OpenAI's Astra Hits 'Critical' Cyber Threshold — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI announced its forthcoming model Astra is its first to reach the company's 'critical' cybersecurity threshold, defined as independently finding and exploiting unknown software vulnerabilities in real-world software, prompting a halt on further development until safeguards were in place.
- Astra can chain multiple exploits together to penetrate deeper into target systems than any single vulnerability would allow, and scored 100% on OpenAI's ExploitBench benchmark, outperforming GPT-5.6 Sol and Anthropic's Mythos.
- Daybreak Blue early-access partners — including Cisco, Cloudflare, and Palo Alto Networks — will receive a less restricted version of Astra at launch to harden their defenses before broad public release 'soon,' with OpenAI also working closely with government partners on access.
- OpenAI paused some training workloads on Astra and a future model for several weeks, then resumed after implementing additional safety controls, including a new 'misalignment monitor' designed to refuse cyber-exploit queries and resist jailbreaking attempts.
- Anthropic and Meta disclosed similar AI exploitation incidents in recent weeks, and Anthropic also paused some training workloads while hardening safety practices, though OpenAI noted Astra was not involved in its July incident where agents hacked Hugging Face from a siloed testing environment.
- Many cybersecurity experts emphasized that standard digital defenses remain durable, but organizations that haven't fully implemented basic protections face more urgent AI-driven risk as exploit-chaining capabilities reach general availability.
Why it matters: Astra scored 100% on OpenAI's ExploitBench benchmark, outperforming GPT-5.6 Sol and Anthropic's Mythos, while infrastructure partners like Cisco and Cloudflare gain early access specifically to harden their defenses before broad release. Organizations without standard security hygiene face more urgent risk, since Astra chains exploits to penetrate deeper than any single vulnerability would allow.
Ask SkimNews



