Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

As fears AI hacking capabilities grow, OpenAI On Monday, he introduced a slew of measures focused on cybersecurity advertisementsincluding an enhanced version of its GPT-5.5-Cyber security model, expanded international work with governments and other organizations to give them “trusted access” to the company’s latest cybersecurity-focused models, and launched the Codex Security scanner as an app add-on.
As advances in the AI industry leave important open source projects at increasing risk of falling behind, the company also said Monday it is launching an effort known as Patch the Planet, founded with prominent research-focused security firm Trail of Bits and in collaboration with vulnerability management firms HackerOne and Calif.
The project has already begun its work by offering free security consulting services to open source maintainers to not only help them find and patch vulnerabilities, but also support them in enhancing their code bases and integrating AI security tools into their development process. The idea is to provide individual support to as many open source projects as possible to improve their current security and long-term resiliency in a way that is truly sustainable.
“Patch the Planet is an Internet-wide effort to help open source software outperform bug-hunting AI tools,” says Dan Guido, CEO and co-founder of Trail of Bits. “But it’s also an effort to help the open source community see the benefits and not just the downsides of AI coding tools.”
Open source developers — typically volunteers who maintain important and widely used software with few resources — often struggle to keep up with bug reports. The rise of AI vulnerability searches in recent months has, for many maintainers, made this backlog seem insurmountable as AI-generated bug reports pile up, making it difficult to prioritize and pulling already limited time and attention away from critical flaws.
Fouad Mateen, head of cyber technology at OpenAI, says maintainers “do their work out of a love of open source, and now they are stuck reviewing common bugs.” With Patch the Planet, “what we effectively did was make it as efficient from a token perspective as possible to reduce the burden on maintainers — code base evaluations, validating potential reports, creating patches, and downloading them,” he says. We want to offset the costs, whether it be tokens or people power, to patch as much of the software world as possible.”
For its Codex Security checker, which has been in research preview since earlier this year, OpenAI supports use for both open source and proprietary code “up to 20 trillion tokens,” Mattin adds.
More than 30 open source projects are already participating in Patch the Planet, and more are in the pipeline. To launch the project, Trail of Bits recently ran a five-day inaugural sprint that had 25 engineers, or roughly a fifth of its workforce, simultaneously working collaboratively with a group of maintainers. OpenAI and Trail of Bits say the project has already uncovered hundreds of bugs and produced dozens of patches in just its first week. With funding from OpenAI as well as unlimited access to models, Trail of Bits plans to continue its extensive commitment to Patch the Planet’s work over the long term, Guido says.
“It’s very rare that we have the opportunity to work on large-scale open source security issues,” says Guido. “Patch the Planet is not a one-size-fits-all solution. We talk to all the maintainers on each individual project and find out what their top priorities are, whether that’s building better testing infrastructure or custom fog machines or just cleaning up the technical data across the project because that’s what will get them up and running faster and patching faster.”