Agregátor RSS

OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold

Computerworld.com [Hacking News] - 4 Září, 2026 - 11:46

OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions.

“GPT‑6 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API and AWS,” OpenAI said in a statement.

Enterprise administrators must manually enable Astra for their workspace, since access is off by default at launch, according to the company.

Developers can access Astra in the API as gpt-6-astra or through Amazon Bedrock, OpenAI said, priced at $10 per million input tokens and $50 per million output tokens. Pro, Business, and Enterprise users also get a variant called Astra Pro, and the company said Astra supports Zero Data Retention for eligible API customers.

Company claims perfect score on exploit benchmark

OpenAI said it tested Astra without production safeguards on ExploitBench, and that the model scored 100%, up from 78.5% for predecessor GPT-5.6 Sol. On ExploitGym, a broader exploit-development benchmark, the company said Astra reached a 42.4% success rate against 30.3% for Sol, while using fewer output tokens.

“Its ability to identify and develop zero-day exploits can help defenders find and patch weaknesses, but it also creates a need for stronger safeguards,” OpenAI said in the blog post.

OpenAI also tested Astra on vulnerabilities disclosed in the three months before launch, to check whether it could find flaws on its own rather than recalling old exploits from training data. The model found two new zero-day vulnerabilities during that test, OpenAI said, and it is now disclosing both to the software makers involved.

Sanchit Vir Gogia, chief analyst at Greyhound Research, said the Critical label is a disclosure event rather than a capability event.

“Astra’s capability did not change between 10 August, when OpenAI said Critical capability could not be ruled out, and September 1, when it said the threshold was met,” Gogia noted. “The testing changed. The model did not.”

That inverts the obvious enterprise response, he said.

“Astra is now the only frontier model whose cyber capability an enterprise actually knows, because it is the only one measured against a published threshold, while every unlabelled model already sitting behind enterprise credentials has never been measured that way and will not be until its vendor chooses to measure it,” Gogia pointed out. “Those models are not safer.”

OpenAI said the public version of Astra will refuse advanced offensive tasks such as generating proof-of-concept exploits, though it plans to loosen those restrictions for vetted defenders through a program called OpenAI Daybreak in the coming weeks.

The launch follows OpenAI’s rollout of GPT-5.6 Sol, which the company said scored 73.5% on ExploitBench at launch, and comes months after Anthropic’s Fable and Mythos models were briefly pulled from export markets over similar concerns.

Governance shifts from the model to the harness around it

Gogia said the bigger shift is that reasoning now translates into state change, since a wrong chatbot answer is an information problem while a wrong agent action inside a customer-record system is an operating event.

“The governance unit therefore moves off the model,” he said, arguing the relevant question is no longer which model is approved, but how much damage a given identity can do before a control intervenes.

Amit Kumar Jena, head of AI development at Kanerika said the visibility problem is concrete: when an agent acts through a user interface, systems of record log the action as a person, so an agent that updates 400 ERP rows shows up as a service account making 400 updates, with no record of which instruction or model version produced them.

“You lose granularity inside the exact system a regulator or auditor will ask to see,” Jena added.

OpenAI said it built a new evaluation, informed by an incident involving Hugging Face, to test whether a model given an impossible task would exceed its authorized scope.

“Compared to GPT‑5.6 Sol, which without production safeguards went beyond the authorized target 48% of the time, GPT‑6 Astra did this in 0% of cases,” the statement added.

Gogia said the more uncomfortable finding is that Astra behaves better and watches worse: OpenAI reports decreased chain-of-thought monitorability against Sol, with Astra less likely to reveal incriminating reasoning, and its monitoring covers OpenAI’s own external deployment but nothing published extends that telemetry to customers. “OpenAI being able to monitor Astra does not mean an enterprise can audit Astra,” Gogia said.

The article originally appeared on CSO.

Kategorie: Hacking & Security

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

The Hacker News - 4 Září, 2026 - 10:48
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
Kategorie: Hacking & Security

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

The Hacker News - 4 Září, 2026 - 10:48
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apokalypsa trhu práce se odkládá. Umělá inteligence nahradí úkoly, ne celá povolání

Živě.cz - 4 Září, 2026 - 10:45
Zatímco někteří věští brzkou apokalypsu pracovního trhu a výrazný nárůst nezaměstnanosti, mnozí analytici vsází spíš na postupnou evoluci. AI práci změní, ale lidé budou stále potřeba.
Kategorie: IT News

U počítače nemusíte stát, můžete i chodit. Alza zlevnila motorový pás na minimum

Živě.cz - 4 Září, 2026 - 10:03
Alza zlevnila chodicí pásy své značky Stormred. • Základní model stojí jen 3500 Kč a hodí se i pod počítačový stůl. • Při práci můžete pálit kalorie, případně použít druhou stranu s masážním povrchem.
Kategorie: IT News

Radeony během srpna zdražily o 11 %, GeForce o 19 %, když se nepočítá RTX 5090

CD-R server - 4 Září, 2026 - 10:00
Přestože se avizované letní zdražení grafických karet ještě na koncových cenách plně neprojevilo, už statistika změn za poslední měsíc ukazuje, že růst cen GeForce byl téměř 2× větší než u Radeonů…
Kategorie: IT News

