Breaking
RUUS Central Command Investigates Deadly Strike on Wedding Party in IranTRShooting in Minneapolis, injured police officersCNVeteran Hong Kong actor Lau Siu-ming passed away at the age of 94CNWuhan police busted a live-streaming fraud gang targeting the elderly, with more than 1,000 victims involved and more than 10 million yuan involvedTRA friend was killed in Ankara Altındağ because of a debt issue.RUThe US special envoy discussed with the UAE actions against Iran, the US cut off the Egyptian Misr bank from the financial systemUSAdult wounded in shooting at Virginia elementary school, no children injuredPLAn attack on a wedding house in Kuhestak, Hormozgan Province, IranRUThe Ukrainian Armed Forces attacked the south of Russia, restrictions were introduced at the airports of Gelendzhik and SochiTRUnited Nations Secretary-General expressed concern over civilian casualties in US-Iran conflictRUUS Central Command Investigates Deadly Strike on Wedding Party in IranTRShooting in Minneapolis, injured police officersCNVeteran Hong Kong actor Lau Siu-ming passed away at the age of 94CNWuhan police busted a live-streaming fraud gang targeting the elderly, with more than 1,000 victims involved and more than 10 million yuan involvedTRA friend was killed in Ankara Altındağ because of a debt issue.RUThe US special envoy discussed with the UAE actions against Iran, the US cut off the Egyptian Misr bank from the financial systemUSAdult wounded in shooting at Virginia elementary school, no children injuredPLAn attack on a wedding house in Kuhestak, Hormozgan Province, IranRUThe Ukrainian Armed Forces attacked the south of Russia, restrictions were introduced at the airports of Gelendzhik and SochiTRUnited Nations Secretary-General expressed concern over civilian casualties in US-Iran conflict
BackOpenAI's Astra model reaches 'critical' cybersecurity threshold under Preparedness Framework
OpenAI's Astra model reaches 'critical' cybersecurity threshold under Preparedness Framework
BREAKING
Decrypt49 minutes agoTech2 min read

OpenAI's Astra model reaches 'critical' cybersecurity threshold under Preparedness Framework

Quick Look

OpenAI announced its unreleased Astra model has crossed the 'critical' cybersecurity threshold in its Preparedness Framework, enabling it to independently develop zero-day exploits and execute full cyberattacks from high-level goals, with Astra achieving perfect scores on exploit benchmarks and demonstrating advanced capabilities in hardened system tests.

AI-generated summary

Why It Matters

OpenAI's Preparedness Framework evaluates AI models across risk tiers, with 'critical' representing the highest level of autonomous cybersecurity capability, requiring enhanced safeguards before deployment.

Font size

OpenAI said Tuesday that Astra, an unreleased model, has crossed the "critical" threshold for cybersecurity capability under its Preparedness Framework, the first model the company has ever put in that category.

That means Astra, which many believe to be GPT-6 instead of an additional model, can find previously unknown security flaws and build working exploits across many hardened systems without a person guiding it step by step.

"We now believe Astra meets the Critical cybersecurity capability threshold under our Preparedness Framework," OpenAI wrote. "It is the first model we are designating at this level, and requires stronger safeguards during development and before release."

Under the framework, a model hits critical if it can independently develop functional zero-day exploits across many hardened real-world systems, or if it can plan and execute an entire cyberattack against a tough target starting from nothing more than a high-level goal. Earlier OpenAI models, including GPT-5.6 Sol, topped out at the framework's lower "high" tier.

On ExploitBench, a benchmark that tests whether a model can turn already-known software vulnerabilities into functioning exploits and scores it as a straight pass rate, Astra hit a perfect 100%.

To rule out memorized answers inflating that score, OpenAI built a second test using 20 high-severity vulnerabilities in Google's V8 JavaScript engine disclosed between June and August. Astra beat GPT-5.6 Sol on arbitrary code-execution rates there too, using far fewer output tokens, and along the way it found and chained together two zero-day vulnerabilities OpenAI is still disclosing to the affected maintainers.

GPT-5.6 Sol is currently OpenAI’s best model.

