Google launches Gemini 3.5 Flash Cyber to find and fix software vulnerabilities faster

3 Sources

Share

Google DeepMind unveiled Gemini 3.5 Flash Cyber, a lightweight AI security model designed to identify and patch security vulnerabilities quickly and affordably. Available initially to governments and trusted partners through CodeMender, the model discovered 55 unique issues in the V8 JavaScript Engine—outperforming larger models while operating at significantly lower cost.

News article

Google DeepMind Introduces Cost-Efficient AI Security Model

Google DeepMind announced the release of Gemini 3.5 Flash Cyber on Tuesday, positioning it as a cost-efficient AI security model designed to discover, validate, and patch software vulnerabilities across large codebases

2

. Built upon the Gemini 3.5 Flash foundation, this specialized model aims to provide organizations with a lighter, more affordable alternative to compute-heavy systems like Anthropic's Mythos, which costs twice as much as Claude Opus 4.8

1

. The new model will be exclusively available to governments and trusted partners through a pilot program via CodeMender, Google's AI-powered agent for vulnerability discovery and remediation

2

.

How CodeMender Uses AI to Fix Flaws Faster

CodeMender can call upon Gemini 3.5 Flash Cyber multiple times at high speed and low cost, enabling the AI-driven cybersecurity agent to scan more code paths and identify and patch security vulnerabilities efficiently

1

. Unlike traditional tools that simply flag potential issues, CodeMender goes further by helping determine whether a suspected bug is actually real, then suggesting fixes to cut down the time between discovery and remediation

3

. In early internal testing, Google found remote code execution flaws and a memory-corruption bug in a production service in approximately two hours

3

. The model also produced a 100% reliable remote code execution exploit that bypassed standard mitigation techniques like Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X)

2

.

Competitive Performance Against Larger Models

Google's testing reveals that Gemini 3.5 Flash Cyber achieved competitive performance compared to significantly larger models on the CyberGym AI cybersecurity benchmark when invoked up to five times

1

. When tested on the highly complex V8 JavaScript Engine, the model identified 55 unique confirmed issues, compared to 47 found by Gemini 3.5 Flash and 36 by Opus 4.6, including 10 issues that no other model caught

2

. Additional stress-testing on complex projects like Google Chrome and Apple Safari showed the model significantly surpassed Gemini 3.5 Flash, 3.6 Flash, and Anthropic Claude Opus 4.6

2

. The model continued to find new code paths and vulnerabilities after being invoked multiple times, demonstrating its ability to uncover issues that might be missed in single-pass scans

1

.

Limited Access Reflects Dual-Use Potential Concerns

Access to Gemini 3.5 Flash Cyber is being kept intentionally restricted due to the dual-use potential of this technology. "Given the dual-use nature of this technology, we have taken an intentional approach to how we deploy 3.5 Flash Cyber," said Raluca Ada Popa, DeepMind's Gemini Security Lead, and Four Flynn, vice president of security and privacy at DeepMind

2

. The limited-access pilot program ensures that frontline defenders get a head start in finding and fixing critical vulnerabilities before they can be exploited, while mitigating against broader misuse

2

. This cautious approach mirrors strategies employed by Anthropic and OpenAI with their cyber-focused systems

3

.

Broader Implications for AI-Driven Cybersecurity

The launch comes as companies race to compete in the AI security space. Microsoft adopted Anthropic's Mythos for its security checks and experienced its biggest Patch Tuesday this month after using AI to find vulnerabilities, while China's Z.ai claims its model can compete with Mythos

1

. Google plans to bring CodeMender's foundational capabilities directly to customers with generally available Gemini models through the Gemini Enterprise Agent Platform

2

. However, organizations should maintain realistic expectations. Survey data indicates that 78% of professionals have seen automated tools miss critical bugs, and while 78% of organizations now use AI in cybersecurity, only 27% consider those deployments mature

3

. Human review remains essential to address false positives and over-trust in automated systems.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved