- What: Google launches Gemini 3.5 Flash Cyber AI for vulnerability detection
- Impact: AI model is designed to find and fix software vulnerabilities
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities Ravie Lakshmanan Jul 21, 2026 Software Security / Artificial Intelligence Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber , a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot program. CodeMender is an AI-powered agent for vulnerability discovery and patching that was unveiled by the company in October 2025. The lightweight model, per DeepMind, is both cost-efficient and highly capable alternative to large, costly cybersecurity-focused models. CodeMender can call upon 3.5 Flash Cyber "multiple times at high speed and low cost," allowing the AI agent to scan more code paths and find vulnerabilities. The release of 3.5 Flash Cyber comes alongside Gemini 3.6 Flash and 3.5 Flash-Lite , which are optimized for improved coding, knowledge work, and multimodal performance and low-latency tasks, respectively. "Given the dual-use nature of this technology, we have taken an intentional approach to how we deploy 3.5 Flash Cyber," Raluca Ada Popa, DeepMind's Gemini Security Lead, and Four Flynn, vice president of security and privacy at DeepMind, said in a blog post shared with The Hacker News ahead of publication. "As part of a limited-access pilot program, 3.5 Flash Cyber will be exclusively available to governments and trusted partners via CodeMender, expanding over time. This will give frontline defenders a head start in finding and fixing critical vulnerabilities before they can be exploited, while mitigating against broader misuse." In evaluations conducted by the AI research laboratory, 3.5 Flash Cyber has been found to outperform Gemini 3.5 Flash and 3.6 Flash when it comes to unearthing new vulnerabilities in codebases. Additional stress-testing of the model on complex projects like Google Chrome and Apple Safari has revealed it to have "significantly" surpassed Gemini 3.5 Flash, 3.6 Flash, and Anthropic Claude Opus 4.6. "3.5 Flash Cyber consistently discovered more unique vulnerabilities compared with 3.5 Flash and Claude Opus 4.6," it pointed out. "When tested on the highly complex V8 JavaScript Engine across a fixed number of invocations, Gemini 3.5 Flash Cyber found 55 unique confirmed issues, compared to 47 found by Gemini 3.5 Flash and 36 found by Opus 4.6, including 10 issues that no other model caught." Like in the case of Anthropic and OpenAI , Google has put 3.5 Flash Cyber to the test to uncover remote code execution vulnerabilities in public APIs and a memory-corruption vulnerability in a sensitive production service. The model is also said to have produced a 100% reliable remote-code execution exploit that bypassed standard mitigation techniques like Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X). Google said it's separately bringing CodeMender's foundational capabilities directly to customers with generally available Gemini models through the Gemini Enterprise Agent Platform . "By powering CodeMender with 3.5 Flash Cyber, we're providing a highly capable, scalable, and affordable architecture designed to help more defenders secure software," it added. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger Share on Telegram SHARE Application Security , artificial intelligence , browser security , Code Security , enterprise security , Software Security , Vulnerability , Web Security ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See