurity requests on OpenAI’s own benchmark, against 1.5% for the general-purpose GPT-5.6 Sol. McCall McIntyre, head of global cyber partnerships at OpenAI, said the network is designed to give defenders the advantage of frontier AI safely. Palo Alto Networks Inc. put the same models to work inside its Unit 42 consulting engagements last month.

On the same day as Cloudflare’s announcement, Proofpoint Inc. said Daybreak models now sit behind a SOC Analyst Agent for threat investigation, and OpenAI committed $1 billion to subsidized Daybreak access for water and electricity utilities, local government, community banks, and nonprofits. Access to the Cloudflare service is by invitation only, with the early phase held to selected enterprise customers, and each engagement begins with one application the customer nominates. Pricing was not disclosed, and Cloudflare gave no timeline for taking the service beyond early access.

More cybersecurity news from TechManNews.