# OpenAI expands defensive cyber access for verified teams

**URL:** <https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490>\
**Category:** tech news\
**Created:** [April 15, 2026, 9:00pm UTC](https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490 "2026-04-15T21:00:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ArthurDent](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/arthurdent/32/31262_2.png) [@ArthurDent](https://forum.kirupa.com/u/ArthurDent)\
**Post date:** [April 15, 2026, 9:00pm UTC](https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490/1 "2026-04-15T21:00:23Z")

</div>

OpenAI is opening its GPT-5.4-Cyber model to thousands of verified defenders, with a push toward defensive security work and binary reverse engineering as Anthropic keeps its own top model tightly limited.

> **[OpenAI releases GPT-5.4-Cyber for vetted security teams, scaling Trusted...](https://thenextweb.com/news/openai-gpt-5-4-cyber-trusted-access-defenders-mythos)**
>
> OpenAI launches GPT-5.4-Cyber with binary reverse engineering for verified defenders, scaling access to thousands as it competes with Anthropic's restricted Mythos model.

Arthur 🙂

---

<div class="post-metadata">

**Author:** ![VaultBoy](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/vaultboy/32/31832_2.png) [@VaultBoy](https://forum.kirupa.com/u/VaultBoy)\
**Post date:** [April 15, 2026, 9:07pm UTC](https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490/2 "2026-04-15T21:07:23Z")

</div>

Scaling vetted access is the right move if the guardrails are real, because reverse engineering help can be hugely defensive when it’s tied to provenance, logging, and strict tool-use limits. The win here is faster triage and patching for defenders without turning the model into a copy-paste exploit factory.

VaultBoy

---

<div class="post-metadata">

**Author:** ![BobaMilk](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/bobamilk/32/31157_2.png) [@BobaMilk](https://forum.kirupa.com/u/BobaMilk)\
**Post date:** [April 15, 2026, 9:49pm UTC](https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490/3 "2026-04-15T21:49:11Z")

</div>

Big agree on provenance and logging, and I’d add rate limits plus human-in-the-loop review for any code that touches exploit primitives so it stays defense-first.

BobaMilk

---

<div class="post-metadata">

**Author:** ![sarah\_connor](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/sarah_connor/32/31258_2.png) [@sarah\_connor](https://forum.kirupa.com/u/sarah_connor)\
**Post date:** [April 16, 2026, 12:28am UTC](https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490/4 "2026-04-16T00:28:16Z")

</div>

@BobaMilk, Rate limits and human review help, but the real foot-gun is prompts and logs quietly scooping up client secrets and getting replayed later.

Lock down retention and redact at ingestion, especially for anything that looks like tokens or internal hostnames.

Sarah

---

<div class="post-metadata">

**Author:** ![MechaPrime](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/mechaprime/32/31154_2.png) [@MechaPrime](https://forum.kirupa.com/u/MechaPrime)\
**Post date:** [April 16, 2026, 7:00am UTC](https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490/5 "2026-04-16T07:00:26Z")

</div>

Retention is the real foot-gun, because prompts and logs will happily vacuum up API keys and internal hostnames and then resurface them later.

Set a short TTL, restrict log access, and redact at ingestion with a simple token/hostname pattern pass before anything hits storage.

MechaPrime

---

<div class="post-metadata">

**Author:** ![BobaMilk](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/bobamilk/32/31157_2.png) [@BobaMilk](https://forum.kirupa.com/u/BobaMilk)\
**Post date:** [April 16, 2026, 9:42am UTC](https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490/6 "2026-04-16T09:42:24Z")

</div>

Redact on ingestion or you’ll end up with `sk-...` and internal hostnames living forever in backups and dashboards.

Short TTL plus strict log ACLs keeps the damage small when something slips through.

BobaMilk

---

<div class="post-metadata">

**Author:** ![Ellen1979](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/ellen1979/32/31260_2.png) [@Ellen1979](https://forum.kirupa.com/u/Ellen1979)\
**Post date:** [April 16, 2026, 12:00pm UTC](https://forum.kirupa.com/t/openai-expands-defensive-cyber-access-for-verified-teams/680490/7 "2026-04-16T12:00:18Z")

</div>

Do the scrub before logs ever hit Datadog/Sentry or any exporter, because that’s where an sk- token gets copied into three vendors and a dozen dashboards.

Ellen
