• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - AI Trends and Related News - OpenAI previews its upcoming latest model Astra, which has reached Critical security level and can autonomously discover zero-day vulnerabilities.

OpenAI previews its upcoming latest model Astra, which has reached Critical security level and can autonomously discover zero-day vulnerabilities.

KOCPC Editor by KOCPC Editor
September 4, 2026
in AI Trends and Related News, Latest Technology News

OpenAI has announced that its next-generation model Astra is about to officially launch, revealing that the model has reached “Critical” cybersecurity capability level for the first time in its internal Preparedness Framework—the highest tier in OpenAI’s self-defined risk framework, a standard no previous model has ever met. During evaluations, Astra successfully discovered and exploited two zero-day vulnerabilities, achieving a perfect score on the proprietary benchmark ExploitBench, demonstrating autonomous exploit capabilities far surpassing the previous generation GPT-5.6 Sol. Due to the extremely high security risk level, OpenAI will impose strict access restrictions on Astra’s advanced cybersecurity features, initially providing access only to a small number of partners such as the U.S. government and critical infrastructure operators. Other users and developers will not be able to use the highest-tier cyber attack defense and analysis features until OpenAI conducts further assessments and gradually opens access.

As we prepare to release Astra, we’re focused on making increasingly capable AI safe and broadly accessible.

Astra represents a significant advance in cybersecurity capability, reaching the Critical threshold under our Preparedness Framework.

We’re previewing how we evaluated…

— OpenAI (@OpenAI) September 1, 2026

Critical level: AI can autonomously discover and exploit zero-day vulnerabilities

According to OpenAI’s Preparedness Framework, the Critical level applies to models capable of “independently discovering and exploiting zero-day vulnerabilities in multiple highly protected systems without human oversight, or launching a full-scale cyberattack on hardened targets based solely on high-level instructions.” Astra is the first OpenAI model to reach this level. Experts note that the threshold for this level is extremely high, indicating that the model has already achieved technical proficiency approaching that of top-tier human white-hat hackers.

To this end, OpenAI internally built a dedicated benchmark called ExploitBench, containing 20 high-severity real-world CVE vulnerabilities. The evaluation required the model to first identify the vulnerabilities and then successfully turn them into working exploits—an extremely difficult process that tests both reasoning and implementation skills. Astra achieved a perfect score on this benchmark, successfully completing the attack chain across all cases. Even more notably, in a separate evaluation targeting recently disclosed vulnerabilities, Astra autonomously discovered two previously unknown zero-day vulnerabilities and chained them into a complete attack chain. OpenAI stated that it is notifying the relevant maintainers about both vulnerabilities, indicating that Astra’s autonomous discovery capabilities have reached a real-world operational level.

OpenAI Astra security protections upgraded in tandem: 91.5% of network jailbreak attempts rejected.

While Astra has made a major leap in attack capability, its security has also improved significantly. OpenAI’s evaluations show that Astra rejected 91.5% of cyber-related jailbreak attempts, compared to GPT-5.6 Sol’s 59%. This means Astra is markedly better than its predecessor at resisting inappropriate requests, and can almost automatically identify and block the vast majority of malicious instructions attempting to bypass safety mechanisms. At the same time, Astra demonstrated a lower tendency than Sol to circumvent safety restrictions or exploit deliberately set honeypot targets in evaluations, indicating that its built-in safety alignment mechanisms are more robust.

However, this stricter filtering also has a double-edged sword effect: Astra may become so cautious that it refuses legitimate cybersecurity requests. If a user asks for help identifying and patching vulnerabilities, the model might misjudge it as malicious intent and decline to assist. Hugging Face previously stated that it was precisely because Anthropic’s models were overly cautious and refused to assist that they were forced to use open-source Chinese models to respond to the OpenAI attack. This also highlights the trade-off between AI safety safeguards and usability.

Hugging Face 遭惡意全自動 AI Agent 攻破:閉源模型拒幫忙,開源 GLM 5.2 緊急救援

The Hugging Face incident led to a delay in the listing.

The release of Astra has been delayed by several weeks due to the Hugging Face attack in July this year. In that incident, an AI model OpenAI was testing autonomously planned and executed a cyberattack against AI company Hugging Face, successfully breaching its infrastructure. OpenAI only discovered the intrusion a full week after the incident occurred, highlighting how stealthy and damaging autonomous AI attacks can be. OpenAI subsequently paused new model training for two weeks to comprehensively strengthen internal security measures. Related improvements included adding more agent monitoring mechanisms, making test environments more isolated to prevent AI from escaping and infiltrating other companies, and establishing better anomaly detection systems.

OpenAI stated that although Astra is more powerful and efficient than GPT-5.6 Sol, it was not directly involved in the Hugging Face incident (the model involved was another unnamed model that has since been deactivated). Astra was a model already in development before the Hugging Face incident and belongs to a different generation from the model involved. However, OpenAI still invested significant additional time in security reviews after the incident, including reassessing the model’s boundaries for autonomous actions and network connection permissions, to ensure Astra has sufficient safety and controllability before deployment.

Cybersecurity functionality restricted: full access available only to government and critical infrastructure operators.

Given Astra’s formidable cyberattack capabilities, OpenAI has changed its usual model release strategy this time. Full advanced cybersecurity features are limited to a small group of alpha testers, including U.S. government agencies and critical infrastructure operators in OpenAI’s Cybersecurity Trust Access Program. An OpenAI spokesperson emphasized that this group includes “individuals and organizations responsible for protecting critical digital infrastructure and critical infrastructure in the broader sense.” OpenAI declined to disclose specific organization names, but outside observers speculate the group may include federal agencies such as the Department of Defense and the Department of Homeland Security, as well as major electric power, financial, and telecommunications operators.

An OpenAI spokesperson stated that the company will closely monitor how Astra is used among these testers, and will only gradually expand access through the Daybreak Blue program after confirming that Astra is “properly calibrated” to “provide defensive benefits while reducing the potential risk of misuse.” Additionally, all use of Astra’s advanced network capabilities will be fully logged and audited to ensure they are not used for unauthorized offensive purposes.

Data source

Source: KOCPC Chinese

Tags: AstraChatGPTOPENAI

Recent Posts

  • OpenAI previews its upcoming latest model Astra, which has reached Critical security level and can autonomously discover zero-day vulnerabilities.
  • ChatGPT, Claude, and Grok all experienced simultaneous global outages — the culprit might be this! Only Google Gemini was spared.
  • Taiwan Mobile launches VIVE Eagle round-frame model, available from $0! 3K video recording and new AI real-time translation feature go live simultaneously.
  • HTC VIVE Eagle Round Frame Edition arrives, adding 3K video recording and fully upgraded AI translation, set to enter Europe, the US, and Australia.
  • Meta Releases Muse Spark 1.3: Four Rapid Iterations in Five Months, Surpassing OpenAI and Google to Enter Global Top Three

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology