404/69 Thursday, July 23, 2026

Google has launched Gemini 3.5 Flash Cyber, a cybersecurity-focused AI model built on Gemini 3.5 Flash and optimized to quickly and effectively find, verify, and help fix software vulnerabilities. Google stated that the model is designed to support defenders in responding to threats at scale, especially in situations where AI agents can discover vulnerabilities faster than administrators can remediate them. Gemini 3.5 Flash Cyber will be available through a limited-access pilot program via CodeMender, initially for government agencies and trusted partners, in order to reduce the risk of misuse.
Google stated that Gemini 3.5 Flash Cyber is notable for its speed and cost efficiency, allowing it to be invoked multiple times to analyze many code paths across large codebases before sub-agents summarize the results into a single high-quality report. This approach helps reduce the limitations of relying on larger and more expensive models and is suitable for frequent vulnerability scanning, pre-release system reviews, or enterprise-level commit scanning pipelines. In tests on benchmarks such as CyberGym, which evaluates AI agents against a large number of real-world software vulnerabilities, CodeMender was able to invoke Gemini 3.5 Flash Cyber multiple times for a single report.
In addition, Google stated that Gemini 3.5 Flash Cyber has already been used in real-world operations across Google codebases, including Chrome, Android, Cloud, Ads, and YouTube, where it has helped find and fix vulnerabilities at an operational level. In testing against the V8 JavaScript engine, the model found 55 confirmed vulnerabilities, outperforming the main Gemini 3.5 Flash model, which found 47, and Claude Opus 4.6, which found 36. It also identified 10 vulnerabilities that other models did not find. Google also stated that its Cloud Vulnerability Research team used the model to discover a remote code execution vulnerability in a public API and a memory corruption vulnerability in a sensitive production service within two hours. Google views Gemini 3.5 Flash Cyber, when used together with CodeMender, as an architecture that can help defenders improve software security effectively and at a reasonable cost.
Source: https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/
