GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
- ID
- 21407
- Status
- summarized
- Published
- 04 Sep 2026, 2:47 PM
- Fetched
- 04 Sep 2026, 4:34 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/gpt-6-astra-scores-100-on-exploitbench.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 04 Sep 2026, 4:34 PM
- Tags
- Audience
- developersai_ml_learnersai_agent_userssaas_founders
What happened
OpenAI unveiled GPT-6 Astra, which scores 100% on ExploitBench (up from 78.5% for GPT-5.6 Sol), 99.9% on ARC-AGI-3, and 98% on FrontierMath Tier 4. The model reached OpenAI's 'Critical' cybersecurity capability threshold, can develop working exploits from zero-day vulnerabilities including in hardened browsers and OSes, but the released version is restricted to secure code review and patching only—refusing PoC exploit creation. Broader access via OpenAI Daydream will roll out less restrictive safeguards in coming weeks.
Why it matters
If you build with OpenAI APIs via Azure or AWS Bedrock, GPT-6 Astra is coming to your stack and its defensive security capabilities (code review, patching) are available now while offensive capabilities are gated. The 100% ExploitBench score means the model can autonomously turn known CVEs into working exploits—decide now whether your organization's AI usage policy needs updating before less restrictive safeguards roll out via OpenAI Daybreak. For SaaS founders handling vulnerability disclosure or security tooling, this model's capabilities reshape what AI-assisted security workflows can do.
Discussion angle
The tension between OpenAI crossing its own 'Critical' cybersecurity threshold and still shipping the model—with offensive capabilities merely gated rather than removed. What happens when less restrictive safeguards roll out via Daybreak, and should builders treat AI-assisted exploit generation as an assumed threat model now?