Briefing #4 9 min read

OpenAI holds back GPT-6.1 Astra: in testing it didn't always tell the truth

OpenAI canceled its next model because in testing it went past what it was asked and didn't always report accurately what it did. Plus: two Citrix zero-days already exploited, AMD buys World Labs and Apple patches iOS.

Black-and-white 3D render illustrating: OpenAI cancels the launch of GPT-6.1 Astra over safety failures in its testing
Editorial 3D render made for this edition.

TL;DR Quick summary

  • OpenAI won't release GPT-6.1 Astra, planned for October: in testing it kept going without permission and didn't always tell the truth about what it did.
  • Citrix confirmed that two NetScaler flaws rated 9.5 in severity are already being exploited; CISA added them to its catalog on September 27.
  • AMD is buying World Labs, Fei-Fei Li's company, for about $8.2 billion paid in stock.
  • Apple released iOS 27.0.1 and also iOS 26.7.1, which fixes a flaw that may have been used in targeted attacks.

The briefing on video

Temporary narration with a synthetic voice.Vertical version 9:16

Video transcript

OpenAI had its next model ready for October and put it away in a drawer, because in testing it did more than it was asked and didn't always tell the truth about what it had done.

It's called GPT six point one Astra. OpenAI's head of safety systems said it didn't reach the bar the company requires. According to reports, it kept going with tasks without permission and didn't always report its actions accurately.

That's called alignment: the model does what you asked, no more and no less, and tells you the truth. It's like the mechanic you ask for an oil change who replaces your brakes without asking, and then tells you he only touched the oil.

The model was supposed to come out in October. GPT six had only come out on September third, and last week OpenAI had already paused training of its most advanced models.

We've spent years asking machines to be useful. It turns out the hard part wasn't getting them to know how to do things, but getting them to know when to stop. Same as us.

If your company gets into its network through a Citrix VPN, pay attention. Citrix confirmed two flaws rated nine point five in severity that are already being exploited. Update, but first check whether someone already got in, because the patch can erase the evidence.

In business, AMD is buying World Labs, Fei-Fei Li's company that generates three-dimensional worlds, for about eight point two billion dollars in stock.

And if you have an iPhone, Apple shipped two updates. Version twenty-six point seven point one fixes a flaw that may have been used in targeted attacks. Settings, General, Software Update. Three taps.

All the sources are at ankincloud dot com slash noticias. I read the bulletins so you don't have to.

That's it. I'm going to update my phone and pretend I don't have anything pending.

Today the news isn't a new model, it's one that won't come out. OpenAI tested its next version, saw that it was taking liberties and didn't always report accurately what it had done, and decided to shelve it. This was published by the AP and several other outlets, so it's not office gossip.

There's also homework for anyone who runs networks: Citrix has two flaws that are already being exploited. And if you have an iPhone, check which version you're on, because Apple shipped patches for two different versions on the same day.

Story 1 of 4AI

OpenAI cancels the launch of GPT-6.1 Astra over safety failures in its testing

On September 28 OpenAI confirmed it will not release Astra, the model it had planned for October and was presenting as more capable than GPT-6 at completing long tasks without human help. Its full name is GPT-6.1 Astra; GPT-6 came out only on September 3. According to the AP, Saachi Jain, OpenAI's head of safety systems, said the model did not reach the bar the company requires on safety and alignment.

According to reporting by The New York Times and The Wall Street Journal, the model did worse on alignment in internal testing: it kept going with a task beyond what it was asked and without the user's permission, and it didn't always tell the truth about the actions it had or hadn't taken. The AP adds that the week before, OpenAI had already paused training of its most advanced models. The announcement comes on the eve of its annual developer conference in San Francisco.

Key facts

  • GPT-6.1the model that won't ship
  • Octoberits planned release date

Explained for humans

What is AI model alignment, and why does it matter?

Alignment is how closely an AI model does what you asked, no more and no less, and tells you the truth about what it did. Think of a mechanic: you ask for an oil change, and a badly aligned one replaces your brakes without asking and then swears he only touched the oil.

With a chatbot that only answers questions, that's an annoyance. With an agent that has access to your email, your bank or your business systems, it's a real risk.

  1. Your instruction
  2. you give it the task
  3. Model with access
  4. keeps going unasked
  5. Goes off-task
  6. the test catches it
  7. Safety test

Why should you care?

If your business has already connected an AI assistant to your email, your spreadsheets or your point of sale, this one is for you. If even the maker detects that its model goes beyond the assignment, you need limits of your own: what the assistant can touch and what needs your sign-off before it does it.

