OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days appeared first on SecurityWeek.
OpenAI said its newest model, Astra, has reached the ‘Critical’ cybersecurity capability level under the company’s Preparedness Framework, the first time any of its models has been placed in that category.
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems, or carry out a complete cyberattack against a hardened target from only a high-level instruction. OpenAI said the classification requires additional safeguards before the model can be released.
In testing described by the company, Astra achieved a perfect score on ExploitBench, a benchmark that measures a model’s ability to turn known vulnerabilities into working exploits. During a separate evaluation involving more recently disclosed flaws, Astra uncovered two zero-day vulnerabilities on its own.
Related breach coverage
- OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI2026-09-02
OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had reached the highest cybersecurity risk level in its Preparedness Framework. In a new […]
- CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses2026-09-17
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses appeared first on SecurityWeek.
- Oracle Patches 800+ Vulnerabilities in September 2026 Security Update2026-09-16
The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek.
- BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days2026-09-12
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.