{
  "story_id": "b91aee38973a01130c4196ce0a35ca2c",
  "desk": "drm3",
  "revision": 2,
  "published_at": "2026-09-02T14:20:28.000Z",
  "content_hash": "8d763c9ded7a8ca84079082fbcabec2005c8eb60c81239115f44199a564798a4",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "OpenAI's Astra Model Crosses Critical Cybersecurity Threshold",
    "dek": "OpenAI's new Astra model is the first to reach the 'Critical' cybersecurity capability level, requiring additional safeguards before release.",
    "prose": "OpenAI stated that its newest model, Astra, has reached the 'Critical' cybersecurity capability level under the company's Preparedness Framework, marking the first time any of its models has been placed in that category. [^1]\n\nOn August 14, 2026, the AI lab Z.ai published a ledger listing 2,436 software vulnerabilities found by its GLM-5.3 model across 269 open-source projects. [^2]\n\nOpenAI announced on its blog that its forthcoming Astra model is the first large language model to meet its 'critical cybersecurity threshold,' and that it plans to make Astra available soon while limiting access to its most advanced cybersecurity capabilities. [^3]\n\nOpenAI rated its Astra model as its most dangerous model to date due to its ability to build exploits and bypass safety checks. [^4]\n\nDuring a separate evaluation involving more recently disclosed flaws, Astra uncovered two zero-day vulnerabilities on its own. [^5]\n\nOpenAI reported that Astra now declines 91.5% of cyber-related jailbreak attempts in its testing, up from 59% for its predecessor, GPT-5.6 Sol. [^6]\n\nOn August 20, 2026, a measurement showed that 28.3% of 46 core npm packages had shipped nothing in the previous 90 days. [^7]\n\nOn August 20, 2026, a measurement showed that 39.3% of 84 of the most-depended-on PyPI packages had shipped no release in the previous 90 days. [^8]\n\nThe 2,436 findings included 107 critical vulnerabilities and 990 high-severity vulnerabilities, affecting projects such as the Linux kernel, Redis, WebKit, and FreeBSD. [^9]\n\nOpenAI reported that Astra scored a perfect score on ExploitBench, an evaluation of an LLM's ability to hack into known system vulnerabilities, and that in a modified test developed by OpenAI engineers, Astra discovered and exploited two zero-day vulnerabilities. [^10]\n\nOpenAI said its Astra model is capable of finding unknown security flaws in computer systems and exploiting them without a person's guidance. [^11]\n\nIn expert-led tests, Astra built a full compromise chain against a browser, broke out of the sandbox, and ran commands on the host the moment the browser opened an HTML file. [^12]",
    "cited": "[{\"statement\":\"OpenAI stated that its newest model, Astra, has reached the 'Critical' cybersecurity capability level under the company's Preparedness Framework, marking the first time any of its models has been placed in that category.\",\"source\":\"SecurityWeek\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T10:38:13.000Z\",\"publisher_count\":1,\"sources\":[\"SecurityWeek\"]},{\"statement\":\"On August 14, 2026, the AI lab Z.ai published a ledger listing 2,436 software vulnerabilities found by its GLM-5.3 model across 269 open-source projects.\",\"source\":\"towardsai.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T10:30:24.000Z\",\"publisher_count\":1,\"sources\":[\"towardsai.com\"]},{\"statement\":\"OpenAI announced on its blog that its forthcoming Astra model is the first large language model to meet its 'critical cybersecurity threshold,' and that it plans to make Astra available soon while limiting access to its most advanced cybersecurity capabilities.\",\"source\":\"TechCrunch\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T21:06:24.000Z\",\"publisher_count\":1,\"sources\":[\"TechCrunch\"]},{\"statement\":\"OpenAI rated its Astra model as its most dangerous model to date due to its ability to build exploits and bypass safety checks.\",\"source\":\"The Decoder\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T14:20:28.000Z\",\"publisher_count\":1,\"sources\":[\"The Decoder\"]},{\"statement\":\"During a separate evaluation involving more recently disclosed flaws, Astra uncovered two zero-day vulnerabilities on its own.