we_are_coded.by CODE · The world, decoded
БГ
OpenAI

OpenAI gives Ukraine its vulnerability-hunting models to protect hospitals, power and telecoms

OpenAI · event date: 23 September 2026Security

On 23 September OpenAI announced that the Ukrainian government gets access to the Daybreak programme for finding and fixing vulnerabilities. In the same announcement the company points to CERT Polska, which used its models to help find six holes in router software; per the Poles' own bulletin, it is MikroTik's.

In short
  • Access goes through Ukraine's Ministry of Digital Transformation; it was announced on the sidelines of the UN General Assembly.
  • CERT-UA handled nearly 6,000 cyber incidents in 2025, including attacks on hospitals, energy and telecoms.
  • CERT Polska used the GPT-5.5-cyber and GPT-5.6-sol models to find six RouterOS vulnerabilities, including CVE-2026-67276 and CVE-2026-86060.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Nearly six thousand incidents in one year. That is the Ukrainian CERT's number for 2025, and it includes hospitals, energy and telecoms.

OpenAI steps in exactly there. Not with weapons, but with its Daybreak programme, which gives defenders models for reviewing old code, investigating suspicious activity and testing fixes before they ship.

The facts: on 23 September 2026 OpenAI announced it is giving the Government of Ukraine access to the Daybreak programme for the cyber defence of civilian infrastructure, in partnership with the Ministry of Digital Transformation. The announcement was made on the sidelines of the UN General Assembly by Dmytro Kushneruk, Consul General of Ukraine in San Francisco, and Sasha Baker, Head of National Security Policy at OpenAI. Per OpenAI, Ukraine's national team CERT-UA handled nearly 6,000 cyber incidents in 2025, including attacks on hospital systems, the energy sector and telecommunications. The company says it has already given access to its cyber models to defenders in France, Germany, Poland and other countries, that the EU cybersecurity agency ENISA has used them to find vulnerabilities in software used by EU institutions, all since fixed, and that CERT Polska used them to find six vulnerabilities in third-party router software. In its own advisory of 5 September, CERT Polska specifies that this is MikroTik RouterOS, that the vulnerabilities were found by Sławomir Rozbicki using the GPT-5.5-cyber and GPT-5.6-sol models, and that a chain of two of them is being used in real attacks; the numbers include CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277.

Why the Polish example weighs more

Because it can be checked. The Ukrainian part is a promise of future work, and the Polish one is already done: six holes, numbers, fixes and confirmed attacks. And the Poles themselves write how it happened, without inflating the model's role.

According to CERT Polska, the most labour-intensive part was not the finding. It was preparing the lab, choosing directions and checking every hypothesis on a real router, with control tests and repeats on a clean machine. The models sped up the search. They did not replace the people who know what they are looking for.

The model finds tracks. A person decides which one leads to a door.

If you run MikroTik, CERT Polska's advisory is for you, not for Ukraine. You update RouterOS and check for unknown users and scripts.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→OpenAI - OpenAI extends cyber access to Ukraine for civilian defense, 23.09.2026→CERT Polska - Critical vulnerabilities in MikroTik RouterOS are being actively exploited, 05.09.2026→CERT Polska - Vulnerabilities in Mikrotik RouterOS software (CVE list), 05.09.2026
Original: https://wearecoded.com/en/articles/openai-daybreak-ukrayna-kiberzashtita.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news