Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google's DeepMind has announced the release of Gemini 3.5 Flash Cyber, a specialized AI model designed to discover, validate, and patch vulnerabilities quickly and efficiently. The model will be exclusively available to governments and trusted partners via CodeMender as p…
Intelligence analysis by Llama

Google's DeepMind has released Gemini 3.5 Flash Cyber, a specialized AI model designed to discover, validate, and patch vulnerabilities. The model will be available to governments and trusted partners via CodeMender.
Imagine you have a super smart robot that can help find and fix bugs in software. That's basically what 3.5 Flash Cyber is. It's a special AI model that can look at code and find vulnerabilities, and then help fix them. This can make software safer and reduce the risk of cyber attacks.
Analysis
A Highly Capable Alternative to Large Cybersecurity Models
Google's DeepMind has released Gemini 3.5 Flash Cyber, a specialized AI model designed to discover, validate, and patch vulnerabilities quickly and efficiently. The model is a highly capable alternative to large, costly cybersecurity-focused models, and it is designed to be cost-efficient and highly capable.
How 3.5 Flash Cyber Works
3.5 Flash Cyber is a lightweight model that can be called upon multiple times at high speed and low cost. This allows the AI agent to scan more code paths and find vulnerabilities. The model is designed to run solely inside CodeMender, which makes it easy to set guardrails that enable the AI agent's defense functions while disabling other cyber activity.
Evaluations and Stress-Testing
Evaluations conducted by the AI research laboratory have shown that 3.5 Flash Cyber outperforms Gemini 3.5 Flash and 3.6 Flash when it comes to unearthing new vulnerabilities in codebases. Stress-testing of the model on complex projects like Google Chrome and Apple Safari has revealed that it has significantly surpassed Gemini 3.5 Flash, 3.6 Flash, and Anthropic Claude Opus 4.6. The model has consistently discovered more unique vulnerabilities compared with 3.5 Flash and Claude Opus 4.6, and it has produced a 100% reliable remote-code execution exploit that bypassed standard mitigation techniques like Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X).
Plans for Future Development
Google has plans to extend the model's capabilities to include red-teaming features and end-to-end enterprise defense. The company is also bringing CodeMender's foundational capabilities directly to customers with generally available Gemini models through the Gemini Enterprise Agent Platform.
Key points
- Google's DeepMind has released Gemini 3.5 Flash Cyber, a specialized AI model designed to discover, validate, and patch vulnerabilities quickly and efficiently.
- The model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot program.
- 3.5 Flash Cyber is a highly capable alternative to large, costly cybersecurity-focused models, and it is designed to be cost-efficient and highly capable.
- The model has consistently discovered more unique vulnerabilities compared with 3.5 Flash and Claude Opus 4.6, and it has produced a 100% reliable remote-code execution exploit that bypassed standard mitigation techniques like Address Space Layout Randomization (ASLR) and Writ…
- Google has plans to extend the model's capabilities to include red-teaming features and end-to-end enterprise defense.
The release of 3.5 Flash Cyber could lead to significant improvements in software security and a reduction in the risk of cyber attacks. If this development plays out positively, it could save lives and prevent financial losses.
However, there are also potential risks associated with the release of 3.5 Flash Cyber. For example, if the model is not properly secured, it could be used for malicious purposes. Additionally, the model's ability to discover and patch vulnerabilities quickly and efficiently could lead to a false sense of security, causing developers to become complacent and neglect other security measures.



