Tech News

OpenAI Releases a Restricted GPT-6 Astra Model Built for Cyber Defenses

OpenAI has unveiled GPT-6 Astra, billed as its smartest model yet. On the cyber side, the public version is deliberately restricted, and that is probably a good thing (just like with Mythos 5). Here is what you need to know.

OpenAI had warned us for several days: GPT-6 Astra had reached a critical threshold in cybersecurity. In other words, OpenAI believes Astra is capable of identifying and developing exploits for zero-day vulnerabilities. That explains why the version intended for the general public is restricted, to avoid things spiraling out of control.

Where did this Astra model come from? Let’s go back a bit to get a clue. Remember, last July, OpenAI admitted that GPT-5.6 Sol and a preview model had escaped a cyber test to hack Hugging Face during a cyber exercise. That preview model, whose name had not been disclosed at the time, may well be Astra. OpenAI did not confirm this in its announcement, but it could be the case. That incident seems to have taught OpenAI a lesson, and Astra has been locked down so it cannot go beyond its authorized perimeter.

Cyber scores that are seriously impressive

GPT-6 Astra is OpenAI’s new AI showcase. More importantly, it is a concrete sign that OpenAI is still in the race, even if Anthropic is also performing strongly. On the GPT-6 Astra presentation page, OpenAI details the results achieved by this model (without production safeguards). And they are, frankly, impressive.

  • ExploitBench. This benchmark measures a model’s ability to turn a known vulnerability into a working exploit. Astra reaches 100%, compared with 78.5% for GPT-5.6 Sol, its predecessor. Pretty formidable.
  • ExploitGym. On this longer, multi-step test, Astra achieves a 42.4% success rate, compared with 30.3% for Sol, while using significantly fewer tokens.
  • SRE-Bench. In binary reverse engineering, with no source code available, Astra solves 88% of tasks on the first try and 99.2% within four attempts, compared with 55.9% and 68.7% for Sol.

OpenAI also states: "Astra even discovered and exploited two previously unknown zero-day vulnerabilities". Disclosure of these vulnerabilities is currently underway with the affected vendors. At the same time, tests carried out by cybersecurity experts using an unrestricted version of Astra show that it is capable of:

  • Exploiting unknown flaws to achieve code execution in hardened browsers.
  • Creating exploits that enable privilege escalation on hardened operating systems.

Incredible.

A deliberately restricted public model

As you might expect, this is not the version arriving in ChatGPT. And thankfully so, because it would be a real problem: it is easy to imagine it being used for more than just defensive purposes. The public release launched on September 3 and is limited to code analysis and patch writing. Which is already very useful. According to OpenAI, Astra will refuse requests to create proof-of-concept (PoC) exploits for vulnerabilities.

Over the next few weeks, some people will be able to access a slightly less restricted version for specific tasks. That is reminiscent of what OpenAI did with one of its previous models: GPT-5.4-Cyber.

OpenAI is adding another layer of production monitoring: a classifier system inspects the model’s reasoning and actions, then automatically interrupts any activity deemed unauthorized. In ChatGPT and Codex, the user will be prompted to confirm the action before continuing. In the API, the task simply stops.

Alongside the launch of GPT-6 Astra, OpenAI announced Daybreak for Frontline Defenders, a $1 billion commitment to subsidize access to its cyber models for operators of critical infrastructure (water, electricity, local governments, regional banks, open source maintainers).

OpenAI’s announcement is available on this page. You will find more details on all the benchmarks performed there.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.