OpenAI’s Astra crosses Critical cybersecurity threshold | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


OpenAI says Astra has crossed the Critical cybersecurity capability threshold under its Preparedness Framework, becoming the company’s first model at that level. With the right tools and access, Astra can find unknown flaws and develop working exploits across hardened systems without a person directing every step. OpenAI plans to release it soon, but its strongest cyber capabilities will first go to a small group of alpha testers, with Daybreak Blue access following for wider defensive use.

OpenAI combined public and private benchmarks with expert-led tests. Astra scored 100% on ExploitBench and was substantially more capable and token-efficient than GPT-5.6 Sol in vulnerability discovery and exploit development. On an internal set of 20 recently disclosed high-severity V8 flaws, Astra delivered higher arbitrary-code-execution rates with far fewer output tokens. It also found two zero-days and used them in an exploit chain now being disclosed to maintainers. The results reflect Daybreak Blue access, not the default production setup.

In hands-on assessments, Astra built a browser compromise chain that escaped the sandbox and ran host commands when an HTML file was opened. It also combined flaws in a hardened operating system to escalate an unprivileged user to root. OpenAI says these results meet its Critical bar for zero-day exploitation across hardened systems or end-to-end attacks from a high-level goal.

OpenAI delayed parts of Astra’s training and release while adding refusals, safety classifiers, offline detection, threat disruption, cross-conversation context handling, and monitoring that can stop unauthorized activity. Astra refused 91.5% of requests in cyber jailbreak evaluations, versus 59% for GPT-5.6 Sol. In honeypot tests based on the Hugging Face incident, Astra did not target surrounding systems or try to bypass auto-review denials.

For OpenAI, Astra is an early test of how its Preparedness Framework governs models capable of consequential work. The company says advanced access will expand cautiously as red-teaming, regression testing, and 24/7 response continue. Chain-of-thought monitoring will examine reasoning and actions for unauthorized behavior, while legitimate tasks may be slowed, paused, or stopped in ChatGPT, Codex, or the API. A system card at launch will provide more detail on Astra’s safety, security, alignment, and evaluations.

Source



——————————————————-


Click Here For The Original Source.