← Journal

OpenAI priced a model it rates Critical for cyber risk

GPT-6 Astra scored 100% on ExploitBench and found two zero-days in evaluation. Today's two real breaches came from an unpatched Metabase flaw.

OpenAI released GPT-6 Astra at $10 per million input tokens and $50 per million output tokens, and rates it as meeting the Critical cybersecurity threshold of its own Preparedness Framework. It scored 100% on ExploitBench and discovered two previously unknown zero-day vulnerabilities during the evaluation.

A lab declaring its own model Critical on cyber is a claim about capability. Three other items on today's page are the evidence for it, and two more are the reason it matters.

The clock, not the exploit

Researchers built WeWorm, a zero-click worm that hijacks a WeChat account through an incoming call the victim never answers or touches. Tencent has blocked the exploit and the researchers found no evidence of real-world use, so the worm itself is a lab artefact. The number worth keeping is the clock: AI found the underlying VoIP memory corruption flaw in about two days, and the worm took a further week to build.

Ivanti disclosed ten CVEs across Endpoint Manager Mobile, Neurons for ITSM and Sentry, including three missing-authorization flaws rated 9.9 and two unauthenticated deserialization flaws scored 9.8 that allow remote code execution. Ivanti credited its own large language models with uncovering the ITSM bugs.

So one page holds a vendor using models to find bugs in its own products, researchers using them to find a bug in someone else's, and a lab selling the capability by the token. Only the third comes with a price list.

What actually got exploited

Neither breach on today's page needed any of that.

Mathspace disclosed a breach affecting 1,079,819 students, teachers, staff and guardians in Australia and New Zealand. The attackers exploited a known SQL injection flaw in its self-hosted Metabase instance on 10 August, and the company upgraded on 29 August: nineteen days, on a vulnerability that was already public.

Toss Payments and Coem Payments are under on-site inspection by South Korea's Financial Supervisory Service after a Chinese hacker took tens of thousands of card records, including names, card numbers, expiry dates and the first two digits of PINs. The detail a regulator should sit with: the hacker tipped off the authorities before either the regulator or the companies knew about the breach.

The offensive frontier now has a rate card at $50 per million output tokens. The defensive floor is still an unpatched dashboard and a breach you hear about from the person who committed it.

The threshold has moved before

The record on OpenAI carries the precedent. In July the Trump administration lifted its restrictions on GPT-5.6, clearing a broad public launch after a cybersecurity-driven delay. Two months later the same lab ships a model it rates Critical on that axis and puts it on a public price list, with the rating in its own launch post rather than in a regulator's.

Containment as a shipped feature

Meta launched Muse, a personal AI agent that runs on its own cloud virtual machine, with a separate Sentinel agent that must approve anything Muse sends to the internet. It is rolling out in the US on iOS, Android and the web, free for most uses with paid tiers above that.

Set beside the Astra card, Sentinel reads less like a privacy feature than like an assumption: the agent will be pointed at the network, and the live question is who approves the packets. Today's record holds one lab pricing the capability, one vendor turning it on its own code, and one company that took nineteen days to apply a patch it already had.

Built from the digest of 2026-09-09.