OpenAI says GPT-6 Astra can find zero-days, and watching how it gets there got harder at the same time. According to implicator.ai, OpenAI's own tests found Astra's reasoning harder to monitor than its predecessor's, so there's less visible work to audit while the model hunts for exploits.
The safety overview OpenAI published on September 3 defines the Critical cybersecurity threshold as the ability to identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or to devise and execute new end-to-end attack strategies against hardened targets. Astra is the first OpenAI model the company placed at that level. BleepingComputer's report on the pairing of both traits came out on September 8.