\",\"source\":\"SecurityWeek\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T10:38:13.000Z\",\"publisher_count\":1,\"sources\":[\"SecurityWeek\"]},{\"statement\":\"OpenAI reported that Astra now declines 91.5% of cyber-related jailbreak attempts in its testing, up from 59% for its predecessor, GPT-5.6 Sol.\",\"source\":\"SecurityWeek\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T10:38:13.000Z\",\"publisher_count\":1,\"sources\":[\"SecurityWeek\"]},{\"statement\":\"On August 20, 2026, a measurement showed that 28.3% of 46 core npm packages had shipped nothing in the previous 90 days.\",\"source\":\"towardsai.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T10:30:24.000Z\",\"publisher_count\":1,\"sources\":[\"towardsai.com\"]},{\"statement\":\"On August 20, 2026, a measurement showed that 39.3% of 84 of the most-depended-on PyPI packages had shipped no release in the previous 90 days.\",\"source\":\"towardsai.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T10:30:24.000Z\",\"publisher_count\":1,\"sources\":[\"towardsai.com\"]},{\"statement\":\"The 2,436 findings included 107 critical vulnerabilities and 990 high-severity vulnerabilities, affecting projects such as the Linux kernel, Redis, WebKit, and FreeBSD.\",\"source\":\"towardsai.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T10:30:24.000Z\",\"publisher_count\":1,\"sources\":[\"towardsai.com\"]},{\"statement\":\"OpenAI reported that Astra scored a perfect score on ExploitBench, an evaluation of an LLM's ability to hack into known system vulnerabilities, and that in a modified test developed by OpenAI engineers, Astra discovered and exploited two zero-day vulnerabilities.\",\"source\":\"TechCrunch\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T21:06:24.000Z\",\"publisher_count\":1,\"sources\":[\"TechCrunch\"]},{\"statement\":\"OpenAI said its Astra model is capable of finding unknown security flaws in computer systems and exploiting them without a person's guidance.\",\"source\":\"TechCrunch\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T21:06:24.000Z\",\"publisher_count\":1,\"sources\":[\"TechCrunch\"]},{\"statement\":\"In expert-led tests, Astra built a full compromise chain against a browser, broke out of the sandbox, and ran commands on the host the moment the browser opened an HTML file.\",\"source\":\"The Decoder\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T14:20:28.000Z\",\"publisher_count\":1,\"sources\":[\"The Decoder\"]}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": null,
  "receipt_note": "this revision predates receipt-keeping (before v0.37.0); the filed row lives in the record",
  "generation_chain": {
    "wire": {
      "stream": "fountain_news",
      "story_id": "504846b647c9640eeb898310c9a0946d",
      "thread_id": "4a1b71b93ea108114c2076f346ca8500",
      "thread_label": "ExploitBench",
      "novelty": "UPDATE",
      "content_hash": "fc9698acd08925d6ae999450c77a2b7ffc80bdaf6d899ce884a310f128cf970c",
      "last_published_at": "2026-09-02T14:20:28.000Z",
      "read_receipt": {
        "slice_hash": "bff706d0b91b9f4763839423c46df3e448ab83cb9be716aef6645f51c84fd704",
        "cursor_from": "eyJ0cyI6IjIwMjYtMDktMDJUMTM6NTU6MDUuMDAwMDAwWiIsImlkIjoiYWNhYmYyOWI5NzVlYzQwOTE2ZmQ0ODdhYWJiMGRmZGIiLCJ2IjoiMSJ9",
        "cursor_to": "eyJ0cyI6IjIwMjYtMDktMDJUMTQ6MjM6MzIuMDAwMDAwWiIsImlkIjoiZTVlMzFkYjQxN2UyYzA0MGU5Nzc1ZWYwNGE4YWE3MTAiLCJ2IjoiMSJ9",
        "view": "v_fountain_news",
        "view_version": "1",
        "row_count": 100,
        "window_days": 3,
        "bytes_scanned": 10113494,
        "credits": 8,
        "price_per_100_rows": 8,
        "sig": "2iCOEBVF4-TfjfzdZF2Bg0ADm6l9x6q3NnXwy70pyYptwlMv7eTsWrZ8Eg9_XYMR-8EL2p_-7_Sjm2mUC8gDAg",
        "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
        "signer_path": "lakehouse/data-extract/v1",
        "alg": "Ed25519",
        "signed": true
      }
    },
    "written_at": "2026-09-03T00:36:05.949Z"
  },
  "cited_facts": [
    {
      "statement": "OpenAI stated that its newest model, Astra, has reached the 'Critical' cybersecurity capability level under the company's Preparedness Framework, marking the first time any of its models has been placed in that category.",
      "source": "SecurityWeek",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T10:38:13.000Z",
