Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. 🔴 Critical: OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

🔴 Critical: OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
1 Posts 1 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    OpenAI has confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities. This places the model at a threshold where it can autonomously identify and analyze unknown vulnerabilities, commonly referred to as zero-days, without relying on pre-existing signatures or known exploit patterns.

    However, the same release notes a significant operational trade-off. The company states that while the model’s offensive security capabilities have advanced, its internal reasoning and tool-use processes are more opaque than previous iterations. This makes monitoring and auditing its actions more difficult, raising concerns about visibility for red teams and defensive security personnel who need to track what the model is doing in real time.

    Key points from the announcement include:

    • GPT-6 Astra can independently discover and validate exploit chains for previously unseen software flaws.
    • The model’s execution path is considered harder to interpret, complicating post-incident analysis and compliance logging.
    • OpenAI has not publicly released a specific CVE identifier or advisory number related to this capability, as no single vulnerability was referenced in the disclosure.
    • The "Critical level" designation implies the model can outperform human experts in certain constrained vulnerability research tasks, but the lack of interpretability is flagged as a risk for misuse or accidental damage.

    For defenders, this highlights a growing divide: AI that can find bugs faster than humans is valuable, but if you cannot see how it made a decision, you lose the ability to replicate, patch, or safely sandbox the discovery process.

    Source: BleepingComputer

    Given the reduced observability of GPT-6 Astra, is your security team prepared to handle AI-generated vulnerability reports that come without a clear reasoning trail?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World