On 23 September OpenAI announced that the Ukrainian government gets access to the Daybreak programme for finding and fixing vulnerabilities. In the same announcement the company points to CERT Polska, which used its models to help find six holes in router software; per the Poles' own bulletin, it is MikroTik's.
- Access goes through Ukraine's Ministry of Digital Transformation; it was announced on the sidelines of the UN General Assembly.
- CERT-UA handled nearly 6,000 cyber incidents in 2025, including attacks on hospitals, energy and telecoms.
- CERT Polska used the GPT-5.5-cyber and GPT-5.6-sol models to find six RouterOS vulnerabilities, including CVE-2026-67276 and CVE-2026-86060.
Nearly six thousand incidents in one year. That is the Ukrainian CERT's number for 2025, and it includes hospitals, energy and telecoms.
OpenAI steps in exactly there. Not with weapons, but with its Daybreak programme, which gives defenders models for reviewing old code, investigating suspicious activity and testing fixes before they ship.
Why the Polish example weighs more
Because it can be checked. The Ukrainian part is a promise of future work, and the Polish one is already done: six holes, numbers, fixes and confirmed attacks. And the Poles themselves write how it happened, without inflating the model's role.
According to CERT Polska, the most labour-intensive part was not the finding. It was preparing the lab, choosing directions and checking every hypothesis on a real router, with control tests and repeats on a clean machine. The models sped up the search. They did not replace the people who know what they are looking for.
If you run MikroTik, CERT Polska's advisory is for you, not for Ukraine. You update RouterOS and check for unknown users and scripts.