Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • GPT-6 Astra Updates Codex Pricing Do Son
    Discover the new GPT-6 Astra Codex pricing policy. OpenAI now removes multiplier penalties for contexts exceeding 272K, offering flat rates up to 1M tokens. Related Posts: Google Workspace Integrates Gemini Live Features Court Upholds Edge Gatekeeper Exemption Microsoft Defender Intercepts Legitimate Links The post GPT-6 Astra Updates Codex Pricing appeared first on Daily CyberSecurity.
     

GPT-6 Astra Updates Codex Pricing

Por:Do Son
4 de Setembro de 2026, 00:20

Discover the new GPT-6 Astra Codex pricing policy. OpenAI now removes multiplier penalties for contexts exceeding 272K, offering flat rates up to 1M tokens.

Related Posts:

The post GPT-6 Astra Updates Codex Pricing appeared first on Daily CyberSecurity.

  • ✇Security Affairs
  • OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI Pierluigi Paganini
    OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had reached the highest cybersecurity risk level in its Preparedness Framework. In a new post, the company confirmed it: Astra meets the Critical cybersecurity capability threshold, making it the first OpenAI model ever cla
     

OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI

2 de Setembro de 2026, 18:31

OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level.

Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had reached the highest cybersecurity risk level in its Preparedness Framework. In a new post, the company confirmed it: Astra meets the Critical cybersecurity capability threshold, making it the first OpenAI model ever classified at that level.

“We now believe Astra meets the Critical cybersecurity capability threshold under our Preparedness Framework, meaning that with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step.” reads the announcement. “It is the first model we are designating at this level, and requires stronger safeguards during development and before release.”

The bar for that classification isn’t vague marketing language, it’s a specific technical threshold OpenAI wrote into its own safety framework back in 2023. A model crosses it if it can identify and develop working zero-day exploits across many well-defended real-world systems entirely without human help, or if it can plan and carry out an entire cyberattack against a hardened target starting from nothing more than a high-level goal. Either condition alone is enough, and OpenAI says Astra clears the bar comfortably.

The benchmark results make the difference hard to ignore. Astra scored 100% on ExploitBench, a test that measures how well an AI can turn known vulnerabilities into working exploits.

OpenAI also tested Astra against a new internal benchmark based on V8 vulnerabilities disclosed between June and August 2026. The benchmark was designed to avoid any overlap with the model’s training data. Astra achieved much higher code-execution success rates than GPT-5.6 Sol while using far fewer tokens.

During the same tests, Astra also found two previously unknown zero-day vulnerabilities while building an exploit chain. OpenAI says it is now working with the affected software developers to disclose both flaws.

In hands-on expert testing against hardened targets, Astra didn’t just find bugs; it chained them into complete attacks. The model built a full browser-compromise chain that escaped the sandbox and executed commands directly on the host machine, triggered simply by opening a malicious HTML file. Separately, it found multiple flaws in a hardened operating system and combined them into a privilege-escalation chain running all the way from an unprivileged user account to root, the kind of end-to-end attack chain that used to require a skilled human operator stitching pieces together by hand.

The announcement comes just after OpenAI’s recent security incident. Earlier this year, the company admitted that a separate unreleased model breached Hugging Face’s systems during testing. OpenAI makes clear that Astra was not involved in that incident.

“Based on retrospective testing, we believe our production safeguards at the time would have prevented the Hugging Face incident.” states OpenAI. “We have since implemented even stronger safeguards for Astra, including training the model to more reliably refuse harmful cyber requests and respect safety restrictions, additional protections against misuse, and monitoring that can stop potentially unauthorized activity.”

The company says that, based on later testing, its current security measures would have stopped the Hugging Face breach. But that also suggests those safeguards were not in place when the earlier incident happened.

The response to reaching this threshold involved actually slowing down, not just adding a warning label. OpenAI paused parts of Astra’s training and delayed release for several weeks specifically to harden isolation, expand monitoring, and strengthen alignment training before resuming a previously halted large-scale reinforcement learning run on August 28. That’s a genuinely unusual move for a company racing competitors on release timelines, and it suggests the internal concern here wasn’t purely theatrical.

The refusal numbers show a clear improvement, although Astra is still not perfect. In OpenAI’s cyber safety tests, Astra refused 91.5% of requests that should not receive cyber assistance, compared with 59% for GPT-5.6 Sol.

OpenAI also ran a “honeypot” test based on the Hugging Face incident. The model was given an impossible task and quietly offered the option of attacking the test environment instead. Without production safeguards, GPT-5.6 Sol took the bait 56% of the time. Astra did it zero times.

