{
  "story_id": "4958bcc675f74e1d5482dae47ddca2f0",
  "desk": "drm3",
  "revision": 1,
  "published_at": "2026-09-02T18:00:00.000Z",
  "content_hash": "f1c677faf47af8477f48bc88eaea5cfb4c2fa1ab333e5abceba09739533431f1",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "OpenAI Astra model reaches 'critical' cyber risk, to launch with restricted access",
    "dek": "OpenAI's Astra model, which solved 10 math problems, is classified as 'critical' cyber risk and launches soon with restricted access.",
    "prose": "On 2026-09-01, OpenAI confirmed in a blog post that Astra meets the 'critical' threshold for cybersecurity risk under its Preparedness Framework, making Astra the first OpenAI model to be classified as 'critical' (previously GPT-5.6-Sol was 'high'). [^1]\n\nOn 2026-08-01, OpenAI announced that its internal model named Astra had solved 10 major open math problems, some unresolved for decades, and called Astra 'our next major model.' [^2]\n\nOn 2026-08-07, OpenAI announced that Astra had developed advanced cyber capabilities requiring new security controls and a pause on some internal development work, and said it could not 'rule out critical cyber capabilities under our Preparedness Framework.' [^3]\n\nOpenAI's blog post defined the critical threshold as a model that can 'identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.' [^4]\n\nA notification sent to affected Dropbox users said an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using the user's email address, in some cases even for users who did not have Lenovo accounts. [^5]\n\nBleepingComputer reported that hackers used the fraudulent Lenovo ID to access the Dropbox account associated with the same email address without needing the login password. [^6]\n\nDropbox forced all sessions authenticated via Lenovo ID to expire and added a new login requirement forcing users to use their Dropbox account password instead. [^7]\n\nHackers accessed approximately 5,000 Dropbox accounts between August 4 and August 21, 2026, by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [^8]",
    "cited": "[{\"statement\":\"On 2026-09-01, OpenAI confirmed in a blog post that Astra meets the 'critical' threshold for cybersecurity risk under its Preparedness Framework, making Astra the first OpenAI model to be classified as 'critical' (previously GPT-5.6-Sol was 'high').\",\"source\":\"Mashable\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T21:08:06.000Z\",\"publisher_count\":1,\"sources\":[\"Mashable\"]},{\"statement\":\"On 2026-08-01, OpenAI announced that its internal model named Astra had solved 10 major open math problems, some unresolved for decades, and called Astra 'our next major model.'\",\"source\":\"Mashable\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T21:08:06.000Z\",\"publisher_count\":1,\"sources\":[\"Mashable\"]},{\"statement\":\"On 2026-08-07, OpenAI announced that Astra had developed advanced cyber capabilities requiring new security controls and a pause on some internal development work, and said it could not 'rule out critical cyber capabilities under our Preparedness Framework.'\",\"source\":\"Mashable\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T21:08:06.000Z\",\"publisher_count\":1,\"sources\":[\"Mashable\"]},{\"statement\":\"OpenAI's blog post defined the critical threshold as a model that can 'identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.'\",\"source\":\"Mashable\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T21:08:06.000Z\",\"publisher_count\":1,\"sources\":[\"Mashable\"]},{\"statement\":\"A notification sent to affected Dropbox users said an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using the user's email address, in some cases even for users who did not have Lenovo accounts.\",\"source\":\"ZeroHedge\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T18:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"ZeroHedge\"]},{\"statement\":\"BleepingComputer reported that hackers used the fraudulent Lenovo ID to access the Dropbox account associated with the same email address without needing the login password.\",\"source\":\"ZeroHedge\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T18:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"ZeroHedge\"]},{\"statement\":\"Dropbox forced all sessions authenticated via Lenovo ID to expire and added a new login requirement forcing users to use their Dropbox account password instead.\",\"source\":\"ZeroHedge\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T18:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"ZeroHedge\"]},{\"statement\":\"Hackers accessed approximately 5,000 Dropbox accounts between August 4 and August 21, 2026, by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs.\",\"source\":\"ZeroHedge\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T18:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"ZeroHedge\"]}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": null,
  "receipt_note": "this revision predates receipt-keeping (before v0.37.0); the filed row lives in the record",
  "generation_chain": {
    "wire": {
      "stream": "fountain_news",
      "story_id": "e9ae94e217be91d7c7b87c3dae2d2f78",
      "thread_id": "5a82602bb80fb561a903c771bd25c49d",
      "thread_label": "Bleeping Computer",
      "novelty": "UPDATE",
      "content_hash": "e069391d16018472855734ffe9de0a35544e43a28c5e63af3ea757ac4a643785",
      "last_published_at": "2026-09-02T18:00:00.000Z",
      "read_receipt": {
        "slice_hash": "11220e4dbf5190921f107dbdea6d99cd844703ff4eef74569640e84ea83ced60",
        "cursor_from": "eyJ0cyI6IjIwMjYtMDktMDJUMTc6NDQ6NDkuMDAwMDAwWiIsImlkIjoiMzY4OTUzMTNmMmQ0NTU3Zjk3Nzk4NTU5NDE1MWQ0OTYiLCJ2IjoiMSJ9",
        "cursor_to": "eyJ0cyI6IjIwMjYtMDktMDJUMTk6NDU6MTcuMDAwMDAwWiIsImlkIjoiMjc4NjE2ZTUxYmJmNDhkYmNlNzZjNjhlYmMxM2E2NmUiLCJ2IjoiMSJ9",
        "view": "v_fountain_news",
        "view_version": "1",
        "row_count": 100,
        "window_days": 3,
        "bytes_scanned": 10113494,
        "credits": 8,
        "price_per_100_rows": 8,
        "sig": "TfMTRUXpx7CzBxHaDv5ngbDuMNWmGAy2xiFXiaO_Paus3_lE3iKiHphYPVaT8Ac2h-vl_QwA11jHegTeg3YTCA",
        "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
        "signer_path": "lakehouse/data-extract/v1",
        "alg": "Ed25519",
        "signed": true
      }
    },
    "written_at": "2026-09-03T00:45:55.229Z"
  },
  "cited_facts": [
    {
      "statement": "On 2026-09-01, OpenAI confirmed in a blog post that Astra meets the 'critical' threshold for cybersecurity risk under its Preparedness Framework, making Astra the first OpenAI model to be classified as 'critical' (previously GPT-5.6-Sol was 'high').",
      "source": "Mashable",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T21:08:06.000Z",
      "publisher_count": 1,
      "sources": [
        "Mashable"
      ]
    },
    {
      "statement": "On 2026-08-01, OpenAI announced that its internal model named Astra had solved 10 major open math problems, some unresolved for decades, and called Astra 'our next major model.'",
      "source": "Mashable",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T21:08:06.000Z",
      "publisher_count": 1,
      "sources": [
        "Mashable"
      ]
    },
    {
      "statement": "On 2026-08-07, OpenAI announced that Astra had developed advanced cyber capabilities requiring new security controls and a pause on some internal development work, and said it could not 'rule out critical cyber capabilities under our Preparedness Framework.'",
      "source": "Mashable",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T21:08:06.000Z",
      "publisher_count": 1,
      "sources": [
        "Mashable"
      ]
    },
    {
      "statement": "OpenAI's blog post defined the critical threshold as a model that can 'identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.'",
      "source": "Mashable",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T21:08:06.000Z",
      "publisher_count": 1,
      "sources": [
        "Mashable"
      ]
    },
    {
      "statement": "A notification sent to affected Dropbox users said an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using the user's email address, in some cases even for users who did not have Lenovo accounts.",
      "source": "ZeroHedge",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T18:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "ZeroHedge"
      ]
    },
    {
      "statement": "BleepingComputer reported that hackers used the fraudulent Lenovo ID to access the Dropbox account associated with the same email address without needing the login password.",
      "source": "ZeroHedge",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T18:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "ZeroHedge"
      ]
    },
    {
      "statement": "Dropbox forced all sessions authenticated via Lenovo ID to expire and added a new login requirement forcing users to use their Dropbox account password instead.",
      "source": "ZeroHedge",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T18:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "ZeroHedge"
      ]
    },
    {
      "statement": "Hackers accessed approximately 5,000 Dropbox accounts between August 4 and August 21, 2026, by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs.",
      "source": "ZeroHedge",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T18:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "ZeroHedge"
      ]
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}