Hi X: Apple CEO John Ternus just demonstrated that Twitter is having a moment


OpenAI says its upcoming AI model, Astra, has achieved a significant cybersecurity milestone. The company has revealed that the model, which is still in development, is the first OpenAI system to reach the “Critical” cybersecurity level under its Preparedness Framework. In practical terms, OpenAI says Astra has become capable of performing highly sophisticated hacking-related tasks with limited human assistance.

According to OpenAI, Astra can identify weaknesses in software, including previously unknown vulnerabilities, and determine how those flaws could be exploited to gain access to systems. It can also combine multiple vulnerabilities into an exploit chain, allowing it to move further into a compromised system after obtaining an initial entry point.

“With the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step,” OpenAI said in a blog post.

The company said Astra reached the Critical threshold following new evaluations and tests conducted with cybersecurity experts. Under OpenAI’s framework, a model qualifies for this level if it can independently discover and develop functional “zero-day” exploits against multiple well-protected real-world systems, or devise and carry out a complete cyberattack strategy based only on a high-level objective.

During one evaluation, Astra achieved a perfect 100 per cent score on ExploitBench, a benchmark designed to assess a model’s ability to develop exploits using known vulnerabilities.

OpenAI also evaluated Astra using an internal benchmark containing 20 recently disclosed, high-severity vulnerabilities affecting V8. The company said Astra achieved a significantly higher rate of arbitrary code execution than GPT-5.6 Sol while generating fewer output tokens. It also identified and exploited two zero-day vulnerabilities as part of an exploit chain.

In expert-led testing, OpenAI said Astra discovered previously unknown security flaws in a protected browser and operating system. The model was reportedly able to use those vulnerabilities to bypass protections and obtain deeper access.

What are the cybersecurity concerns?

An AI model capable of independently finding and exploiting vulnerabilities could offer major benefits to cybersecurity researchers, allowing them to identify and fix weaknesses before malicious actors can exploit them.

At the same time, those capabilities could create serious risks if they were used to attack real-world systems.

OpenAI says it recognises these concerns and has introduced additional safeguards ahead of Astra’s release. The company also temporarily paused parts of the model’s development while it worked on improving its safety and security controls, before resuming development once those measures were implemented.

According to OpenAI, Astra is already operating under these restrictions. During cyber jailbreak evaluations, the model reportedly refused 91.5 per cent of prohibited requests, compared with 59 per cent for GPT-5.6 Sol.

In another evaluation based on the Hugging Face incident, OpenAI said Astra did not attempt to attack surrounding security infrastructure.

When will Astra launch?

Astra has not yet been released. OpenAI says the model is coming soon but has not provided a specific launch date.

When it becomes available, however, the model’s most advanced cybersecurity capabilities will not initially be open to everyone. Access will first be provided to a limited group of alpha testers before being expanded through OpenAI’s Daybreak programme, which is focused on defensive cybersecurity applications.

OpenAI said it will provide additional information about Astra’s capabilities and the results of its safety evaluations in the model’s system card when it officially launches.


 

buttons=(Accept !) days=(20)

Our website uses cookies to enhance your experience. Learn More
Accept !