OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI
OpenAI says its newest AI model, Astra, can find unknown security flaws in well protected software and build working exploits for them largely on its own. OpenAI now rates Astra at the highest risk level in its own safety framework, the first model it has ever put in that category.
- Report priority
- High
- Victim
- OpenAI
What is known
OpenAI's internal safety rules say a model crosses the top risk line if it can independently discover and weaponize unknown bugs across many hardened systems, or plan and carry out a full attack from just a high level goal, without a person walking it through each step, and OpenAI's testing showed Astra clearing that bar.
What to do
Watch for OpenAI's promised disclosures to the developers of the two software products where Astra found new flaws, and for the added safeguards OpenAI says it is putting around Astra's release.
Reported details
OpenAI ran Astra against a fresh set of Chrome's V8 engine bugs disclosed between June and August 2026, deliberately excluded from its training data so it could not have simply memorized the answers. Astra reached working code execution far more often than OpenAI's GPT-5.6 Sol model while using far fewer tokens to get there. During that same testing, Astra also turned up two brand new, previously unknown bugs on its own while stitching together a working exploit chain, and OpenAI is now working with the affected software's developers to get them fixed.
OpenAI's Preparedness Framework, published in 2023, defines a 'Critical' cybersecurity tier that a model reaches if it can autonomously discover and develop zero-day exploits against many well-defended real-world systems, or independently plan and execute a full attack chain from a high-level goal. OpenAI says Astra meets this bar. On ExploitBench, a benchmark for turning known vulnerabilities into working exploits, Astra scored 100%. On a separate, training-data-excluded benchmark built from V8 vulnerabilities disclosed June to August 2026, Astra beat GPT-5.6 Sol on code-execution success while using fewer tokens, and surfaced two previously unknown zero-days during exploit-chain construction.
References
- openai.com · updating-our-preparedness-framework SecurityAffairs
- openai.com · path-to-astra SecurityAffairs
- i0.wp.com · image-6.png SecurityAffairs
- infosec.exchange · @securityaffairs SecurityAffairs
- securityaffairs.co · wordpress SecurityAffairs
- bleepingcomputer.com · ransomware-protection-for-msps-a-6-point-checklist-for-faster-recovery BleepingComputer
- unit42.paloaltonetworks.com · sdlc-supply-chain Unit 42
- socket.dev · microsoft-teams Socket
- docs.socket.dev · notifications Socket
- sonatype.com · hugging-face-security-incident-a-new-class-of-threat-is-here Sonatype
- huggingface.co · security-incident-july-2026 Sonatype
- snyk.io · snyk-agent-fix-remediation-benchmark Snyk
- stepsecurity.io · arrayref-rust-crate-supply-chain-attack StepSecurity
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1033 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1063 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1076 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1096 CERT-FR Advisories
- cert.ssi.gouv.fr · CERTFR-2026-AVI-1097 CERT-FR Advisories
- acn.gov.it · rilevate-nuove-vulnerabilita-in-langflow ACN CSIRT Italy
- acn.gov.it · rilevata-vulnerabilita-in-prodotti-cpanel-1 ACN CSIRT Italy
- acn.gov.it · rilevate-vulnerabilita-in-prodotti-mongodb-3 ACN CSIRT Italy
- acn.gov.it · sanata-vulnerabilita-in-grafana-alloy ACN CSIRT Italy
- acn.gov.it · aggiornamenti-di-sicurezza-sanano-molteplici-vulnerabilita-in-servicenow ACN CSIRT Italy
- acn.gov.it · risolte-vulnerabilita-in-prodotti-spring-5 ACN CSIRT Italy
- acn.gov.it · ee-21 ACN CSIRT Italy
- acn.gov.it · rilevato-sfruttamento-di-vulnerabilita-in-gitea ACN CSIRT Italy
- acn.gov.it · risolte-vulnerabilita-in-prodotti-nvidia-2 ACN CSIRT Italy
- security.gentoo.org · 202608-19 Gentoo Advisories
- security.gentoo.org · 202608-17 Gentoo Advisories
- security.gentoo.org · 202608-16 Gentoo Advisories
- security.gentoo.org · 202608-15 Gentoo Advisories
- security.gentoo.org · 202608-05 Gentoo Advisories
- cyber.gc.ca · veeam-security-advisory-av26-855 CCCS Canada
- veeam.com · kb4902 CCCS Canada
- veeam.com · kb4905 CCCS Canada
- veeam.com · knowledge-base.html CCCS Canada
- cyber.gc.ca · sonicwall-security-advisory-av26-853 CCCS Canada
- psirt.global.sonicwall.com · SNWLID-2026-0013 CCCS Canada
- psirt.global.sonicwall.com · vuln-list CCCS Canada
- thehackernews.com · threatsday-ceo-phishing-kits-5k-dropbox.html TheHackerNews