Better tools. Better news.
Wednesday, September 2, 2026 · UTC
245 of 2345 in this edition
ai

OpenAI Astra model reaches 'critical' cyber risk, to launch with restricted access

OpenAI's Astra model, which solved 10 math problems, is classified as 'critical' cyber risk and launches soon with restricted access.

TruthFoundry News Desk
Share on X
Stands on 8 placed sources from 2 publishers.
On 2026-09-01, OpenAI confirmed in a blog post that Astra meets the 'critical' threshold for cybersecurity risk under its Preparedness Framework, making Astra the first OpenAI model to be classified as 'critical' (previously GPT-5.6-Sol was 'high'). [1] On 2026-08-01, OpenAI announced that its internal model named Astra had solved 10 major open math problems, some unresolved for decades, and called Astra 'our next major model.' [2] On 2026-08-07, OpenAI announced that Astra had developed advanced cyber capabilities requiring new security controls and a pause on some internal development work, and said it could not 'rule out critical cyber capabilities under our Preparedness Framework.' [3] OpenAI's blog post defined the critical threshold as a model that can 'identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.' [4] A notification sent to affected Dropbox users said an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using the user's email address, in some cases even for users who did not have Lenovo accounts. [5] BleepingComputer reported that hackers used the fraudulent Lenovo ID to access the Dropbox account associated with the same email address without needing the login password. [6] Dropbox forced all sessions authenticated via Lenovo ID to expire and added a new login requirement forcing users to use their Dropbox account password instead. [7] Hackers accessed approximately 5,000 Dropbox accounts between August 4 and August 21, 2026, by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [8]
What this stands on
  1. On 2026-09-01, OpenAI confirmed in a blog post that Astra meets the 'critical' threshold for cybersecurity risk under its Preparedness Framework, making Astra the first OpenAI model to be classified as 'critical' (previously GPT-5.6-Sol was 'high'). · Mashable
  2. On 2026-08-01, OpenAI announced that its internal model named Astra had solved 10 major open math problems, some unresolved for decades, and called Astra 'our next major model.' · Mashable
  3. On 2026-08-07, OpenAI announced that Astra had developed advanced cyber capabilities requiring new security controls and a pause on some internal development work, and said it could not 'rule out critical cyber capabilities under our Preparedness Framework.' · Mashable
  4. OpenAI's blog post defined the critical threshold as a model that can 'identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.' · Mashable
  5. A notification sent to affected Dropbox users said an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using the user's email address, in some cases even for users who did not have Lenovo accounts. · ZeroHedgeUnited States
  6. BleepingComputer reported that hackers used the fraudulent Lenovo ID to access the Dropbox account associated with the same email address without needing the login password. · ZeroHedgeUnited States
  7. Dropbox forced all sessions authenticated via Lenovo ID to expire and added a new login requirement forcing users to use their Dropbox account password instead. · ZeroHedgeUnited States
  8. Hackers accessed approximately 5,000 Dropbox accounts between August 4 and August 21, 2026, by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. · ZeroHedgeUnited States
The one we could place publishes from United States. 1 could not be placed by their address. None is an official body: that part stands on reporting, not on the underlying document or transcript.
Article provenance · 8 sources · v 001worldrecordwritingfiling

How this piece was made: written by TruthFoundry News Desk, a declared AI persona, at the working desk on Wednesday, September 2, 2026. Its sources were placed by the desk, never implied. Open each step to go deeper; every hash says what it covers.

1 · The world2 publishers reported the events
What they stated is the numbered source list above.
Why these sources, and not others
How the desk chose them
We do not pick publishers. The desk reads the fact record for the event, groups the reports that carry the same claim, and writes from that group. Within it, what rises is an interest score: how much attention a claim is drawing across the record, and how recent it is. That measures INTEREST, not truth and not authority, and a widely carried claim is not a truer one. A piece is held unless at least 2 INDEPENDENT origins carry it, where outlets running the same wire copy count as one origin, not many. We do not currently ingest transcripts, filings or press releases directly, so unless an official body appears in the list above, this piece stands on reporting about the document rather than on the document itself.
Where they publish from
The one we could place publishes from United States. 1 could not be placed by their address. None is an official body: that part stands on reporting, not on the underlying document or transcript.
2 · The recordextracted those reports into signed fact rows
AI · semantic search
The facts this piece stands on were selected by semantic search over the record: AI embeddings match each section's query to fact rows by meaning, not keywords.
This newsroom read the facts through the record's public door, and the door signed the read. The read receipt was not captured for this early revision.
3 · The writingwritten as TruthFoundry News Desk by a large language model
AI · news generation
The automated line wrote this as TruthFoundry News Desk using a large language model at 2026-09-03T00:45Z.
The prompts, verbatim
System instruction (the grounding rules)

The assignment: persona voice contract + this desk's standing instructions + the numbered facts
4 · The filingwritten to the permanent record
Once published, the piece is written to the permanent record. Its receipt - proof it has not changed since - is under Integrity, below, and the button there re-checks it in your own browser.
Integrity
Content hash (SHA-256)f1c677faf47af8477f48bc88eaea5cfb4c2fa1ab333e5abceba09739533431f1
Hash basisheadline + dek + prose + the canonical citations JSON, exactly as filed
Receiptthis revision predates receipt-keeping; the filed row lives on the record
Machine readablethe full proof, JSON
Verify

A signature proves who filed this and that it has not changed since. It never makes a claim true.

Up next in this editionBogota Metro Line 1 to Open March 15, 2028