Express Computer
Home  »  News  »  GPT-6 Astra can find zero-days on its own. OpenAI calls that ‘Critical.’

GPT-6 Astra can find zero-days on its own. OpenAI calls that ‘Critical.’

0 0

OpenAI this week shipped GPT-6 Astra, a model its president called a “generational leap,” with some executives suggesting — carefully, and with hedges attached — that it might be a first glimpse of artificial general intelligence. For the security community, the more consequential headline is buried a few paragraphs down: Astra is the first OpenAI model formally designated as reaching the “critical” cybersecurity threshold under the company’s preparedness framework.

It means OpenAI’s own testing found that, absent production safeguards, Astra can identify and exploit previously unknown vulnerabilities in hardened systems without a human walking it through each step. In other words: a model that can independently discover and weaponize zero-days.

The Numbers Behind the Threshold
OpenAI’s release materials lay out benchmark results that illustrate why the critical designation was triggered. On ExploitBench, a benchmark measuring whether a model can convert known vulnerabilities into working exploits, Astra reportedly hit a 100% success rate, up from roughly 78% for its predecessor. On a harder benchmark simulating exploit development from scratch, Astra’s success rate came in above 42%, again outpacing the prior generation while using markedly fewer tokens to get there — a proxy for efficiency, and therefore speed.

Most notably, OpenAI says that when it built a fresh benchmark using vulnerabilities disclosed only in the prior three months — specifically to rule out the possibility that the model was simply recalling memorized exploits from training data — Astra still discovered two previously unknown zero-days during testing. OpenAI says it’s disclosing both to the affected maintainers.

Separately, on a reverse-engineering benchmark that tests a model’s ability to understand compiled binaries without source code, Astra reportedly solved the large majority of tasks on a single attempt, a substantial jump over its predecessor.

Defenders Get the Tool First — With Guardrails
To its credit, OpenAI says the version shipping today is deliberately hobbled for offense. The company states that Astra will refuse more advanced cybersecurity requests, such as generating proof-of-concept exploits, and that the more capable, less-restricted cyber functionality will be limited to a small group of vetted testers through its early-access program, with broader defensive workflows — vulnerability validation, malware analysis, detection engineering — rolling out gradually.

The practical question for CISOs isn’t whether Astra-class models will eventually be able to do this work at scale — it’s how much lead time defenders get before that capability becomes broadly accessible, including to less scrupulous actors running open or leaked derivatives.
If a frontier lab’s own testing shows a model discovering real zero-days, threat actors experimenting with less-restricted or open-weight models will get there too, eventually. Patch velocity and exposure management matter more, not less.

If you are evaluating agentic AI tools for internal use — code review, pentesting, SOC automation — ask vendors directly whether the underlying model has crossed a similar threshold and what safeguards travel with it in your deployment, not just in the vendor’s own product.

Leave A Reply

Your email address will not be published.