OpenAI says its next model Astra is the first to hit "Critical" cybersecurity capability.
That means it can find zero-day vulnerabilities and build working exploits across hardened systems without human guidance.
"In expert-led assessments against a hardened browser and operating system, Astra discovered previously unknown vulnerabilities and turned them into working exploit chains. It built a full browser-compromise chain that escaped the sandbox and executed commands on the host."
In testing, Astra scored 100% on ExploitBench and discovered two actual zero-days during evaluation. OpenAI delayed parts of development after the Hugging Face agent hack, paused frontier training for two weeks, and hardened its training infrastructure.
On jailbreak resistance, Astra refuses 91.5% of disallowed cyber requests vs 59% for the previous model.
Access to advanced cybersecurity capabilities will initially be limited to a small group of testers.
https://openai.com/index/path-to-astra/












