[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fABbi5f4X2PYLfZPjaDDXfwTgO03ZE444IyJRih5LtaY":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"ae094c11-ef0d-4d1c-bde4-2ac2c28f47ac","GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests","gpt-6-astra-scores-100-on-exploitbench-as-openai-blocks-poc-exploit-requests-09bf1e","OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the \"world's most intelligent and aligned model.\" The development comes days after the artificial intelligence (AI) company said the model had reached the \"Critical\" cybersecurity capability threshold under its Preparedness Framework. \"Astra is state-of-the-art on computer use, browsing, software engineering,","OpenAI has launched GPT-6 Astra, an AI model that scored a perfect 100% on ExploitBench, a test for developing exploits from software vulnerabilities. While the model demonstrated advanced capabilities in identifying and exploiting zero-day vulnerabilities, OpenAI has implemented safeguards to prevent its misuse for creating proof-of-concept exploits, limiting its current use to secure code review and patching.","OpenAI unveils GPT-6 Astra, achieving 100% on exploit development tests.","GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests Ravie LakshmananSep 04, 2026Artificial Intelligence \u002F Vulnerability OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the \"world's most intelligent and aligned model.\" The development comes days after the artificial intelligence (AI) company said the model had reached the \"Critical\" cybersecurity capability threshold under its Preparedness Framework. \"Astra is state-of-the-art on computer use, browsing, software engineering, cybersecurity, science, and professional work. Astra saturates FrontierMath Tier 4 with a 98% score,\" OpenAI said. \"Astra also saturates ARC-AGI-3 with a 99.9% score and ExploitBench with a 100% score. It also sets a new frontier on computer and browser use, handling the most demanding professional work with unmatched speed, accuracy, and judgment.\" The model is currently rolling out to a small set of organizations and is expected to be available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API, Microsoft Azure, and Amazon Web Services (AWS) Bedrock. On ExploitBench, which evaluates a model's ability to turn known software vulnerabilities into working exploits, Astra achieved a perfect score of 100%, as opposed to 78.5% for GPT‑5.6 Sol, its previous frontier cyber-capable model. OpenAI said the model also achieves substantially higher arbitrary code-execution rates than GPT‑5.6 Sol when testing its exploit development capabilities using flaws from the previous three months between July and August 2026. This included two zero-day vulnerabilities in unspecified software. Astra is also equipped to use previously unknown vulnerabilities to achieve code execution in hardened browsers and develop privilege-escalation exploits for hardened operating-systems, if allowed to run without any safeguards. Given the dual-use nature of these tools – the capabilities that can help defenders find weaknesses faster can also be abused by bad actors to exploit them more easily – OpenAI said the version of Astra being released is limited to secure code review and patching, while refusing to comply with prompts related to creating proof-of-concept (PoC) exploits for vulnerabilities. \"Through OpenAI Daybreak⁠, we plan to expand access and roll out less restrictive safeguards in the coming weeks,\" the AI upstart said. \"This will enable more defensive workflows, including vulnerability and proof-of-concept validation, malware analysis, and detection engineering.\" To address concerns about model misuse, OpenAI said it has included stronger model robustness to better tackle jailbreaks, more context to its monitoring systems, and extra safeguards to help detect and contain misalignment. Astra is also \"more likely\" to operate within the confines set by the user and implied by its environment, although it warned the safety checks can sometimes interrupt legitimate work, including defensive cybersecurity, at which point, the user will be prompted to review the action before continuing. \"In sensitive environments, Astra proceeds with care commensurate with its risk,\" the company added. \"In an evaluation of computer use tasks adversarially selected to elicit misbehavior, Astra was more successful at avoiding unintended consequences. Running with additional security measures offered by default yielded even stronger performance.\" The release of Astra comes as OpenAI launched a new initiative designed to provide subsidized access to its models, hands-on training, and technical assistance to critical infrastructure sectors, including water systems, electricity providers, state and local governments, banks, non-profits, open-source maintainers, and organizations with limited security resources. The global project, called Daybreak for Frontline Defenders, aims to commit $1 billion to help defenders use frontier AI cyber capabilities to safeguard essential services against cyber attacks. In tandem, the company has announced a new pilot with the U.S. Multi-State Information Sharing and Analysis Center (MS-ISAC) to equip an initial group of public sector and water system defenders with Daybreak access, guided training, and hands-on assistance. \"We have a defender's window: a narrowing opportunity to use AI to close security gaps before attackers seize them,\" OpenAI said. \"Our role is to help put powerful tools in defenders’ hands so they can protect the systems, and the people, they are responsible for.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, critical infrastructure, Vulnerability ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fgpt-6-astra-scores-100-on-exploitbench.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhbaZmLqqSMfwaOmjs47_PEd97T29HeDX_1dAOZn0Qzo0HuloopzzhZ7pnQzlsHvXvIAwzMWq1tbza325niZMSgjTMn0z5MyT-CWb7NfoprOWz2L_cj6tosVDyyp2ZbV4s59p-khE64lXWULLOW8zVMCv720iwDwCYUEuAHYkV8m2diDsyzFKwvNifzq-oT\u002Fs1600\u002Fgpt6.jpg","2026-09-04T06:47:52+00:00","2026-09-04T10:00:21.688973+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"GPT-6 Astra","product",{"name":22,"type":23},"OpenAI","vendor",{"name":25,"type":20},"GPT-5.6 Sol",{"name":27,"type":20},"ChatGPT Plus",{"name":29,"type":20},"ChatGPT Pro",{"name":31,"type":20},"ChatGPT Business","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":32,"icon":34,"name":35,"slug":36},null,"AI Security","ai-security",[38,43,45],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":44},{"id":32,"icon":34,"name":35,"slug":36},{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]