Threat Intelligence

OpenAI's New GPT-6 Astra Can Hunt Exploits at Expert Level — Here's What SMBs Need to Know

The Hacker News · 4 Sept 2026
Key Takeaway Keep software patched promptly and don't assume 'security through obscurity' will protect unpatched systems — AI is making vulnerability discovery and exploitation faster for attackers everywhere.

OpenAI has officially released GPT-6 Astra, calling it its most intelligent and well-aligned model to date. The announcement follows OpenAI's own assessment that the model has reached the 'Critical' cybersecurity capability threshold under its internal Preparedness Framework — a designation reserved for AI systems capable of significantly amplifying both offensive and defensive cyber operations. As part of this, OpenAI says it is now blocking requests that ask the model to generate proof-of-concept exploit code.

The milestone reflects a broader trend: AI models are becoming highly capable at tasks like vulnerability discovery, software analysis, and automated exploitation research — skills that were once the domain of specialist security researchers. While this can help defenders find and fix flaws faster, it also lowers the bar for less-skilled attackers who might attempt to misuse similar capabilities, either through this model or others that lack the same safeguards.

For small and medium businesses, the direct risk isn't that GPT-6 Astra will be used against them specifically — OpenAI has built in restrictions — but that the pace of AI-assisted attack tool development is accelerating industry-wide. Attackers are increasingly using AI to speed up reconnaissance, phishing content creation, and vulnerability research, meaning the window between a flaw being discovered and being exploited is shrinking.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.