In hands-on tests against a hardened browser and a hardened operating system, Astra built a full compromise chain that broke out of a browser sandbox and ran commands on the host just from opening a malicious HTML file. It also found multiple flaws in the hardened OS and strung them into a privilege-escalation path from an ordinary user account to root.

OpenAI said the model refuses 91.5% of cyber jailbreak attempts in its own testing, up from 59% for GPT-5.6 Sol. Access to Astra's most advanced cybersecurity capabilities starts with a small group of alpha testers, with wider access rolling out later through OpenAI's Daybreak Blue program for defensive security work.

The disclosure follows weeks of jitters across the industry. Just a few days ago, OpenAI paused Astra's development after the model's cyber and coding skills advanced quickly, a warning that landed on the heels of a separate, unreleased OpenAI system that chained vulnerabilities to breach Hugging Face while gaming a security benchmark. OpenAI says Astra had no role in that incident.

Traders had already priced in a fast turnaround. Prediction markets on Myriad tracked by Decrypt gave Astra, internally tied to the codename GPT-6, 72% odds of a public release by Sept. 30 even after OpenAI's early-August pause, and OpenAI still hasn't set a public launch date. Those odds changed 55% in favor of a release by November 2026.

The timing puts Astra up against a fresh rival. Anthropic released Fable 5.1 and Mythos 5.1 on Tuesday, and Mythos 5.1, like the earlier Mythos 5, is reserved for vetted cybersecurity and life-sciences organizations rather than the general public.

Decrypt reported in June that OpenAI's GPT-5.5-Cyber had already outscored Mythos 5 on CyberGym, a benchmark that runs AI agents against more than 1,500 known vulnerabilities from real open-source projects and scores them on how many they correctly reproduce.

Both companies had been rumored to be readying new frontier models around the same window, and now they have. Fable 5.1 landed Sept. 1, and OpenAI says Astra is coming soon, with its most capable cyber tools gated behind alpha access first and Daybreak Blue after that.

What to Watch

AI outlook — possibilities, not facts

  • Astra will receive a public release by November 2026

    Likely · Within months

  • Regulatory scrutiny of advanced AI models will increase

    Very likely · Within months

Open Questions

  • What specific safeguards will OpenAI implement for Astra's release?
  • When will Astra be publicly available?
  • How will regulators respond to AI models with autonomous exploit development capabilities?

Related Topics

This article was originally published by Decrypt.

Related Stories

Circle warns quantum threat to blockchain signatures is growing more efficient, cites 813-qubit record
Developing·2 minutes ago

Circle warns quantum threat to blockchain signatures is growing more efficient, cites 813-qubit record

Circle issued a warning that advances in quantum circuit design are reducing the resources needed to break blockchain signatures, citing a record of 813 logical qubits for ECDSA attacks. The company emphasized that migrating USDC to post-quantum cryptography requires coordination across 37 host networks, wallets, custodians, and users, as Circle cannot unilaterally change signature rules on chains like Ethereum or Solana. While NIST has standardized quantum-resistant algorithms, Circle stressed that readiness—not a predicted Q-day—is the practical trigger for migration.

CryptoSlate
2 min read
TAC Network Halt Continues After Exploit Drains Bonded Staking Pool
Developing·3 hours ago

TAC Network Halt Continues After Exploit Drains Bonded Staking Pool

The TAC network remains halted at block 24,671,475 over 10 days after an exploit drained 2,985,651,403.40 TAC (28.6% of supply) from the bonded staking pool via a balance mismatch between EVM StateDB and Cosmos SDK ledger. The attacker sold portions on BNB Chain and TON for ~1,005,774 USDT. Recovery proposes a targeted state edit to restore delegator balances using treasury reserves, but bridging and redemption remain disabled while validators await patched binary adoption.

CryptoSlate
2 min read
AI-backed group spends millions on ads to defend data centers in battleground states
Developing·5 hours ago

AI-backed group spends millions on ads to defend data centers in battleground states

Build American AI, funded by AI billionaires via super PAC Leading the Future, is spending millions on advertising in Kansas, Ohio and Wisconsin to support data center construction amid rising local opposition, which has increased to 61% nationally according to Annenberg polling, with political figures and lenders increasingly treating data center siting as a credit risk and campaign issue.

Decrypt
2 min read
More on this topicopenai