OpenAI has unveiled GPT-6 Astra, which scored 100% on ExploitBench and reached its Critical cybersecurity capability threshold, while restricting proof-of-concept exploit requests and expanding defensive access through its $1 billion Daybreak for Frontline Defenders cybersecurity initiative.

OpenAI Unveils GPT-6 Astra With Perfect Score on ExploitBench Cybersecurity Test

The420.in Staff
5 Min Read

OpenAI has unveiled GPT-6 Astra, a new artificial intelligence model that the company says has reached its “Critical” cybersecurity capability threshold, after recording a perfect score on a benchmark designed to assess whether AI systems can turn known software vulnerabilities into working exploits.

The model scored 100% on ExploitBench, compared with 78.5% for GPT-5.6 Sol, its previous frontier cyber-capable model. OpenAI described Astra as its “world’s most intelligent and aligned model” and said it also achieved 98% on FrontierMath Tier 4 and 99.9% on ARC-AGI-3.

Astra is initially being rolled out to a small group of organisations. It is expected to become available to ChatGPT Plus, Pro, Business and Enterprise users, as well as through the OpenAI API, Microsoft Azure and Amazon Web Services Bedrock.

Perfect ExploitBench Score Highlights Cyber Capabilities

ExploitBench evaluates a model’s ability to convert known software vulnerabilities into working exploits. Astra achieved a 100% score on the benchmark, marking a substantial increase over the 78.5% recorded by GPT-5.6 Sol.

OpenAI said Astra also demonstrated substantially higher arbitrary code-execution rates when its exploit-development abilities were tested using flaws disclosed between June and August 2026. The testing included two zero-day vulnerabilities in unspecified software.

According to the company, Astra is capable of using previously unknown vulnerabilities to achieve code execution in hardened browsers and developing privilege-escalation exploits for hardened operating systems if allowed to operate without safeguards.

Those capabilities have prompted restrictions on how the model can be used. OpenAI said the version being released is limited to secure code review and patching and will refuse requests related to creating proof-of-concept exploits for vulnerabilities.

The company said it plans to expand access through OpenAI Daybreak and introduce less restrictive safeguards in the coming weeks. The broader defensive workflows are expected to include vulnerability and proof-of-concept validation, malware analysis and detection engineering.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

OpenAI Adds Safeguards Against Misuse

OpenAI said it has strengthened Astra’s resistance to jailbreaks and provided additional context to monitoring systems, alongside safeguards intended to detect and contain misalignment.

The company said Astra is more likely to operate within boundaries established by users and its environment. However, it acknowledged that safety checks may sometimes interrupt legitimate activity, including defensive cybersecurity work. In such cases, users can be prompted to review an action before proceeding.

OpenAI also said Astra performed better at avoiding unintended consequences in evaluations involving computer-use tasks deliberately selected to elicit misbehaviour. Additional security measures enabled by default produced stronger results, according to the company.

The restrictions reflect the dual-use nature of advanced cybersecurity capabilities. Tools capable of helping defenders identify and repair vulnerabilities more quickly can also potentially make those weaknesses easier to exploit if misused.

$1 Billion Initiative Targets Frontline Cyber Defenders

Astra’s release comes alongside a new OpenAI initiative aimed at expanding access to advanced AI cybersecurity capabilities for critical infrastructure and organisations with limited security resources.

The global project, called Daybreak for Frontline Defenders, aims to commit $1 billion to helping defenders use frontier AI cyber capabilities to protect essential services against cyberattacks. The initiative is designed to provide subsidised model access, hands-on training and technical assistance.

The programme covers sectors and organisations including water systems, electricity providers, state and local governments, banks, non-profits, open-source maintainers and groups with limited cybersecurity resources.

OpenAI has also announced a pilot with the U.S. Multi-State Information Sharing and Analysis Center to provide an initial group of public-sector and water-system defenders with Daybreak access, guided training and hands-on assistance.

The company said there is a narrowing opportunity for defenders to use artificial intelligence to close security gaps before attackers exploit them, positioning the new initiative as an effort to place more advanced cybersecurity tools in the hands of organisations responsible for protecting critical systems.

Follow the Centre for Police Technology on LinkedIn to stay updated on the latest developments in policing, cybersecurity, digital forensics, investigations, fraud risk management, and technology-driven public safety.

https://www.linkedin.com/company/policetechnology/

Stay Connected