StratosAlly – Cybersecurity for digital safety

GPT-6 Astra Is Changing the Cybersecurity Game

OpenAI’s newest AI model, GPT-6 Astra, is showing just how quickly artificial intelligence is moving from assisting cybersecurity researchers to potentially doing parts of their job on its own.

The company’s latest model scored a perfect 100% on ExploitBench, a benchmark designed to evaluate how effectively AI systems can identify and exploit software vulnerabilities. That performance puts Astra well ahead of its predecessor, GPT-5.6 Sol, which scored 78.5% on the same benchmark.

But the benchmark score is not the most interesting part. During testing, Astra reportedly demonstrated the ability to discover previously unknown vulnerabilities, including two zero-day flaws, and turn those findings into working proof-of-concept exploits. OpenAI also found that, when operating without safeguards, the model could achieve code executionthrough previously unknown vulnerabilities in hardened browsers and develop privilege-escalation exploits against hardened operating systems.

That changes the conversation around AI-powered cybersecurity.

Until recently, AI security tools were largely viewed as assistants, useful for reviewing code, spotting suspicious patterns or helping researchers investigate vulnerabilities. Astra suggests a future where an AI system can potentially reason through a vulnerability, test different approaches and progress much further into the exploitation process with limited human guidance.

OpenAI has therefore classified Astra as its first model to reach the “Critical” cybersecurity capability threshold under its Preparedness Framework. The company says the model can, with the right tools and access, discover unknown security flaws and develop exploitation methods across well-protected systems without someone guiding every step.

And that capability comes with an obvious problem: the same technology that can help defenders find vulnerabilities faster could also make attacks easier to automate.

For that reason, OpenAI is taking a cautious approach to Astra’s release. The initial version is restricted to defensive activities such as secure code review and vulnerability patching, and it blocks requests to create proof-of-concept exploits. OpenAI says its Daybreak program will eventually provide trusted testers with broader defensive capabilities, including vulnerability and PoC validation, malware analysis and detection engineering.

Cybersecurity is only one part of Astra’s capabilities. OpenAI says the model also reaches state-of-the-art performance in computer use, coding, science and professional workflows. It scores 98% on FrontierMath Tier 4, 99.9% on ARC-AGI-3, and can complete complex computer-use tasks significantly faster than its predecessor.

The bigger takeaway is simple: AI is no longer just helping cybersecurity teams look for problems. Increasingly, it is learning how to find them itself.

And as models become better at discovering vulnerabilities, the race between automated defense and automated exploitation is only beginning.

Let’s refine your stalking skills; go through our Instagram and LinkedIn.

more Related articles