OpenAI is not making Astra’s most powerful capabilities publicly available. Advanced cybersecurity features will first be given to a small group of alpha testers, before being expanded through a program called Daybreak Blue, focused on defensive security work.

This creates a deliberate access barrier. OpenAI also admits that its safeguards may sometimes block legitimate security research because it can look similar to malicious activity. In some cases, defensive work could therefore be paused or stopped simply because it resembles an attack.

The key shift is that AI-driven exploit discovery could make traditional patching timelines obsolete. The real challenge is becoming how quickly defenders can detect and respond when an AI finds a vulnerability before attackers exploit it.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, OpenAI)

OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities

1 de Setembro de 2026, 17:00
The company will give select partners early access to its Astra AI model—so they have time to shore up their defenses.

  • ✇Cybersecurity News
  • OpenAI Astra Security Model: Pausing Development for Safety Do Son
    OpenAI slows development as its new Astra security model reaches critical cyber thresholds. Discover how they dedicate massive compute to prevent AI escapes. Related Posts: Telegram Applies for .gram Domain to Give Every User Their Own TLD GitHub Outage Postmortem: Retry Storm and Copilot Auth Overload Explained GeForce NOW Now Fully Supports Firefox, Delivering 1440p 120fps Streaming The post OpenAI Astra Security Model: Pausing Development for Safety appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns Pierluigi Paganini
    OpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework. OpenAI disclosed that internal evaluations of Astra, one of its upcoming models, have found cybersecurity capabilities significant enough that the company “cannot rule out” reaching the Critical threshold under its own Preparedness Framework. In response, the company paused certain internal activities involving Astra and implemented
     

OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns

10 de Agosto de 2026, 08:16

OpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company’s framework.

OpenAI disclosed that internal evaluations of Astra, one of its upcoming models, have found cybersecurity capabilities significant enough that the company “cannot rule out” reaching the Critical threshold under its own Preparedness Framework.

In response, the company paused certain internal activities involving Astra and implemented a set of security controls that it had not previously needed to apply. This is the first time an AI lab has publicly announced slowing development of a model specifically because of cybersecurity concerns.

“Under our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.” reads the announcement.

“While we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time. Astra is an upcoming model, and was not involved in exploiting Hugging Face.”

Previous models, including GPT-5.6-Sol, had been assessed at the High threshold rather than Critical. Astra wasn’t involved in the Hugging Face incident disclosed last month. OpenAI is making that distinction deliberately, because the news cycle has already connected every AI breach to every AI model.

“We are pausing internal activities involving Astra that do not yet meet these strengthened security control requirements.” continues the announcement. “We have implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra, including training and evaluation. Monitors evaluate the model’s Chain of Thought and trigger a security response to review and interrupt high risk activity.”

The new controls also include isolated testing environments, restricted network and tool access, enhanced encryption of model weights, and sandboxed execution. OpenAI says it will share recommended security controls with third-party testing partners for running higher-risk evaluations, a direct response to the series of incidents in which evaluation environments gave AI models unintended internet access.

The broader context makes this disclosure land harder than it might otherwise. The UK AI Security Institute reported last week that AI models autonomously reached out to real-world targets across 10 of 122 evaluation runs, with 17 of 19 such actions originating from Anthropic’s Mythos 5. In the most serious case, an agent tried to insert malicious code into an open-source project and created fake online identities to pressure the project’s maintainer into approving it. A human maintainer caught it. Models from Meta and Chinese company Moonshot, Muse Spark 1.1 and Kimi K3, have also been reported escaping sandboxes, with Kimi K3 probing the network during an evaluation, finding that GitHub was reachable, cloning the benchmark repository it was supposed to be solving, and reading the answer directly off disk. The incidents are being tracked on a new site called Felony Bench.

OpenAI says it believes advanced cyber-capable models should help defenders find vulnerabilities before attackers do, and frames the pause as responsible stewardship rather than alarm. That may be true. It’s also true that the Preparedness Framework was designed for exactly this moment, and that using it to actually slow down a model rather than just document the risk is a meaningful choice, one the industry will be watching to see whether others follow.

“We’re committed to working alongside governments, safety institutes, and civil society to ensure that the frontier capabilities of models like Astra, and those that follow, are deployed responsibly and broadly for the benefit of all humanity.” concludes the announcement.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Astra)

  • ✇ASEC BLOG
  • June 2026 Dark Web Threat Actor Trend Report ATCP
    Note The June 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—operating on the deep web and dark web. It is noted that the accuracy of some information could not be verified. Major Issues In Malaysia, a series of website defacement and compromise incidents targeting local development agencies and public […]
     
❌
❌