3 Sources
[1]
Google launches a cheaper alternative to large AI security models like Mythos
Google is launching an AI security model dedicated to quickly finding and patching security vulnerabilities. In a blog post on Tuesday, Google describes Gemini 3.5 Flash Cyber as a "cost-efficient and highly capable alternative" to larger, more expensive AI systems, such as the one offered by
[2]
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively
[3]
Google releases Gemini 3.5 Flash Cyber: a lighter AI to fix flaws faster
Pilot access is limited to governments and trusted partners Google rolled out Gemini 3.5 Flash Cyber and CodeMender today, a new security model and agent built to help organizations spot, verify, and fix software vulnerabilities across large codebases. For now, Gemini 3.5 Flash Cyber is only being
Share
Copy Link
Google DeepMind unveiled Gemini 3.5 Flash Cyber, a lightweight AI security model designed to identify and patch security vulnerabilities quickly and affordably. Available initially to governments and trusted partners through CodeMender, the model discovered 55 unique issues in the V8 JavaScript Engine—outperforming larger models while operating at significantly lower cost.

Google DeepMind announced the release of Gemini 3.5 Flash Cyber on Tuesday, positioning it as a cost-efficient AI security model designed to discover, validate, and patch software vulnerabilities across large codebases
2
. Built upon the Gemini 3.5 Flash foundation, this specialized model aims to provide organizations with a lighter, more affordable alternative to compute-heavy systems like Anthropic's Mythos, which costs twice as much as Claude Opus 4.81
. The new model will be exclusively available to governments and trusted partners through a pilot program via CodeMender, Google's AI-powered agent for vulnerability discovery and remediation2
.CodeMender can call upon Gemini 3.5 Flash Cyber multiple times at high speed and low cost, enabling the AI-driven cybersecurity agent to scan more code paths and identify and patch security vulnerabilities efficiently
1
. Unlike traditional tools that simply flag potential issues, CodeMender goes further by helping determine whether a suspected bug is actually real, then suggesting fixes to cut down the time between discovery and remediation3
. In early internal testing, Google found remote code execution flaws and a memory-corruption bug in a production service in approximately two hours3
. The model also produced a 100% reliable remote code execution exploit that bypassed standard mitigation techniques like Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X)2
.Google's testing reveals that Gemini 3.5 Flash Cyber achieved competitive performance compared to significantly larger models on the CyberGym AI cybersecurity benchmark when invoked up to five times
1
. When tested on the highly complex V8 JavaScript Engine, the model identified 55 unique confirmed issues, compared to 47 found by Gemini 3.5 Flash and 36 by Opus 4.6, including 10 issues that no other model caught2
. Additional stress-testing on complex projects like Google Chrome and Apple Safari showed the model significantly surpassed Gemini 3.5 Flash, 3.6 Flash, and Anthropic Claude Opus 4.62
. The model continued to find new code paths and vulnerabilities after being invoked multiple times, demonstrating its ability to uncover issues that might be missed in single-pass scans1
.Related Stories
Access to Gemini 3.5 Flash Cyber is being kept intentionally restricted due to the dual-use potential of this technology. "Given the dual-use nature of this technology, we have taken an intentional approach to how we deploy 3.5 Flash Cyber," said Raluca Ada Popa, DeepMind's Gemini Security Lead, and Four Flynn, vice president of security and privacy at DeepMind
2
. The limited-access pilot program ensures that frontline defenders get a head start in finding and fixing critical vulnerabilities before they can be exploited, while mitigating against broader misuse2
. This cautious approach mirrors strategies employed by Anthropic and OpenAI with their cyber-focused systems3
.The launch comes as companies race to compete in the AI security space. Microsoft adopted Anthropic's Mythos for its security checks and experienced its biggest Patch Tuesday this month after using AI to find vulnerabilities, while China's Z.ai claims its model can compete with Mythos
1
. Google plans to bring CodeMender's foundational capabilities directly to customers with generally available Gemini models through the Gemini Enterprise Agent Platform2
. However, organizations should maintain realistic expectations. Survey data indicates that 78% of professionals have seen automated tools miss critical bugs, and while 78% of organizations now use AI in cybersecurity, only 27% consider those deployments mature3
. Human review remains essential to address false positives and over-trust in automated systems.Summarized by
Navi
25 Jun 2026•Technology

08 Apr 2025•Technology

16 Jul 2026•Technology

1
Policy and Regulation

2
Technology

3
Technology