      "publisher_count": 1,
      "sources": [
        "SecurityWeek"
      ]
    },
    {
      "statement": "On August 14, 2026, the AI lab Z.ai published a ledger listing 2,436 software vulnerabilities found by its GLM-5.3 model across 269 open-source projects.",
      "source": "towardsai.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T10:30:24.000Z",
      "publisher_count": 1,
      "sources": [
        "towardsai.com"
      ]
    },
    {
      "statement": "OpenAI announced on its blog that its forthcoming Astra model is the first large language model to meet its 'critical cybersecurity threshold,' and that it plans to make Astra available soon while limiting access to its most advanced cybersecurity capabilities.",
      "source": "TechCrunch",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T21:06:24.000Z",
      "publisher_count": 1,
      "sources": [
        "TechCrunch"
      ]
    },
    {
      "statement": "OpenAI rated its Astra model as its most dangerous model to date due to its ability to build exploits and bypass safety checks.",
      "source": "The Decoder",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T14:20:28.000Z",
      "publisher_count": 1,
      "sources": [
        "The Decoder"
      ]
    },
    {
      "statement": "During a separate evaluation involving more recently disclosed flaws, Astra uncovered two zero-day vulnerabilities on its own.",
      "source": "SecurityWeek",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T10:38:13.000Z",
      "publisher_count": 1,
      "sources": [
        "SecurityWeek"
      ]
    },
    {
      "statement": "OpenAI reported that Astra now declines 91.5% of cyber-related jailbreak attempts in its testing, up from 59% for its predecessor, GPT-5.6 Sol.",
      "source": "SecurityWeek",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T10:38:13.000Z",
      "publisher_count": 1,
      "sources": [
        "SecurityWeek"
      ]
    },
    {
      "statement": "On August 20, 2026, a measurement showed that 28.3% of 46 core npm packages had shipped nothing in the previous 90 days.",
      "source": "towardsai.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T10:30:24.000Z",
      "publisher_count": 1,
      "sources": [
        "towardsai.com"
      ]
    },
    {
      "statement": "On August 20, 2026, a measurement showed that 39.3% of 84 of the most-depended-on PyPI packages had shipped no release in the previous 90 days.",
      "source": "towardsai.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T10:30:24.000Z",
      "publisher_count": 1,
      "sources": [
        "towardsai.com"
      ]
    },
    {
      "statement": "The 2,436 findings included 107 critical vulnerabilities and 990 high-severity vulnerabilities, affecting projects such as the Linux kernel, Redis, WebKit, and FreeBSD.",
      "source": "towardsai.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T10:30:24.000Z",
      "publisher_count": 1,
      "sources": [
        "towardsai.com"
      ]
    },
    {
      "statement": "OpenAI reported that Astra scored a perfect score on ExploitBench, an evaluation of an LLM's ability to hack into known system vulnerabilities, and that in a modified test developed by OpenAI engineers, Astra discovered and exploited two zero-day vulnerabilities.",
      "source": "TechCrunch",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T21:06:24.000Z",
      "publisher_count": 1,
      "sources": [
        "TechCrunch"
      ]
    },
    {
      "statement": "OpenAI said its Astra model is capable of finding unknown security flaws in computer systems and exploiting them without a person's guidance.",
      "source": "TechCrunch",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T21:06:24.000Z",
      "publisher_count": 1,
      "sources": [
        "TechCrunch"
      ]
    },
    {
      "statement": "In expert-led tests, Astra built a full compromise chain against a browser, broke out of the sandbox, and ran commands on the host the moment the browser opened an HTML file.",
      "source": "The Decoder",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T14:20:28.000Z",
      "publisher_count": 1,
      "sources": [
        "The Decoder"
      ]
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}