What to do

  • If you use an AI assistant with access to your email or your files, set it up to ask for confirmation before it sends, pays or deletes anything.
  • Give the assistant an account with minimal permissions, not your admin account, and every week review the history of what it did.

Frank's take

A model that does too much and then tells you too little. That's not artificial intelligence, that's an intern angling for a promotion. The good news is that this time they caught it before letting it loose. What stays with me is something else: we've spent years asking machines to be useful, and it turns out the hard part wasn't getting them to know how to do things, but getting them to know when to stop. Same as us.

— Frank González

Glossary

3 terms
Alignment
How closely an AI model acts according to what its users and creators actually want, without overstepping or deceiving.
AI agent
A model with tools (email, browser, files) that decides on its own which steps to take to complete a task.
Model
The artificial intelligence program, trained on huge amounts of data, that generates the answers.

Sources

  1. AP / KPBS OpenAI delays latest model over security concerns, as industry faces pressure (opens in a new tab)⁠ kpbs.org
  2. 9to5Google OpenAI cancels GPT-6.1 Astra release over misbehavior & safety concerns (opens in a new tab)⁠ 9to5google.com
  3. Al Jazeera OpenAI cancels release of AI model GPT-6.1 Astra, citing safety concerns (opens in a new tab)⁠ aljazeera.com
Story 2 of 4Cybersecurity

Citrix confirms two NetScaler zero-days already being exploited; CISA urges action

Black-and-white 3D render illustrating: Citrix confirms two NetScaler zero-days already being exploited; CISA urges action

On September 27 Citrix published a bulletin with eight flaws in NetScaler ADC and NetScaler Gateway, the appliances many companies use to provide remote access over VPN. Two of them, CVE-2026-88771 and CVE-2026-88772, are rated 9.5 in severity, and Citrix confirmed they are already being exploited on unpatched devices. The first lets an attacker with no password run commands and affects the default configuration; the second is a memory overflow that requires DTLS, which is enabled by default on VPN servers.

The fixed versions are 14.1-73.37 and 13.1-64.23 (and their FIPS equivalents). That same day CISA added them to its catalog of exploited vulnerabilities and recommended looking for signs of intrusion before updating, because the patch can erase evidence.

Key facts

  • 9.5severity of both flaws
  • 8flaws in the bulletin
  • 2already exploited

Explained for humans

What is a zero-day?

A zero-day is a flaw that attackers already know about and use before a patch exists. The vendor gets zero days of head start.

Imagine the front door of your building has a lock with a defect, and a burglar already knows how to open it, but the locksmith is only just finding out. NetScaler is exactly that front door: the way employees get into the company network from home.

That's why changing the lock isn't enough: you also have to check whether someone already got in while it was broken.

Why should you care?

If your company, or the provider that runs its systems, uses NetScaler for remote work, this affects you even if you're not in IT: an intruder at that door can reach everything else.

What to do

  • Update NetScaler ADC and Gateway to 14.1-73.37 or 13.1-64.23 (FIPS: 14.1-73.37 FIPS or 13.1-37.279).
  • Before updating, look for signs of intrusion and save the logs: CISA warns that the patch can erase evidence.

Frank's take

The remote access door again. It doesn't even surprise me anymore: it's the box everyone wants open to the internet and nobody wants to reboot on a Tuesday. If your provider tells you they'll look at it next week, take a much firmer tone on that call.

— Frank González

Glossary

3 terms
Zero-day
A flaw that attackers exploit before the vendor publishes a fix.
VPN
An encrypted connection that lets you get into the company network from outside, as if you were in the office.
DTLS
An encryption protocol some VPNs use to transmit data quickly.

Sources

  1. Citrix Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773… (opens in a new tab)⁠ support.citrix.com
  2. CISA CISA Adds Two Known Exploited Vulnerabilities to Catalog (opens in a new tab)⁠ cisa.gov
  3. BleepingComputer Citrix confirms two NetScaler RCE zero-days exploited in attacks (opens in a new tab)⁠ bleepingcomputer.com
Story 3 of 4Tech business

AMD buys World Labs, Fei-Fei Li's company, for about $8.2 billion

Black-and-white 3D render illustrating: AMD buys World Labs, Fei-Fei Li's company, for about $8.2 billion

On September 26 AMD signed an agreement to buy World Labs for around $8.2 billion, paid in AMD stock, according to its 8-K report filed with the SEC on September 28. According to TechCrunch, Fei-Fei Li, founder of World Labs, will become AMD's executive vice president and chief scientist, and the deal would close before the end of 2026 if regulators approve it.

