OpenAI Launches “Patch the Planet” Initiative to Fix Open-Source Security Vulnerabilities

OpenAI announced a set of cybersecurity-focused initiatives in June 2026, including a new program called Patch the Planet aimed at helping open-source software projects find and fix security vulnerabilities before AI-powered bug-hunting tools can exploit them.

The Patch the Planet initiative was founded alongside Trail of Bits, a research-focused security firm, and in collaboration with vulnerability management companies HackerOne and Calif. The program offers free security consulting to open-source maintainers, helping them identify and patch vulnerabilities, strengthen their code bases, and incorporate AI security tools into their development workflows. More than 30 open-source projects are already participating, with more expected to join.

To kick off the effort, Trail of Bits ran a five-day sprint in which 25 engineers — roughly a fifth of its workforce — worked simultaneously with open-source maintainers. OpenAI and Trail of Bits say the project uncovered hundreds of bugs and produced dozens of patches in its first week alone. Trail of Bits CEO and co-founder Dan Guido said OpenAI is providing both funding and unmetered model access to sustain the work long-term.

The initiative responds to a growing problem for open-source maintainers, who are typically volunteers managing widely used software with limited resources. The rise of AI-generated vulnerability reports has added to their workload, flooding them with low-quality submissions that make it harder to focus on genuine security flaws. “Maintainers do their work out of love of open source, and now they’re stuck reviewing slop CVEs,” said OpenAI’s cyber tech lead, Fouad Matin.

Alongside Patch the Planet, OpenAI also announced an improved version of its security-specialized model GPT-5.5-Cyber, expanded government partnerships for trusted access to its cybersecurity models, and the release of its Codex Security scanner as an app plug-in. Matin noted that OpenAI has subsidized Codex Security scanner usage for open-source and private code to the equivalent of 20 trillion tokens.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top