Wire Observer.
Technology

OpenAI Claims New Astra Model Can Autonomously Find and Exploit Zero‑Day Vulnerabilities

OpenAI Claims New Astra Model Can Autonomously Find and Exploit Zero‑Day Vulnerabilities

OpenAI announced that its upcoming Astra artificial‑intelligence system has met the company’s internal "Critical cybersecurity capability" benchmark, a threshold that signals the model can independently identify previously unknown software flaws and generate functional exploits when supplied with the necessary tools and system access.

The company says internal evaluations demonstrated Astra’s ability to locate zero‑day vulnerabilities in hardened environments and to produce working proof‑of‑concept code that could bypass existing defenses. Reaching the critical threshold, according to OpenAI, marks a shift from using AI merely as an assistant for code review to a system capable of full‑cycle offensive security research.

This development arrives amid a broader surge of interest in AI‑driven security tools. Earlier iterations of OpenAI’s technology, such as ChatGPT, have been employed for code generation and vulnerability scanning, but they required extensive human guidance. Astra, by contrast, is described as capable of operating with minimal supervision, a capability that both excites defensive researchers and raises alarms about potential misuse.

Security experts have offered mixed reactions. Some see the model as a powerful asset for penetration‑testing teams and bug‑bounty programs, arguing that an AI that can rapidly surface hidden weaknesses could accelerate patch cycles. Others warn that the same capability could be weaponized by malicious actors, especially if the model were to be leaked or released without stringent safeguards.

OpenAI acknowledges the dual‑use nature of the technology and says it is implementing layered access controls, usage monitoring, and a phased rollout strategy designed to limit exposure. The firm also notes that Astra will initially be available only to vetted partners under strict contractual terms, and that it is working with industry groups and policymakers to shape responsible deployment guidelines.

Looking ahead, OpenAI plans to collaborate with cybersecurity firms to integrate Astra into controlled testing environments, hoping to demonstrate its defensive value while gathering data on potential abuse vectors. If successful, the model could reshape how organizations approach vulnerability management, but it will also likely intensify calls for clearer regulation of AI systems that possess offensive cyber capabilities.

Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related