OpenAI suspended work on Astra after internal evaluations showed it reached "critical cybersecurity threshold."
That means it can independently identify and carry out zero-day exploits against hardened real-world systems. No human help required.
This isn't a future capability. It's happening now in OpenAI's labs.
Under their own Preparedness Framework, "critical" means the model can pinpoint zero-day exploits of all severity levels and execute end-to-end novel attack strategies against hardened targets.
The previous model, GPT-5.6 Sol, only hit "high." Astra cleared it.
OpenAI paused all internal activities that don't meet stricter security controls. Isolated testing environments. Restricted network access. Enhanced model weight protections.
Sam Altman said they need "a little longer to do this safely."
Here's what this means for your security posture:
The offensive capability curve just outpaced your defensive baseline. If an AI lab's own model can autonomously find zero-days in hardened systems, your perimeter is already behind.
Audit your vulnerability management program today. If your patch cycle is measured in weeks, not hours, you're exposed to a threat class that didn't exist six months ago.
Your incident response playbook needs a model-capable adversary section. Now.
OpenAI just paused its next model. It can find zero-day exploits autonomously. Your CISO needs to see this.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments