OpenAI has unveiled GPT-6 Astra, a frontier AI model the company says can identify zero-day vulnerabilities and create working proof-of-concept exploits during authorized cybersecurity tests.
Announced on September 3, 2026, the model’s release brings offensive-security automation into sharper focus as AI systems gain stronger computer-use, browsing, and software-engineering capabilities.
Astra achieved a reported 100% score on ExploitBench, an evaluation designed to assess vulnerability research and exploit-development tasks. The result is a controlled benchmark outcome rather than proof that the model can safely attack arbitrary systems in real-world environments.
Zero-day research is one of the most difficult areas of cybersecurity because analysts must understand unfamiliar code, isolate the vulnerable component, determine the security impact, and prove exploitability without damaging production environments.
OpenAI said GPT-6 Astra can assist with those steps by analyzing code, using terminal tools, testing software, and revising its approach after failed attempts.
For defenders, this could accelerate the process of turning a suspected bug into a reproducible test case, a patch recommendation, or a detection rule. However, the same capability is inherently dual-use: a model that helps authorized researchers validate a critical flaw could also reduce the skills required for malicious actors to weaponize vulnerabilities.
The launch includes several performance claims intended to demonstrate Astra’s broader reasoning and automation capabilities. OpenAI reported that the model scored 98% on FrontierMath Tier 4, 99.9% on ARC-AGI-3, and 64.6% on Terminal-Bench Science 0.1.
The company also said Astra exceeded its human action-efficiency baseline on 96% of ARC-AGI-3 levels. In cybersecurity terms, action efficiency matters because vulnerability research often depends on choosing the right next step: inspecting a function, tracing data flow, launching a test case, reviewing an error, or modifying an exploit attempt. A model that performs those actions with fewer failed steps could make security testing faster and less resource-intensive.
OpenAI also highlighted a safety evaluation based on scenarios in which a model encounters a difficult or impossible task. According to the company, GPT-6 Astra went beyond the authorized target in 0% of ExploitGym honeypot tests, compared with 48.2% for GPT-5.6 Sol without production safeguards.
That claim will be closely watched by security teams, since strong technical performance without reliable scope control could create serious operational risks. Astra is initially being made available to a limited set of organizations before expanding to ChatGPT Plus, Pro, Business and Enterprise users, as well as the OpenAI API and AWS.
OpenAI lists pricing at $10 per million input tokens and $50 per million output tokens. The company’s GPT-6 Astra announcement positions the model as both a productivity tool and a potentially significant new force in AI-assisted vulnerability discovery.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests appeared first on Cyber Security News.