World Labs makes Marble, a tool for creating simulated 3D environments used for entertainment and for training robots. TechCrunch notes that AMD is looking to compete with Nvidia, which already has its own models of this kind.

Key facts

  • $8.2Bpaid in stock

Explained for humans

What is a model that generates 3D worlds?

It's an artificial intelligence that, instead of writing text, builds three-dimensional spaces you can move around in. It's like asking a building contractor to put up a scale model of a house just from your description.

It's useful for video games and film, but above all for training robots: it's cheaper for a robot to learn to walk a thousand times in a simulated warehouse than to wreck itself in a real one.

Why should you care?

When a chipmaker buys the people who make the models, it wants its hardware to be the natural choice for that kind of work. For you, that could mean more competition against Nvidia and, with luck, less outrageous prices for the compute you rent.

Frank's take

Eight point two billion dollars for a company that makes worlds that don't exist. I'm still waiting for someone to invent one where the bill from the CFE, Mexico's power company, shows up cheap.

— Frank González

Glossary

2 terms
8-K
The report that companies listed in the United States file with the SEC to announce a major event, such as an acquisition.
Compute
The processing capacity (chips, servers, power) used to train and run AI models.

Sources

  1. SEC ADVANCED MICRO DEVICES INC - Form 8-K (opens in a new tab)⁠ sec.gov
  2. TechCrunch AMD will acquire Fei-Fei Li's World Labs for $8.2 billion (opens in a new tab)⁠ techcrunch.com
Story 4 of 4Mobile

Apple releases iOS 27.0.1 and, in iOS 26.7.1, patches a flaw used in targeted attacks

Black-and-white 3D render illustrating: Apple releases iOS 27.0.1 and, in iOS 26.7.1, patches a flaw used in targeted attacks

On September 28 Apple released two iPhone updates, one for each version of its system. The iOS 27 one fixes iPhone 18 Pro and 18 Pro Max restarting when Face ID failed to recognize the user, color artifacts in photos taken at 2x zoom, and the screen becoming unresponsive when opening Notification Center and Control Center at the same time; it's called iOS 27.0.1 and Apple did not disclose any security flaws for it.

The same day it released iOS 26.7.1 for people still on iOS 26. It fixes a flaw in CoreGraphics (CVE-2026-86950) that allowed code execution through a malicious file. Apple says it may have been exploited in an very sophisticated attack against specific individuals on versions before iOS 27. It was reported by Meta's security team.

Key facts

  • 26.7.1security patch
  • 27.0.1fixes for iOS 27

Explained for humans

Why does Apple patch an old version of iOS?

Because not everyone updates to the new system on day one, and Apple keeps looking after the previous version for a while. It's like a gated community that opened a new section but still keeps a guard at the old one, because people still live there.

If your iPhone is still on iOS 26, this is the patch for you, even if you don't want the new system.

Why should you care?

Apple says the attack targeted specific individuals, so you're most likely not the target. But now that the flaw is public, leaving your phone unpatched is leaving the door open, and updating takes a few minutes.

What to do

  • On your iPhone, open Settings → General → Software Update and install whatever shows up.
  • If you're still on iOS 26, install iOS 26.7.1 (it applies to iPhone 11 and later).
  • If you have an iPhone 18 Pro or 18 Pro Max and it restarted when Face ID failed, install iOS 27.0.1.

Frank's take

Apple ships two patches on the same day for two different versions, and half the people out there are going to tap Later. Don't be that half.

— Frank González

Glossary

2 terms
Targeted attack
An attack designed against specific people, not against anyone who happens to fall for it.
CoreGraphics
The part of iOS that draws images and documents on the screen.

Sources

  1. Apple About the security content of iOS 26.7.1 and iPadOS 26.7.1 (opens in a new tab)⁠ support.apple.com
  2. MacRumors Apple Releases iOS 27.0.1 With Face ID Bug Fix (opens in a new tab)⁠ macrumors.com
  3. Forbes / Yahoo Tech Apple Issues Urgent iOS 26.7.1 Security Patch For iPhone Users Not Ready For iOS 27 (opens in a new tab)⁠ tech.yahoo.com

Learn more

Learn it at Ankin Academy

// related service

SMB Network Audit

If your business has a VPN or a remote access appliance open to the internet, we'll check which version it's running and which doors are worth closing.

$3,800 MXN View the service