Telefon TCL jako první kombinuje matný Nxtpaper s displejem AMOLED

Živě.cz - 4 Září, 2026 - 09:45
Značka TCL přechází na AMOLED displeje, technologie Nxtpaper ale zůstává • Výrobce představil trojici nových telefonů, které se liší v detailech • Nejvyšší Ultra nabízí i teleobjektiv, základní P80 klade důraz na co nejnižší cenu
Kategorie: IT News

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

The Hacker News - 4 Září, 2026 - 09:35
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users
Kategorie: Hacking & Security

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

The Hacker News - 4 Září, 2026 - 09:35
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop usersRavie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

The Hacker News - 4 Září, 2026 - 09:18
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote
Kategorie: Hacking & Security

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

The Hacker News - 4 Září, 2026 - 09:18
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

The Hacker News - 4 Září, 2026 - 08:47
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,
Kategorie: Hacking & Security

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

The Hacker News - 4 Září, 2026 - 08:47
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering, Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Nvidia PAIR zdarma propojí vaše počítače do domácího AI clusteru

Živě.cz - 4 Září, 2026 - 08:45
Kolik doma máte počítačů? A opravdu jsou všechny stále zapnuté a zatížené? Co kdyby se dokázaly domluvit a ve chvíli volna vám pomoci se spouštěním úkolů pro vaše AI agenty. To je cílem novinky Nvidie. NDA 3.9. 18:00 nemusí to vyjít přesně s koncem NDA, ale hlavně ne před ním Nvidia PAIR – ...
Kategorie: IT News

Nová robosekačka Mammotion Luba 4 AWD konečně vyřešila roky kritizovaný problém

Živě.cz - 4 Září, 2026 - 07:45
Mimořádně oblíbené sekačky Mammotion Luba AWD doposud neuměly řídit přední kola, ale otáčely se odvalováním drobných válečků po obvodu předních kol. Ty se nicméně často zanesly špínou a místo otáčení drásaly povrch. Zejména na okrajích pozemku, kde je pod stromy často tráva nejslabší, dokázaly ...
Kategorie: IT News

Hynix uvažuje o výrobě HBM základny u Intelu. Šíří se i cenové fámy

CD-R server - 4 Září, 2026 - 07:40
Hynix plánuje nasadit 12nm proces TSMC pro základny čtvrté generace HBM. Uvažuje i o využití procesů Intelu, aby si vylepšil vyjednávací pozici a získal výhodnější cenové nabídky…
Kategorie: IT News

Hry zadarmo, nebo se slevou: Balík klasických RPG a emotivní sci-fi příběh zdarma

Živě.cz - 4 Září, 2026 - 07:15
Na všech herních platformách je každou chvíli nějaká slevová akce. Každý týden proto vybíráme ty nejatraktivnější, které by vám neměly uniknout. Pokud chcete získat hry zdarma nebo s výhodnou slevou, podívejte se na aktuální přehled akcí!
Kategorie: IT News

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

The Register - Anti-Virus - 4 Září, 2026 - 04:18
Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit. CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default. CVE-2026-20279 is another 9.8-rated flaw. Cisco says it’s an improper access control problem that covers “improper certificate validation, missing authentication for critical function, missing authorization, and incorrect authorization.” Cisco also spotted a trio of 8.8-rated flaws, plus another rated 8.6 and one more scored at 8.2 The company’s advisory says the company found the flaws after “a comprehensive internal security review,” language that perhaps hints at Cisco dabbling with Mythos and/or other bug-finding models. The fix is in: Cisco has published new versions of IOS XR that fix the problems and “strongly recommends” customers adopt them. Cisco’s support organization spotted the third critical flaw it revealed on Wednesday. CVE-2026-20212 is a tad embarrassing because the cause is a bad integration with Cisco’s own Silicon One networking processors that means some Nexus 9000 Series Switches “could allow an unauthenticated, remote attacker to execute code with root privileges.” “This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF),” according to Cisco’s advisory. A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.” Ten Nexus 9000 devices have the problem, which Cisco suggests owners mitigate by using infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. “Alternatively, the iACLs may be used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211,” the company advises. The networking giant suggests that approach because it hasn’t yet created a software update to fix the flaw once and for all. The company has, however, delivered a download that helps to implement the mitigation. Cisco hasn't seen attacks on these flaws. That may change, fast, now that evildoers can use AI to whip up nastyware. ®
Kategorie: Viry a Červi

Audacity 4.0

AbcLinuxu [zprávičky] - 4 Září, 2026 - 02:28
Byla vydána nová stabilní verze 4.0 svobodného multiplatformního softwaru pro editování a nahrávání zvukových souborů Audacity (Wikipedie). S rozhraním přepsaným do Qt. Přehled novinek také na YouTube. Ke stažení je oficiální AppImage. Zatím starší verze Audacity lze instalovat také z Flathubu a Snapcraftu.
Kategorie: GNU/Linux & BSD
Syndikovat obsah