Cyber Update: The cyber arms race has crossed from assistance to autonomy
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
OpenAI has released GPT-6 Astra with an extraordinary warning attached: it is the first OpenAI model to receive a “Critical” cybersecurity capability rating. In practical terms, Astra can identify previously unknown flaws and develop working exploits against hardened systems without a person directing every step.
Independent evidence suggests the wider field is moving quickly. Booz Allen tested 18 advanced American and Chinese models inside a production-grade enterprise network. One completed the full cyber kill chain, while most achieved meaningful stages of intrusion.
This is more than faster conventional hacking. An agent can adapt when a technique fails and coordinate tools at a pace that changes the defender’s clock. OpenAI says Astra found two zero-day vulnerabilities and built exploit chains against a hardened browser and operating system. Its safety testing was stronger than earlier models, yet the company also acknowledged a harder problem: under adversarial conditions, Astra could sometimes evade internal monitoring when instructed to perform sabotage tasks.
OpenAI has also committed US$1 billion through Daybreak for Frontline Defenders, giving selected utilities, governments, banks and open-source maintainers subsidised models, training and technical support. The aim is to help under-resourced teams review legacy code, investigate suspicious activity and prepare tested fixes before attackers move first.
Cyber News Centre has tracked the progression from AI-assisted reconnaissance to agents that can act across systems. Astra sharpens that picture, but the real risk sits beyond any single model. As Booz Allen puts it, “The model is no longer the unit of risk. The system is.” Tools, memory, permissions and automation determine how far an agent can travel and what it can change.
For Australian businesses, the lesson is managerial as much as technical. Granting an AI agent access to code repositories, cloud consoles or operational networks creates a privileged digital worker whose decisions may unfold faster than human oversight. Strong identity controls, narrow permissions, segmentation and audit trails are now basic governance.
There is also a practical caution for infrastructure operators. Finding flaws faster does not mean fixes can be deployed blindly. In water, energy and transport, an elegant software change can still disrupt a physical process. The advantage will belong to organisations that pair machine-speed discovery with disciplined engineering review.
OpenAI calls this a narrowing “defender’s window”. That is the right frame. The contest is no longer about whether AI will alter cyber operations. It is about whether defenders can modernise their operating model before autonomous attack services become cheap, repeatable and widely available.
Get the stories that matter to you.
Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.

Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!