TechNewsReel
Live

OpenAI's Astra Model Hits 'Critical' Cyber Rating After Finding Zero-Days

The new model can autonomously discover software flaws and execute full exploit chains, prompting OpenAI to delay development for safety.

TechNewsReel Newsroom · September 2, 2026

OpenAI has announced that its upcoming Astra model is the first in the company's history to receive a "Critical" cyber capability rating under its Preparedness Framework. The model demonstrated the ability to autonomously discover zero-day software flaws and develop working exploits without human intervention.

In standardized testing, Astra scored 100% on ExploitBench, a benchmark designed to measure the ability to create exploits from known vulnerabilities. More alarmingly, during internal exploit chain tests, Astra discovered two previously unknown zero-day vulnerabilities. The model further proved its potency by successfully escaping a hardened browser sandbox to execute commands on a host computer and combining multiple operating system flaws to escalate privileges from an unprivileged user to root access.

The Shift to Autonomous Problem Solving

The emergence of Astra occurs as frontier AI models transition from simple text generation toward complex, multi-step problem solving. This trend is evident across the industry, where models are increasingly capable of tackling long-standing technical challenges. However, in the cybersecurity domain, this evolution is viewed with higher scrutiny. Researchers express growing concern that AI could compress the time required to identify and exploit software misconfigurations from several weeks down to a matter of seconds.

Implications for Global Security

The ability of an AI to execute the entire lifecycle of a cyber attack—from the initial discovery of a zero-day to gaining full root access—marks a fundamental shift in the digital threat landscape. This capability is particularly perilous for the cryptocurrency sector, where software vulnerabilities can be exploited for immediate financial gain. Because these attacks can occur at machine speed, they potentially outpace the ability of human defenders to respond or patch systems in real time.

Safeguards and Next Steps

In response to these findings, OpenAI has delayed portions of Astra's development to implement additional safety safeguards. The company has also confirmed that advanced security features will be restricted to a small group of selected testers rather than a general release. While the model's offensive capabilities are now confirmed, the industry remains watchful for how these tools will be gated and whether similar autonomous capabilities will emerge in other frontier models.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.