Security researchers and AI vendors reported rapid progress in applying frontier models to offensive and defensive cybersecurity work, including the discovery of CVE-2025-37899, a remote zero-day in the Linux kernel’s SMB implementation. A published account described using an advanced model to help identify the flaw, while OpenAI's Daybreak and Anthropic's Project Glasswing highlighted broader efforts to build AI systems for cyber operations, vulnerability research, and security workflows.
SentinelLABS added evidence that these systems are moving beyond isolated tasks into sustained investigations, describing an eight-stage benchmark based on reverse engineering fast16, a 2005 Windows sabotage toolkit tied to interference with high-precision solvers used in nuclear-weapons modeling. In that evaluation, GPT-5.6 Sol was reported as the only publicly available model tested that completed the full long-horizon malware-analysis workflow, while other models showed useful point-in-time reasoning but failed to maintain consistency as new evidence forced earlier conclusions to be revised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On July 2, 2026, SentinelLABS published research describing a multi-stage benchmark based on its reverse-engineering investigation of the 2005 fast16 sabotage toolkit and reported that GPT-5.6 Sol was the only publicly available model evaluated to complete the full benchmark.
On April 7, 2026, Anthropic published its Project Glasswing page.
On February 5, 2026, OpenAI published its Daybreak page focused on cybersecurity.
On May 22, 2025, Sean Heelan published details on how he used o3 to find CVE-2025-37899, described as a remote zero-day vulnerability in the Linux kernel's SMB implementation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourceanthropic.com
Open sourceopenai.com
Open sourcesean.heelan.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.