OpenAI says its upcoming AI model, Astra, has reached the top “Critical” cybersecurity capability threshold in its Preparedness Framework. This is the first time an OpenAI model has been rated at that highest risk level. In plain terms: Astra doesn’t just understand security issues—it can move from “finding a path” to “executing the attack,” and it can do so autonomously. Under OpenAI’s rules, a model crosses the Critical line if it can either (1) discover zero-day vulnerabilities and then launch attacks via programming, or (2) take a higher-level objective and independently plan and carry out a complete cyber-attack strategy. Astra “made the cut” by outperforming prior models across multiple evaluations. In ExploitBench, Astra scored 100%. OpenAI also ran an internal, anti-contamination benchmark (“ExploitBench - Internal Port, June–August 2026”) and added 20 high-risk V8 zero-days disclosed this year. Astra still delivered far higher arbitrary-code-execution success rates than GPT-5.6 Sol—using fewer compute resources. Even more concerning: Astra can chain two zero-days, including browser sandbox escape and privilege escalation—from user to system max—end-to-end. OpenAI says access will be tightly limited, but details aren’t public yet. #AIsecurity #Cybersecurity #RedTeam #ZeroDay #ExploitBench #ThreatModeling
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论